Skip to content
Snippets Groups Projects
Commit fa6edace authored by Marc Burnie [AWS]'s avatar Marc Burnie [AWS]
Browse files

adding support for EKS 1.23

parent b4f0d36b
No related branches found
No related tags found
1 merge request!448Adding support for EKS 1.23
Pipeline #165781 failed
apiVersion: v2
name: "os-schema"
version: __CHART_VERSION__
kubeVersion: "v1.21.x-x-x"
kubeVersion: ">= 1.21.x-x-x < 1.24.x-x-x"
description: Schema Helm Chart for Kubernetes
type: application
appVersion: __VERSION__
dependencies:
- name: osdu-aws-lib
version: 0.1.0
version: 0.2.0
repository: __HELM_REPO__/osdu-aws-lib/
deprecated: false
apiVersion: v1
kind: Pod
metadata:
name: "{{ include "common.fullname" . }}-test-connection"
labels:
{{- include "common.labels" . | nindent 4 }}
annotations:
"helm.sh/hook": test
spec:
containers:
- name: wget
image: busybox
command: ['wget']
args: ['{{ include "common.fullname" . }}:{{ .Values.service.port }}']
restartPolicy: Never
......@@ -6,10 +6,8 @@
"image",
"imagePullPolicy",
"service",
"podAnnotations",
"replicaCount",
"serviceAccountRole",
"securityContext"
"serviceAccountRole"
],
"properties": {
"image": {
......@@ -262,7 +260,7 @@
"type": "string",
"title": "Allowed principal",
"examples": [
"cluster.local/ns/istio-system/sa/istio-ingressgateway-service-account",
"cluster.local/ns/istio-system/sa/istio-ingressgateway",
"cluster.local/ns/osdu-services/sa/compliance-queue"
]
}
......
......@@ -26,8 +26,6 @@ environmentVariables:
value: "http://os-entitlements:8080"
- name: PARTITION_BASE_URL
value: http://os-partition:8080
podAnnotations:
seccomp.security.alpha.kubernetes.io/pod: "runtime/default"
# Resource Config
replicaCount: 1
......@@ -66,9 +64,13 @@ securityContext:
capabilities:
drop:
- ALL
podSecurityContext:
fsGroup: 1337
seccompProfile:
type: RuntimeDefault
allowedPrincipals:
- cluster.local/ns/istio-system/sa/istio-ingressgateway-service-account
- cluster.local/ns/istio-system/sa/istio-ingressgateway
- cluster.local/ns/{{ .Release.Namespace }}/sa/os-dataset
- cluster.local/ns/{{ .Release.Namespace }}/sa/os-indexer
- cluster.local/ns/os-timeseries-dms/sa/os-timeseries-dms
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment