Skip to content

Commit

Permalink
Merge pull request #37 from GDATASoftwareAG/pod_security_admission_re…
Browse files Browse the repository at this point in the history
…stricted

Pod security admission restricted
  • Loading branch information
doxthree authored Feb 9, 2024
2 parents 43fdb23 + 2872c21 commit bdccd23
Show file tree
Hide file tree
Showing 5 changed files with 43 additions and 22 deletions.
5 changes: 4 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
@@ -1 +1,4 @@
*-local.yaml
*-local.yaml
*-locale.yml
*-locale.yaml
*-local.yml
2 changes: 1 addition & 1 deletion charts/gdscan/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,4 @@ maintainers:
- name: G DATA CyberDefense AG
email: [email protected]
type: application
version: 1.5.1
version: 1.6.0
15 changes: 8 additions & 7 deletions charts/gdscan/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -39,10 +39,8 @@ spec:
emptyDir: {}
- name: scan-socket
emptyDir: {}
{{- if .Values.client.containerSecurityContext.enabled }}
- name: client-tmp
emptyDir: {}
{{- end }}
- name: server-var-log
emptyDir: {}
{{- include "gdscan.imagePullSecrets" . | nindent 6 }}
Expand All @@ -53,6 +51,9 @@ spec:
value: "{{ now | unixEpoch }}"
image: '{{ .Values.server.image.repository }}:{{ .Values.server.image.tag | default "latest" }}'
imagePullPolicy: {{ .Values.server.image.pullPolicy }}
{{- if .Values.server.containerSecurityContext.enabled }}
securityContext: {{- omit .Values.server.containerSecurityContext "enabled" | toYaml | nindent 12 }}
{{- end }}
volumeMounts:
- name: server-tmp
mountPath: /tmp
Expand All @@ -75,10 +76,8 @@ spec:
mountPath: /tmp/scan
- name: scan-socket
mountPath: /var/share/run
{{- if .Values.client.containerSecurityContext.enabled }}
- name: client-tmp
mountPath: /tmp
{{- end }}
resources:
{{- toYaml .Values.resources.client | nindent 12 }}
ports:
Expand All @@ -96,8 +95,8 @@ spec:
path: /health
port: api
initialDelaySeconds: 15
periodSeconds: 5
terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }}
periodSeconds: 5
terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }}
{{- with .Values.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
Expand All @@ -110,4 +109,6 @@ spec:
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- end }}
securityContext:
fsGroup: 1654
{{- end }}
12 changes: 3 additions & 9 deletions charts/gdscan/templates/stateful-set.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -37,14 +37,10 @@ spec:
emptyDir: {}
- name: scan-socket
emptyDir: {}
{{- if .Values.client.containerSecurityContext.enabled }}
- name: client-tmp
emptyDir: {}
{{- end }}
{{- if .Values.server.containerSecurityContext.enabled }}
- name: server-var-log
emptyDir: {}
{{- end }}
containers:
- name: {{ .Values.server.name }}
env:
Expand All @@ -62,10 +58,8 @@ spec:
mountPath: /tmp/scan
- name: scan-socket
mountPath: /var/share/run
{{- if .Values.server.containerSecurityContext.enabled }}
- name: server-var-log
mountPath: /var/log
{{- end }}
resources:
{{- toYaml .Values.resources.server | nindent 12 }}
- name: {{ .Values.client.name }}
Expand All @@ -79,10 +73,8 @@ spec:
mountPath: /tmp/scan
- name: scan-socket
mountPath: /var/share/run
{{- if .Values.client.containerSecurityContext.enabled }}
- name: client-tmp
mountPath: /tmp
{{- end }}
resources:
{{- toYaml .Values.resources.client | nindent 12 }}
ports:
Expand All @@ -101,7 +93,7 @@ spec:
port: api
initialDelaySeconds: 15
periodSeconds: 5
terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }}
terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }}
{{- with .Values.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
Expand All @@ -114,4 +106,6 @@ spec:
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}
securityContext:
fsGroup: 1654
{{- end }}
31 changes: 27 additions & 4 deletions charts/gdscan/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,15 +7,31 @@ server:
pullPolicy: Always
tag: 1
containerSecurityContext:
enabled: false
enabled: true
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
runAsNonRoot: true
capabilities:
drop: ["ALL"]
seccompProfile:
type: RuntimeDefault
runAsGroup: 1001
runAsUser: 1001
client:
name: client
image:
repository: ghcr.io/gdatasoftwareag/vaas/scanclient
pullPolicy: Always
tag: 1
containerSecurityContext:
enabled: false
enabled: true
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
runAsNonRoot: true
capabilities:
drop: ["ALL"]
seccompProfile:
type: RuntimeDefault
terminationGracePeriodSeconds: 30

imagePullSecrets:
Expand Down Expand Up @@ -88,9 +104,16 @@ autoUpdate:
image:
registry: docker.io
repository: bitnami/kubectl
tag: latest
tag: 1.29
containerSecurityContext:
enabled: false
enabled: true
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
runAsNonRoot: true
capabilities:
drop: ["ALL"]
seccompProfile:
type: RuntimeDefault
enabled: true
# every hour
schedule: "0 * * * *"
Expand Down

0 comments on commit bdccd23

Please sign in to comment.