Commit 4a42bf4
committed
Set runAsNonRoot at the container-level only
Some service meshes require privileged init-containers or sidecars, and
the pod-level setting prevents these from working correctly.
We satisfy Kubernetes' Restricted Pod Security policy by setting
"runAsNonRoot" for all our containers, so setting it on the pod is
redundant.
Issue: [sc-15204]
See: https://kubernetes.io/docs/concepts/security/pod-security-admission/
See: https://kubernetes.io/docs/concepts/security/pod-security-standards/1 parent b5d6cc3 commit 4a42bf4
File tree
10 files changed
+14
-32
lines changed- internal
- controller/postgrescluster
- initialize
- postgres
10 files changed
+14
-32
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
528 | 528 | | |
529 | 529 | | |
530 | 530 | | |
531 | | - | |
532 | 531 | | |
533 | 532 | | |
534 | 533 | | |
| |||
541 | 540 | | |
542 | 541 | | |
543 | 542 | | |
544 | | - | |
545 | 543 | | |
546 | 544 | | |
547 | 545 | | |
| |||
668 | 666 | | |
669 | 667 | | |
670 | 668 | | |
671 | | - | |
672 | 669 | | |
673 | 670 | | |
674 | 671 | | |
| |||
704 | 701 | | |
705 | 702 | | |
706 | 703 | | |
707 | | - | |
708 | 704 | | |
709 | 705 | | |
710 | 706 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
715 | 715 | | |
716 | 716 | | |
717 | 717 | | |
718 | | - | |
| 718 | + | |
719 | 719 | | |
720 | 720 | | |
721 | 721 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
344 | 344 | | |
345 | 345 | | |
346 | 346 | | |
347 | | - | |
348 | 347 | | |
349 | 348 | | |
350 | 349 | | |
| |||
2519 | 2518 | | |
2520 | 2519 | | |
2521 | 2520 | | |
2522 | | - | |
2523 | 2521 | | |
2524 | 2522 | | |
2525 | 2523 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
447 | 447 | | |
448 | 448 | | |
449 | 449 | | |
450 | | - | |
| 450 | + | |
451 | 451 | | |
452 | 452 | | |
453 | 453 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
470 | 470 | | |
471 | 471 | | |
472 | 472 | | |
473 | | - | |
474 | 473 | | |
475 | 474 | | |
476 | 475 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
811 | 811 | | |
812 | 812 | | |
813 | 813 | | |
814 | | - | |
815 | 814 | | |
816 | 815 | | |
817 | 816 | | |
| |||
860 | 859 | | |
861 | 860 | | |
862 | 861 | | |
863 | | - | |
864 | 862 | | |
865 | 863 | | |
866 | 864 | | |
| |||
924 | 922 | | |
925 | 923 | | |
926 | 924 | | |
927 | | - | |
928 | 925 | | |
929 | 926 | | |
930 | 927 | | |
| |||
972 | 969 | | |
973 | 970 | | |
974 | 971 | | |
975 | | - | |
976 | 972 | | |
977 | 973 | | |
978 | 974 | | |
| |||
1038 | 1034 | | |
1039 | 1035 | | |
1040 | 1036 | | |
1041 | | - | |
1042 | 1037 | | |
1043 | 1038 | | |
1044 | 1039 | | |
| |||
1089 | 1084 | | |
1090 | 1085 | | |
1091 | 1086 | | |
1092 | | - | |
1093 | 1087 | | |
1094 | 1088 | | |
1095 | 1089 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
23 | | - | |
24 | | - | |
| 22 | + | |
| 23 | + | |
25 | 24 | | |
26 | 25 | | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | 26 | | |
31 | 27 | | |
32 | 28 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
28 | | - | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
29 | 33 | | |
30 | 34 | | |
31 | 35 | | |
| |||
47 | 51 | | |
48 | 52 | | |
49 | 53 | | |
50 | | - | |
51 | | - | |
52 | | - | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
53 | 57 | | |
54 | 58 | | |
55 | 59 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
262 | 262 | | |
263 | 263 | | |
264 | 264 | | |
265 | | - | |
| 265 | + | |
266 | 266 | | |
267 | 267 | | |
268 | 268 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
604 | 604 | | |
605 | 605 | | |
606 | 606 | | |
607 | | - | |
608 | 607 | | |
609 | 608 | | |
610 | 609 | | |
611 | 610 | | |
612 | 611 | | |
613 | | - | |
614 | 612 | | |
615 | 613 | | |
616 | 614 | | |
617 | 615 | | |
618 | 616 | | |
619 | | - | |
620 | 617 | | |
621 | 618 | | |
622 | 619 | | |
623 | 620 | | |
624 | 621 | | |
625 | | - | |
626 | 622 | | |
627 | 623 | | |
628 | 624 | | |
| |||
632 | 628 | | |
633 | 629 | | |
634 | 630 | | |
635 | | - | |
636 | 631 | | |
637 | 632 | | |
638 | 633 | | |
| |||
0 commit comments