* SELinux support Add support to the chart to set the SELinux context to enable a working system. Enable it by default on OpenShift clusters. Signed-off-by: Kevin Fox <[email protected]> * Incorperate feedback Signed-off-by: Kevin Fox <[email protected]> --------- Signed-off-by: Kevin Fox <[email protected]>
67 lines
1.6 KiB
YAML
67 lines
1.6 KiB
YAML
global:
|
|
openshift: true
|
|
telemetry:
|
|
prometheus:
|
|
enabled: true
|
|
spire:
|
|
namespaces:
|
|
system:
|
|
labels:
|
|
security.openshift.io/scc.podSecurityLabelSync: "false"
|
|
pod-security.kubernetes.io/enforce: privileged
|
|
pod-security.kubernetes.io/warn: privileged
|
|
pod-security.kubernetes.io/audit: privileged
|
|
server:
|
|
labels:
|
|
security.openshift.io/scc.podSecurityLabelSync: "false"
|
|
pod-security.kubernetes.io/enforce: privileged
|
|
pod-security.kubernetes.io/warn: privileged
|
|
pod-security.kubernetes.io/audit: privileged
|
|
|
|
spire-server:
|
|
tornjak:
|
|
image:
|
|
registry: ghcr.io
|
|
repository: spiffe/tornjak-backend
|
|
tag: ubi-v1.4.1
|
|
nodeAttestor:
|
|
k8sPsat:
|
|
serviceAccountAllowList: ["spire-system:spire-agent"]
|
|
notifier:
|
|
k8sbundle:
|
|
namespace: spire-system
|
|
podSecurityContext:
|
|
# These are unset so that openshift can automatically assign its own restricted uids to the pods
|
|
runAsUser: null
|
|
runAsGroup: null
|
|
fsGroup: null
|
|
|
|
spire-agent:
|
|
podSecurityContext:
|
|
runAsUser: null
|
|
runAsGroup: null
|
|
fsGroup: null
|
|
|
|
upstream-spire-agent:
|
|
podSecurityContext:
|
|
runAsUser: null
|
|
runAsGroup: null
|
|
fsGroup: null
|
|
|
|
spiffe-oidc-discovery-provider:
|
|
podSecurityContext:
|
|
runAsUser: null
|
|
runAsGroup: null
|
|
fsGroup: null
|
|
|
|
tornjak-frontend:
|
|
workingDir: /opt/app-root/src
|
|
image:
|
|
registry: ghcr.io
|
|
repository: spiffe/tornjak-frontend
|
|
tag: ubi-v1.4.1
|
|
podSecurityContext:
|
|
runAsUser: null
|
|
runAsGroup: null
|
|
fsGroup: null
|