Skip to content

Commit

Permalink
Do not run placement service as root
Browse files Browse the repository at this point in the history
  • Loading branch information
gibizer committed Nov 16, 2023
1 parent c45baee commit 9bdfd76
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 14 deletions.
9 changes: 2 additions & 7 deletions pkg/placement/dbsync.go
Original file line number Diff line number Diff line change
Expand Up @@ -37,8 +37,6 @@ func DbSyncJob(
labels map[string]string,
annotations map[string]string,
) *batchv1.Job {
runAsUser := int64(0)

args := []string{"-c"}
if instance.Spec.Debug.DBSync {
args = append(args, common.DebugCommand)
Expand Down Expand Up @@ -70,11 +68,8 @@ func DbSyncJob(
Command: []string{
"/bin/bash",
},
Args: args,
Image: instance.Spec.ContainerImage,
SecurityContext: &corev1.SecurityContext{
RunAsUser: &runAsUser,
},
Args: args,
Image: instance.Spec.ContainerImage,
Env: env.MergeEnvs([]corev1.EnvVar{}, envVars),
VolumeMounts: getVolumeMounts(),
},
Expand Down
9 changes: 2 additions & 7 deletions pkg/placement/deployment.go
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,6 @@ func Deployment(
labels map[string]string,
annotations map[string]string,
) *appsv1.Deployment {
runAsUser := int64(0)

livenessProbe := &corev1.Probe{
// TODO might need tuning
TimeoutSeconds: 5,
Expand Down Expand Up @@ -109,11 +107,8 @@ func Deployment(
Command: []string{
"/bin/bash",
},
Args: args,
Image: instance.Spec.ContainerImage,
SecurityContext: &corev1.SecurityContext{
RunAsUser: &runAsUser,
},
Args: args,
Image: instance.Spec.ContainerImage,
Env: env.MergeEnvs([]corev1.EnvVar{}, envVars),
VolumeMounts: getVolumeMounts(),
Resources: instance.Spec.Resources,
Expand Down

0 comments on commit 9bdfd76

Please sign in to comment.