File tree 3 files changed +17
-1
lines changed
3 files changed +17
-1
lines changed Original file line number Diff line number Diff line change 26
26
spec :
27
27
securityContext :
28
28
runAsNonRoot : true
29
+ readOnlyRootFilesystem : true
29
30
seccompProfile :
30
31
type : RuntimeDefault
31
32
serviceAccount : csi-snapshot-controller
Original file line number Diff line number Diff line change 53
53
volumeMounts :
54
54
- mountPath : /etc/guest-kubeconfig
55
55
name : guest-kubeconfig
56
+ - mountPath : /var/run/secrets/serving-cert
57
+ name : serving-cert
56
58
securityContext :
57
59
runAsNonRoot : true
58
60
seccompProfile :
62
64
- name : guest-kubeconfig
63
65
secret :
64
66
secretName : service-network-admin-kubeconfig
67
+ - name : serving-cert
68
+ secret :
69
+ secretName : serving-cert
70
+ optional : true
Original file line number Diff line number Diff line change 31
31
requests :
32
32
memory : 65Mi
33
33
cpu : 10m
34
+ volumeMounts :
35
+ - mountPath : /var/run/secrets/serving-cert
36
+ name : serving-cert
34
37
securityContext :
35
38
allowPrivilegeEscalation : false
36
- readOnlyRootFilesystem : false
39
+ readOnlyRootFilesystem : true
37
40
capabilities :
38
41
drop :
39
42
- ALL
54
57
fieldRef :
55
58
fieldPath : metadata.name
56
59
terminationMessagePolicy : FallbackToLogsOnError
60
+ volumes :
61
+ - name : serving-cert
62
+ secret :
63
+ secretName : serving-cert
64
+ optional : true
57
65
priorityClassName : " system-cluster-critical"
58
66
nodeSelector :
59
67
node-role.kubernetes.io/master : " "
73
81
runAsNonRoot : true
74
82
seccompProfile :
75
83
type : RuntimeDefault
84
+
You can’t perform that action at this time.
0 commit comments