Skip to content
Snippets Groups Projects
Commit 6cea8da1 authored by Marc Burnie [AWS]'s avatar Marc Burnie [AWS]
Browse files

adding support for EKS 1.23

parent efc85621
No related branches found
No related tags found
4 merge requests!438Draft: CG Vulnerability for Woodstox - CVE-2022-40151,!430Upgraded Version of spring-security-config due to Component Governance CVE-2023-34034,!377Renaming dependency helm chart repo to osdu-aws and removing versioning constraints,!360Spring Vulnerabilities
Pipeline #165777 failed
apiVersion: v2
name: "os-legal"
version: __CHART_VERSION__
kubeVersion: "v1.21.x-x-x"
kubeVersion: ">= 1.21.x-x-x < 1.24.x-x-x"
description: Legal Helm Chart for Kubernetes
type: application
appVersion: __VERSION__
dependencies:
- name: osdu-aws-lib
version: 0.1.0
version: 0.2.0
repository: __HELM_REPO__/osdu-aws-lib/
deprecated: false
apiVersion: v1
kind: Pod
metadata:
name: "{{ include "common.fullname" . }}-test-connection"
labels:
{{- include "common.labels" . | nindent 4 }}
annotations:
"helm.sh/hook": test
spec:
containers:
- name: wget
image: busybox
command: ['wget']
args: ['{{ include "common.fullname" . }}:{{ .Values.service.port }}']
restartPolicy: Never
......@@ -6,10 +6,8 @@
"image",
"imagePullPolicy",
"service",
"podAnnotations",
"replicaCount",
"serviceAccountRole",
"securityContext"
"serviceAccountRole"
],
"properties": {
"image": {
......@@ -262,7 +260,7 @@
"type": "string",
"title": "Allowed principal",
"examples": [
"cluster.local/ns/istio-system/sa/istio-ingressgateway-service-account",
"cluster.local/ns/istio-system/sa/istio-ingressgateway",
"cluster.local/ns/osdu-services/sa/compliance-queue"
]
}
......
......@@ -61,8 +61,6 @@ environmentVariables:
value: "true"
- name: MONGODB_ENABLE_TLS
value: "false"
podAnnotations:
seccomp.security.alpha.kubernetes.io/pod: "runtime/default"
# Resource Config
maxConnections: 200
......@@ -104,9 +102,13 @@ securityContext:
capabilities:
drop:
- ALL
podSecurityContext:
fsGroup: 1337
seccompProfile:
type: RuntimeDefault
allowedPrincipals:
- cluster.local/ns/istio-system/sa/istio-ingressgateway-service-account
- cluster.local/ns/istio-system/sa/istio-ingressgateway
- cluster.local/ns/{{ .Release.Namespace }}/sa/compliance-queue-trigger
- cluster.local/ns/{{ .Release.Namespace }}/sa/os-policy
- cluster.local/ns/{{ .Release.Namespace }}/sa/opa-agent
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment