From 197a826cc466db03834dca96554acb098880641a Mon Sep 17 00:00:00 2001 From: Bruno Willenborg Date: Fri, 3 Nov 2023 00:36:25 +0100 Subject: [PATCH] Revert "Remove rather specific default for podSecurityContext for solr" This reverts commit 313c09c12b8adcb0856f85d3af0c214ed4f63308. --- charts/sddi-ckan/charts/solr/README.md | 2 +- charts/sddi-ckan/charts/solr/values.yaml | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/charts/sddi-ckan/charts/solr/README.md b/charts/sddi-ckan/charts/solr/README.md index 88cf639..bd5c1ab 100644 --- a/charts/sddi-ckan/charts/solr/README.md +++ b/charts/sddi-ckan/charts/solr/README.md @@ -38,7 +38,7 @@ A Helm chart for Solr pre-configured for CKAN and ckanext-spatial. | persistence.capacity | string | `"4Gi"` | Storage [capacity](https://kubernetes.io/docs/concepts/storage/persistent-volumes/#capacity) | | persistence.storageClassName | string | `nil` | StorageClass to use, leave empty to use default StorageClass. | | podAnnotations | object | `{}` | Additional pod annotations | -| podSecurityContext | object | `{}` | [k8s: Security context](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) | +| podSecurityContext | object | `{"fsGroup":8983,"runAsGroup":8983,"runAsUser":8983}` | [k8s: Security context](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) | | resources | object | `{}` | [k8s: Resource management](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | | securityContext | object | `{}` | [k8s: Security context](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) | | service.port | int | `8983` | Service port for http | diff --git a/charts/sddi-ckan/charts/solr/values.yaml b/charts/sddi-ckan/charts/solr/values.yaml index ecf2a46..49766bb 100644 --- a/charts/sddi-ckan/charts/solr/values.yaml +++ b/charts/sddi-ckan/charts/solr/values.yaml @@ -33,10 +33,10 @@ serviceAccount: name: "" # -- [k8s: Security context](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) -podSecurityContext: {} - # runAsUser: 8983 - # runAsGroup: 8983 - # fsGroup: 8983 +podSecurityContext: + runAsUser: 8983 + runAsGroup: 8983 + fsGroup: 8983 # -- [k8s: Security context](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/) securityContext: {}