Skip to content

Commit 63699c0

Browse files
committed
fix: update security context to drop all capabilities for daemonset
Signed-off-by: zeroalphat <taichi-takemura@cybozu.co.jp>
1 parent 7ed243d commit 63699c0

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

charts/ofen/templates/daemonset.yaml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,9 @@ spec:
6060
- name: containerd-host-dir
6161
mountPath: {{ .Values.daemon.containerdHostDirPath }}
6262
securityContext:
63-
runAsUser: 0 # Run as root to mount containerd socket
63+
capabilities:
64+
drop:
65+
- ALL
6466
serviceAccountName: '{{ template "ofen.fullname" . }}-controller-manager'
6567
terminationGracePeriodSeconds: 10
6668
{{- with .Values.daemon.imagePullSecrets }}

0 commit comments

Comments
 (0)