diff --git a/config/base/manager/manager.yaml b/config/base/manager/manager.yaml index 4428ba9b..03abf32f 100644 --- a/config/base/manager/manager.yaml +++ b/config/base/manager/manager.yaml @@ -47,6 +47,8 @@ spec: - linux securityContext: runAsNonRoot: true + seLinuxOptions: + type: spc_t seccompProfile: type: RuntimeDefault containers: diff --git a/openshift/kustomize/overlays/openshift/olmv1-ns/patches/manager_deployment_certs.yaml b/openshift/kustomize/overlays/openshift/olmv1-ns/patches/manager_deployment_certs.yaml index 2d78f878..f8b75b53 100644 --- a/openshift/kustomize/overlays/openshift/olmv1-ns/patches/manager_deployment_certs.yaml +++ b/openshift/kustomize/overlays/openshift/olmv1-ns/patches/manager_deployment_certs.yaml @@ -19,3 +19,6 @@ - op: add path: /spec/template/spec/containers/1/env value: [{"name":"SSL_CERT_DIR", "value":"/var/ca-certs"}] +- op: add + path: /spec/template/spec/securityContext/seLinuxOptions + value: {"type":"spc_t"} diff --git a/openshift/manifests/14-deployment-openshift-catalogd-catalogd-controller-manager.yml b/openshift/manifests/14-deployment-openshift-catalogd-catalogd-controller-manager.yml index 8e434b84..8a37f0a7 100644 --- a/openshift/manifests/14-deployment-openshift-catalogd-catalogd-controller-manager.yml +++ b/openshift/manifests/14-deployment-openshift-catalogd-catalogd-controller-manager.yml @@ -119,6 +119,8 @@ spec: node-role.kubernetes.io/master: "" securityContext: runAsNonRoot: true + seLinuxOptions: + type: spc_t seccompProfile: type: RuntimeDefault serviceAccountName: catalogd-controller-manager