[CONSUL] Make consul run as non-root
[oom.git] / kubernetes / consul / charts / consul-server / templates / statefulset.yaml
index d572ec2..872ef13 100644 (file)
@@ -42,10 +42,11 @@ spec:
       containers:
       - name: {{ include "common.name" . }}
         image: "{{ include "common.repository" . }}/{{ .Values.image }}"
-        command:
-        - sh
+        securityContext:
+          runAsUser: {{ .Values.securityContext.runAsUser }}
+          runAsGroup: {{ .Values.securityContext.runAsGroup }}
+        command: ["/usr/local/bin/docker-entrypoint.sh"]
         args:
-        - /usr/local/bin/docker-entrypoint.sh
         - "agent"
         - "-bootstrap-expect={{ .Values.replicaCount }}"
         - "-enable-script-checks"