Merge "[COMMON] Security Context templates"
authorKrzysztof Opasiak <k.opasiak@samsung.com>
Fri, 22 May 2020 14:35:36 +0000 (14:35 +0000)
committerGerrit Code Review <gerrit@onap.org>
Fri, 22 May 2020 14:35:36 +0000 (14:35 +0000)
kubernetes/common/common/templates/_pod.tpl

index d3fc25a..de25485 100644 (file)
 {{-     end }}
 {{-   end }}
 {{- end -}}
+
+{{/*
+   Generate securityContext for pod
+*/}}
+{{- define "common.podSecurityContext" -}}
+securityContext:
+  runAsUser: {{ .Values.securityContext.user_id }}
+  runAsGroup: {{ .Values.securityContext.group_id }}
+  fsGroup: {{ .Values.securityContext.group_id }}
+{{- end }}
+
+{{/*
+   Generate securityContext for container
+*/}}
+{{- define "common.containerSecurityContext" -}}
+securityContext:
+  readOnlyRootFilesystem: true
+  privileged: false
+  allowPrivilegeEscalation: false
+{{- end }}
+