Skip to content

Commit

Permalink
feat: run as non-root
Browse files Browse the repository at this point in the history
  • Loading branch information
ed382 committed Nov 14, 2024
1 parent bba6fff commit 8432ae5
Showing 1 changed file with 15 additions and 10 deletions.
25 changes: 15 additions & 10 deletions charts/testkube-enterprise/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -96,14 +96,16 @@ global:
# -- Global security Context for all containers.
containerSecurityContext: {}
# -- Global security Context for all pods.
podSecurityContext: {}
podSecurityContext:
runAsNonRoot: true
# Testkube requires a variety of secrets to operate.
# Any secret not provided manually will be automatically generated with a random value by the shared secret job.
sharedSecretGenerator:
# -- Toggle whether to enable the Shared Secret Generator Job
enabled: false
# -- Pod Security Context for the Shared Secret Generator Job
securityContext: {}
securityContext:
runAsNonRoot: true
# -- Container Security Context for the Shared Secret Generator Job
containerSecurityContext: {}
# -- Resources for the Shared Secret Generator Job
Expand Down Expand Up @@ -171,6 +173,7 @@ minio:
affinity: {}
# MinIO Pod Security Context
podSecurityContext:
runAsNonRoot: true
# -- Toggle whether to render the pod security context
enabled: true
fsGroup: 1001
Expand Down Expand Up @@ -223,8 +226,8 @@ testkube-cloud-api:
repository: kubeshop/testkube-enterprise-api
tag: 1.10.81
# -- Pod Security Context
podSecurityContext: {}
# fsGroup: 2000
podSecurityContext:
runAsNonRoot: true
# -- Container Security Context
securityContext:
readOnlyRootFilesystem: true
Expand Down Expand Up @@ -413,8 +416,8 @@ testkube-cloud-ui:
repository: kubeshop/testkube-enterprise-ui
tag: 2.7.3
# -- Pod Security Context
podSecurityContext: {}
# fsGroup: 2000
podSecurityContext:
runAsNonRoot: true
# -- Container Security Context
securityContext:
readOnlyRootFilesystem: true
Expand Down Expand Up @@ -447,8 +450,8 @@ testkube-worker-service:
repository: kubeshop/testkube-enterprise-worker-service
tag: 1.10.74
# -- Pod Security Context
podSecurityContext: {}
# fsGroup: 2000
podSecurityContext:
runAsNonRoot: true
# -- Container Security Context
securityContext:
readOnlyRootFilesystem: true
Expand Down Expand Up @@ -646,7 +649,8 @@ mongodb:
tolerations: []
# ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod
# -- MongoDB Pod Security Context
podSecurityContext: {}
podSecurityContext:
runAsNonRoot: true
# ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
# -- Security Context for MongoDB container
containerSecurityContext: {}
Expand Down Expand Up @@ -736,7 +740,8 @@ dex:
securityContext: {}
# ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod
# -- Dex Pod Security Context
podSecurityContext: {}
podSecurityContext:
runAsNonRoot: true
# -- Set resources requests and limits for Dex Service
resources:
requests:
Expand Down

0 comments on commit 8432ae5

Please sign in to comment.