File tree Expand file tree Collapse file tree 4 files changed +31
-6
lines changed
Expand file tree Collapse file tree 4 files changed +31
-6
lines changed Original file line number Diff line number Diff line change @@ -3,14 +3,18 @@ kind: Namespace
33metadata :
44 name : {{ .Values.namespace }}
55 labels :
6- pod-security.kubernetes.io/enforce : restricted
7- pod-security.kubernetes.io/enforce-version : latest
6+ {{- if .Values.namespace_psa }}
7+ pod-security.kubernetes.io/enforce : {{ .Values.namespace_psa.enforceLevel }}
8+ pod-security.kubernetes.io/enforce-version : {{ .Values.namespace_psa.enforceVersion }}
9+ {{- end }}
810
911---
1012apiVersion : v1
1113kind : Namespace
1214metadata :
1315 name : {{ .Values.operator_namespace }}
1416 labels :
15- pod-security.kubernetes.io/enforce : baseline
16- pod-security.kubernetes.io/enforce-version : latest
17+ {{- if .Values.operator_namespace_psa }}
18+ pod-security.kubernetes.io/enforce : {{ .Values.operator_namespace_psa.enforceLevel }}
19+ pod-security.kubernetes.io/enforce-version : {{ .Values.operator_namespace_psa.enforceVersion }}
20+ {{- end }}
Original file line number Diff line number Diff line change 8484 - --client-ca
8585 - /profile-collector-cert/tls.crt
8686 {{- end }}
87- - --set-workload-user-id
88- - " true"
87+ {{- if eq .Values.catalog.setWorkloadUserID true }}
88+ - --set-workload-user-id=true
89+ {{- else }}
90+ - --set-workload-user-id=false
91+ {{ end }}
8992 image : {{ .Values.catalog.image.ref }}
9093 imagePullPolicy : {{ .Values.catalog.image.pullPolicy }}
9194 ports :
Original file line number Diff line number Diff line change 11rbacApiVersion : rbac.authorization.k8s.io
22namespace : operator-lifecycle-manager
3+ # see https://kubernetes.io/docs/concepts/security/pod-security-admission/ for more details
4+ namespace_psa :
5+ enforceLevel : restricted
6+ enforceVersion : latest
37catalog_namespace : operator-lifecycle-manager
48operator_namespace : operators
9+ # see https://kubernetes.io/docs/concepts/security/pod-security-admission/ for more details
10+ operator_namespace_psa :
11+ enforceLevel : baseline
12+ enforceVersion : latest
513minKubeVersion : 1.11.0
614writeStatusName : ' ""'
715imagestream : false
2533 memory : 160Mi
2634
2735catalog :
36+ setWorkloadUserID : true
2837 replicaCount : 1
2938 commandArgs : --configmapServerImage=quay.io/operator-framework/configmap-operator-registry:latest
3039 image :
Original file line number Diff line number Diff line change 11installType : upstream
22rbacApiVersion : rbac.authorization.k8s.io
33namespace : olm
4+ # see https://kubernetes.io/docs/concepts/security/pod-security-admission/ for more details
5+ namespace_psa :
6+ enforceLevel : restricted
7+ enforceVersion : latest
48catalog_namespace : olm
59operator_namespace : operators
10+ # see https://kubernetes.io/docs/concepts/security/pod-security-admission/ for more details
11+ operator_namespace_psa :
12+ enforceLevel : baseline
13+ enforceVersion : latest
614imagestream : false
715writeStatusName : ' ""'
816writePackageServerStatusName : " "
1422 service :
1523 internalPort : 8080
1624catalog :
25+ setWorkloadUserID : true
1726 replicaCount : 1
1827 image :
1928 ref : quay.io/operator-framework/olm@sha256:e74b2ac57963c7f3ba19122a8c31c9f2a0deb3c0c5cac9e5323ccffd0ca198ed
You can’t perform that action at this time.
0 commit comments