mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 14:47:34 +02:00
specify ReadOnlyRootFilesystem: false for pod security policies (#560)
Explicitly specify ReadOnlyRootFilesystem: false so kubernetes can pick a less restrictive policy the operator has access to.
This commit is contained in:
committed by
Felix Kunde
parent
44acd7e4db
commit
c65a9baedf
@@ -359,6 +359,8 @@ func generateContainer(
|
||||
volumeMounts []v1.VolumeMount,
|
||||
privilegedMode bool,
|
||||
) *v1.Container {
|
||||
falseBool := false
|
||||
|
||||
return &v1.Container{
|
||||
Name: name,
|
||||
Image: *dockerImage,
|
||||
@@ -382,6 +384,7 @@ func generateContainer(
|
||||
Env: envVars,
|
||||
SecurityContext: &v1.SecurityContext{
|
||||
Privileged: &privilegedMode,
|
||||
ReadOnlyRootFilesystem: &falseBool,
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user