diff --git a/devops/aws/chart/Chart.yaml b/devops/aws/chart/Chart.yaml index ab059d183b540705a84b1c0f395bf68d68ac20ec..851a59075fc508cefb09fde4ff3005461d0da644 100644 --- a/devops/aws/chart/Chart.yaml +++ b/devops/aws/chart/Chart.yaml @@ -1,12 +1,12 @@ apiVersion: v2 name: "os-notification" version: __CHART_VERSION__ -kubeVersion: "v1.21.x-x-x" +kubeVersion: ">= 1.21.x-x-x < 1.24.x-x-x" description: Notification Helm Chart for Kubernetes type: application appVersion: __VERSION__ dependencies: - name: osdu-aws-lib - version: 0.1.0 + version: 0.2.0 repository: __HELM_REPO__/osdu-aws-lib/ deprecated: false diff --git a/devops/aws/chart/templates/tests/test-connection.yaml b/devops/aws/chart/templates/tests/test-connection.yaml deleted file mode 100644 index f341212ea253eced15fd153dd894287341d8db93..0000000000000000000000000000000000000000 --- a/devops/aws/chart/templates/tests/test-connection.yaml +++ /dev/null @@ -1,15 +0,0 @@ -apiVersion: v1 -kind: Pod -metadata: - name: "{{ include "common.fullname" . }}-test-connection" - labels: - {{- include "common.labels" . | nindent 4 }} - annotations: - "helm.sh/hook": test -spec: - containers: - - name: wget - image: busybox - command: ['wget'] - args: ['{{ include "common.fullname" . }}:{{ .Values.service.port }}'] - restartPolicy: Never diff --git a/devops/aws/chart/values.schema.json b/devops/aws/chart/values.schema.json index c3bc0eb63c7dbdc49322be085c6a65f1be4938b7..56b4ef3ad17e31807c9528dcda46a3c52acf69ae 100644 --- a/devops/aws/chart/values.schema.json +++ b/devops/aws/chart/values.schema.json @@ -6,10 +6,8 @@ "image", "imagePullPolicy", "service", - "podAnnotations", "replicaCount", - "serviceAccountRole", - "securityContext" + "serviceAccountRole" ], "properties": { "image": { @@ -262,7 +260,7 @@ "type": "string", "title": "Allowed principal", "examples": [ - "cluster.local/ns/istio-system/sa/istio-ingressgateway-service-account", + "cluster.local/ns/istio-system/sa/istio-ingressgateway", "cluster.local/ns/osdu-services/sa/compliance-queue" ] } diff --git a/devops/aws/chart/values.yaml b/devops/aws/chart/values.yaml index b5242dd0fd63c0e1571dfaf1561d09f119c71ef3..a8b091f4aa5ecbb5223c37ae940532020b22a75c 100644 --- a/devops/aws/chart/values.yaml +++ b/devops/aws/chart/values.yaml @@ -27,8 +27,6 @@ environmentVariables: value: "http://os-entitlements:8080" - name: REGISTER_BASE_URL value: http://os-register:8080 -podAnnotations: - seccomp.security.alpha.kubernetes.io/pod: "runtime/default" # Resource Config replicaCount: 1 @@ -69,9 +67,13 @@ securityContext: capabilities: drop: - ALL +podSecurityContext: + fsGroup: 1337 + seccompProfile: + type: RuntimeDefault allowedPrincipals: - - cluster.local/ns/istio-system/sa/istio-ingressgateway-service-account + - cluster.local/ns/istio-system/sa/istio-ingressgateway - cluster.local/ns/aws-binary-dms/sa/binary-dms - cluster.local/ns/osdu-airflow/sa/airflow-dag-upload - cluster.local/ns/osdu-ingest/sa/os-data-workflow