Skip to content

Commit 047453f

Browse files
authored
Security contexts for k8s (#657)
1 parent d405395 commit 047453f

File tree

3 files changed

+19
-1
lines changed

3 files changed

+19
-1
lines changed

deployment/k8s/charts/Chart.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ apiVersion: v1
22
appVersion: 0.11.7
33
description: A dynamic Web Map tile server
44
name: titiler
5-
version: 1.1.1
5+
version: 1.1.2
66
icon: https://raw.githubusercontent.com/developmentseed/titiler/main/docs/logos/TiTiler_logo_small.png
77
maintainers:
88
- name: emmanuelmathot # Emmanuel Mathot

deployment/k8s/charts/templates/deployment.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,10 +14,14 @@ spec:
1414
labels:
1515
{{- include "titiler.selectorLabels" . | nindent 8 }}
1616
spec:
17+
securityContext:
18+
{{- toYaml .Values.podSecurityContext | nindent 8 }}
1719
containers:
1820
- name: {{ .Chart.Name }}
1921
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
2022
imagePullPolicy: {{ .Values.image.pullPolicy }}
23+
securityContext:
24+
{{- toYaml .Values.securityContext | nindent 12 }}
2125
env:
2226
{{- range $key, $val := .Values.env }}
2327
- name: {{ $key }}

deployment/k8s/charts/values.yaml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,3 +65,17 @@ nodeSelector: {}
6565
tolerations: []
6666

6767
affinity: {}
68+
69+
securityContext: {}
70+
# capabilities:
71+
# drop:
72+
# - ALL
73+
# readOnlyRootFilesystem: true
74+
# allowPrivilegeEscalation: false
75+
# runAsNonRoot: true
76+
# runAsUser: 1001
77+
78+
podSecurityContext: {}
79+
# fsGroup: 1001
80+
# runAsNonRoot: true
81+
# runAsUser: 1001

0 commit comments

Comments
 (0)