Skip to content
Snippets Groups Projects
Commit 1f873c4f authored by Marc Burnie [AWS]'s avatar Marc Burnie [AWS]
Browse files

adding support for EKS 1.23

parent e901feed
No related branches found
No related tags found
1 merge request!346Adding support for EKS 1.23
Pipeline #165779 failed
apiVersion: v2 apiVersion: v2
name: os-partition name: os-partition
version: __CHART_VERSION__ version: __CHART_VERSION__
kubeVersion: "v1.21.x-x-x" kubeVersion: ">= 1.21.x-x-x < 1.24.x-x-x"
description: Partitions Helm chart for Kubernetes description: Partitions Helm chart for Kubernetes
type: application type: application
appVersion: __VERSION__ appVersion: __VERSION__
dependencies: dependencies:
- name: osdu-aws-lib - name: osdu-aws-lib
version: 0.1.0 version: 0.2.0
repository: __HELM_REPO__/osdu-aws-lib/ repository: __HELM_REPO__/osdu-aws-lib/
deprecated: false deprecated: false
apiVersion: v1
kind: Pod
metadata:
name: "{{ include "common.fullname" . }}-test-connection"
labels:
{{- include "common.labels" . | nindent 4 }}
annotations:
"helm.sh/hook": test
spec:
containers:
- name: wget
image: busybox
command: ['wget']
args: ['{{ include "common.fullname" . }}:{{ .Values.service.port }}']
restartPolicy: Never
...@@ -6,10 +6,8 @@ ...@@ -6,10 +6,8 @@
"image", "image",
"imagePullPolicy", "imagePullPolicy",
"service", "service",
"podAnnotations",
"replicaCount", "replicaCount",
"serviceAccountRole", "serviceAccountRole"
"securityContext"
], ],
"properties": { "properties": {
"image": { "image": {
...@@ -262,10 +260,10 @@ ...@@ -262,10 +260,10 @@
"type": "string", "type": "string",
"title": "Allowed principal", "title": "Allowed principal",
"examples": [ "examples": [
"cluster.local/ns/istio-system/sa/istio-ingressgateway-service-account", "cluster.local/ns/istio-system/sa/istio-ingressgateway",
"cluster.local/ns/osdu-services/sa/compliance-queue" "cluster.local/ns/osdu-services/sa/compliance-queue"
] ]
} }
} }
} }
} }
\ No newline at end of file
...@@ -61,8 +61,6 @@ environmentVariables: ...@@ -61,8 +61,6 @@ environmentVariables:
value: "true" value: "true"
- name: MONGODB_ENABLE_TLS - name: MONGODB_ENABLE_TLS
value: "false" value: "false"
podAnnotations:
seccomp.security.alpha.kubernetes.io/pod: "runtime/default"
# Resource Config # Resource Config
replicaCount: 1 replicaCount: 1
...@@ -101,9 +99,13 @@ securityContext: ...@@ -101,9 +99,13 @@ securityContext:
capabilities: capabilities:
drop: drop:
- ALL - ALL
podSecurityContext:
fsGroup: 1337
seccompProfile:
type: RuntimeDefault
allowedPrincipals: allowedPrincipals:
- cluster.local/ns/istio-system/sa/istio-ingressgateway-service-account - cluster.local/ns/istio-system/sa/istio-ingressgateway
- cluster.local/ns/{{ .Release.Namespace }}/sa/compliance-queue - cluster.local/ns/{{ .Release.Namespace }}/sa/compliance-queue
- cluster.local/ns/{{ .Release.Namespace }}/sa/compliance-queue-trigger - cluster.local/ns/{{ .Release.Namespace }}/sa/compliance-queue-trigger
- cluster.local/ns/{{ .Release.Namespace }}/sa/indexer-queue - cluster.local/ns/{{ .Release.Namespace }}/sa/indexer-queue
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment