Run as non-root

I tried to follow a principle of encapsulation here - we can still default to
peeps making connections to 80/443 on a Service object, but internally we will
use 8080/8443.

Signed-off-by: Andrew Keesler <akeesler@vmware.com>
This commit is contained in:
Andrew Keesler
2020-11-02 12:51:15 -05:00
parent 7639d5e161
commit fcea48c8f9
14 changed files with 54 additions and 41 deletions
+6 -3
View File
@@ -86,6 +86,9 @@ spec:
annotations:
scheduler.alpha.kubernetes.io/critical-pod: ""
spec:
securityContext:
runAsUser: 1001
runAsGroup: 1001
serviceAccountName: #@ defaultResourceName()
#@ if data.values.image_pull_dockerconfigjson and data.values.image_pull_dockerconfigjson != "":
imagePullSecrets:
@@ -113,7 +116,7 @@ spec:
livenessProbe:
httpGet:
path: /healthz
port: 443
port: 8443
scheme: HTTPS
initialDelaySeconds: 2
timeoutSeconds: 15
@@ -122,7 +125,7 @@ spec:
readinessProbe:
httpGet:
path: /healthz
port: 443
port: 8443
scheme: HTTPS
initialDelaySeconds: 2
timeoutSeconds: 3
@@ -173,7 +176,7 @@ spec:
ports:
- protocol: TCP
port: 443
targetPort: 443
targetPort: 8443
---
apiVersion: apiregistration.k8s.io/v1
kind: APIService