Skip to content

Commit 8cd8009

Browse files
authored
Merge pull request kubernetes#3021 from Lujeni/rootless_kubernetes
Run as non-root for kubernetes on VPA
2 parents 8b72a52 + 03d89f7 commit 8cd8009

File tree

4 files changed

+12
-0
lines changed

4 files changed

+12
-0
lines changed

vertical-pod-autoscaler/deploy/admission-controller-deployment.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,9 @@ spec:
1515
app: vpa-admission-controller
1616
spec:
1717
serviceAccountName: vpa-admission-controller
18+
securityContext:
19+
runAsNonRoot: true
20+
runAsUser: 65534 # nobody
1821
containers:
1922
- name: admission-controller
2023
image: us.gcr.io/k8s-artifacts-prod/autoscaling/vpa-admission-controller:0.8.0

vertical-pod-autoscaler/deploy/recommender-deployment.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,9 @@ spec:
2121
app: vpa-recommender
2222
spec:
2323
serviceAccountName: vpa-recommender
24+
securityContext:
25+
runAsNonRoot: true
26+
runAsUser: 65534 # nobody
2427
containers:
2528
- name: recommender
2629
image: us.gcr.io/k8s-artifacts-prod/autoscaling/vpa-recommender:0.8.0

vertical-pod-autoscaler/deploy/updater-deployment.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,9 @@ spec:
2121
app: vpa-updater
2222
spec:
2323
serviceAccountName: vpa-updater
24+
securityContext:
25+
runAsNonRoot: true
26+
runAsUser: 65534 # nobody
2427
containers:
2528
- name: updater
2629
image: us.gcr.io/k8s-artifacts-prod/autoscaling/vpa-updater:0.8.0

vertical-pod-autoscaler/examples/hamster.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,9 @@ spec:
3939
labels:
4040
app: hamster
4141
spec:
42+
securityContext:
43+
runAsNonRoot: true
44+
runAsUser: 65534 # nobody
4245
containers:
4346
- name: hamster
4447
image: k8s.gcr.io/ubuntu-slim:0.1

0 commit comments

Comments
 (0)