File tree Expand file tree Collapse file tree 3 files changed +14
-0
lines changed
bootkube/bootstrap-manifests Expand file tree Collapse file tree 3 files changed +14
-0
lines changed Original file line number Diff line number Diff line change @@ -146,6 +146,7 @@ spec:
146
146
- name : GOGC
147
147
value : " {{ .GOGC }}"
148
148
securityContext :
149
+ readOnlyRootFilesystem : true
149
150
privileged : true
150
151
- name : kube-apiserver-cert-syncer
151
152
env :
@@ -169,6 +170,8 @@ spec:
169
170
requests :
170
171
memory : 50Mi
171
172
cpu : 5m
173
+ securityContext :
174
+ readOnlyRootFilesystem : true
172
175
volumeMounts :
173
176
- mountPath : /etc/kubernetes/static-pod-resources
174
177
name : resource-dir
@@ -194,6 +197,8 @@ spec:
194
197
requests :
195
198
memory : 50Mi
196
199
cpu : 5m
200
+ securityContext :
201
+ readOnlyRootFilesystem : true
197
202
volumeMounts :
198
203
- mountPath : /etc/kubernetes/static-pod-resources
199
204
name : resource-dir
@@ -211,6 +216,8 @@ spec:
211
216
requests :
212
217
memory : 50Mi
213
218
cpu : 5m
219
+ securityContext :
220
+ readOnlyRootFilesystem : true
214
221
- name : kube-apiserver-check-endpoints
215
222
image : {{.OperatorImage}}
216
223
imagePullPolicy : IfNotPresent
@@ -264,6 +271,8 @@ spec:
264
271
requests :
265
272
memory : 50Mi
266
273
cpu : 10m
274
+ securityContext :
275
+ readOnlyRootFilesystem : true
267
276
terminationGracePeriodSeconds : {{.GracefulTerminationDuration}}
268
277
hostNetwork : true
269
278
priorityClassName : system-node-critical
Original file line number Diff line number Diff line change 50
50
requests :
51
51
memory : 1Gi
52
52
cpu : 265m
53
+ securityContext :
54
+ readOnlyRootFilesystem : true
53
55
volumeMounts :
54
56
- mountPath : /etc/ssl/certs
55
57
name : ssl-certs-host
@@ -117,6 +119,8 @@ spec:
117
119
requests :
118
120
memory : 50Mi
119
121
cpu : 5m
122
+ securityContext :
123
+ readOnlyRootFilesystem : true
120
124
{{end}}
121
125
terminationGracePeriodSeconds : {{ .TerminationGracePeriodSeconds }}
122
126
volumes :
Original file line number Diff line number Diff line change 35
35
- name : kube-apiserver-operator
36
36
securityContext :
37
37
allowPrivilegeEscalation : false
38
+ readOnlyRootFilesystem : true
38
39
capabilities :
39
40
drop : ["ALL"]
40
41
image : docker.io/openshift/origin-cluster-kube-apiserver-operator:v4.0
You can’t perform that action at this time.
0 commit comments