@@ -19,13 +19,24 @@ spec:
1919 labels :
2020 app : {{ include "mgmt-agent.resourceNamePrefix" . }}-mgmt-agent
2121 spec :
22+ securityContext :
23+ runAsUser : {{ default 0 .Values.deployment.security.runAsUser }}
24+ runAsGroup : {{ default 0 .Values.deployment.security.runAsGroup }}
25+ fsGroup : {{ default 0 .Values.deployment.security.fsGroup }}
2226 serviceAccountName : {{ include "mgmt-agent.serviceAccount" . }}
2327 imagePullSecrets :
2428 - name : {{ include "mgmt-agent.resourceNamePrefix" . }}-mgmt-agent-container-registry-key
2529 restartPolicy : Always
2630 containers :
2731 - name : {{ include "mgmt-agent.resourceNamePrefix" . }}-mgmt-agent
2832 image : {{ .Values.mgmtagent.image.url }}
33+ resources :
34+ requests :
35+ cpu : {{ .Values.deployment.resource.request.cpuCore }}
36+ memory : {{ .Values.deployment.resource.request.memory }}
37+ limits :
38+ cpu : {{ .Values.deployment.resource.limit.cpuCore }}
39+ memory : {{ .Values.deployment.resource.limit.memory }}
2940 volumeMounts :
3041 - name : mgmtagent-secret
3142 mountPath : /opt/oracle/mgmtagent_secret
@@ -34,19 +45,28 @@ spec:
3445 mountPath : /opt/oracle
3546 - name : mgmtagent-config
3647 mountPath : /opt/oracle/mgmtagent_config
48+ - mountPath : /tmp
49+ name : tmp
50+ securityContext :
51+ allowPrivilegeEscalation : false
52+ readOnlyRootFilesystem : true
3753 volumes :
3854 - name : mgmtagent-secret
3955 secret :
4056 secretName : {{ include "mgmt-agent.resourceNamePrefix" . }}-mgmt-agent-rsp
4157 - name : mgmtagent-config
4258 configMap :
4359 name : {{ include "mgmt-agent.resourceNamePrefix" . }}-metrics
60+ - emptyDir : {}
61+ name : tmp
4462 volumeClaimTemplates :
4563 - metadata :
4664 name : mgmtagent-pvc
4765 spec :
4866 accessModes : [ "ReadWriteOnce" ]
49- storageClassName : " oci-bv"
67+ {{- if .Values.deployment.storageClass }}
68+ storageClassName : {{ .Values.deployment.storageClass }}
69+ {{- end }}
5070 resources :
5171 requests :
52- storage : 2Gi
72+ storage : {{ .Values.deployment.resource.request.storage }}
0 commit comments