Skip to content

Commit f978a0b

Browse files
Update ingress.tf - 4.10.1 + runAsNonRoot (#17)
* Update ingress.tf - 4.10.1 + runAsNonRoot
1 parent fba5732 commit f978a0b

File tree

1 file changed

+36
-1
lines changed

1 file changed

+36
-1
lines changed

modules/base/ingress.tf

Lines changed: 36 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ resource "helm_release" "ingress_nginx" {
1515
repository = "https://kubernetes.github.io/ingress-nginx"
1616

1717
chart = "ingress-nginx"
18-
version = "4.10.0"
18+
version = "4.10.1"
1919
wait = true
2020
timeout = 600
2121

@@ -55,5 +55,40 @@ resource "helm_release" "ingress_nginx" {
5555
value = var.ingress_nginx_min_unavailable
5656
}
5757

58+
set {
59+
name = "controller.containerSecurityContext.runAsUser"
60+
value = 101
61+
}
62+
63+
set {
64+
name = "controller.containerSecurityContext.runAsGroup"
65+
value = 101
66+
}
67+
68+
set {
69+
name = "controller.containerSecurityContext.allowPrivilegeEscalation"
70+
value = false
71+
}
72+
73+
set {
74+
name = "controller.containerSecurityContext.readOnlyRootFilesystem"
75+
value = false
76+
}
77+
78+
set {
79+
name = "controller.containerSecurityContext.runAsNonRoot"
80+
value = true
81+
}
82+
83+
set_list {
84+
name = "controller.containerSecurityContext.capabilities.drop"
85+
value = ["ALL"]
86+
}
87+
88+
set_list {
89+
name = "controller.containerSecurityContext.capabilities.add"
90+
value = ["NET_BIND_SERVICE"]
91+
}
92+
5893
depends_on = [module.azure_aks.node_resource_group]
5994
}

0 commit comments

Comments
 (0)