Skip to content

Commit 736a236

Browse files
authored
Merge pull request #622 from snyk/fix/volume-mount-permissions
Fix/volume mount permissions
2 parents 2376065 + 8757166 commit 736a236

File tree

4 files changed

+12
-1
lines changed

4 files changed

+12
-1
lines changed

snyk-monitor/templates/deployment.yaml

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,10 +23,18 @@ spec:
2323
initContainers:
2424
- name: volume-permissions
2525
image: "{{ .Values.initContainerImage.repository }}:{{ .Values.initContainerImage.tag }}"
26-
command : ['sh', '-c', 'chmod -R 777 /var/tmp']
26+
command : ['sh', '-c', 'chmod -R g+rwX /var/tmp || true']
2727
volumeMounts:
2828
- name: temporary-storage
2929
mountPath: "/var/tmp"
30+
securityContext:
31+
privileged: false
32+
runAsNonRoot: false
33+
allowPrivilegeEscalation: false
34+
readOnlyRootFilesystem: true
35+
capabilities:
36+
drop:
37+
- ALL
3038
containers:
3139
- name: {{ include "snyk-monitor.name" . }}
3240
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"

test/fixtures/operator/custom-resource-k8s.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,4 @@ metadata:
55
namespace: marketplace
66
spec:
77
integrationApi: https://kubernetes-upstream.dev.snyk.io
8+
temporaryStorageSize: 20Gi

test/fixtures/operator/custom-resource.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,4 @@ metadata:
55
namespace: snyk-monitor
66
spec:
77
integrationApi: https://kubernetes-upstream.dev.snyk.io
8+
temporaryStorageSize: 20Gi

test/setup/deployers/helm.ts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@ async function deployKubernetesMonitor(
3232
'--set integrationApi=https://kubernetes-upstream.dev.snyk.io ' +
3333
'--set nodeSelector."kubernetes\\.io/os"=linux ' +
3434
'--set psp.enabled=true ' +
35+
'--set pvc.enabled=true ' +
3536
'--set log_level="INFO"'
3637
);
3738
console.log(`Deployed ${imageOptions.nameAndTag} with pull policy ${imageOptions.pullPolicy}`);

0 commit comments

Comments
 (0)