Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add helm dependencies to Dockerfile #1457

Merged
merged 3 commits into from
Nov 20, 2023
Merged

Conversation

kovayur
Copy link
Contributor

@kovayur kovayur commented Nov 10, 2023

Description

Fleetshard operator lacks external secrets dependency in the image. The following changes have been added:

  1. Add the external secrets dependency secrets operator can’t work without the external secrets dependency
  2. Delete the default securityContext.runAsUser from the subchart. External secrets operator sets user id as 1000 by default which is prohibited by openshift (without extra scc config). If you delete the key then openshift assigns a user id from a range, so from security perspective it should be better. The null value I set for securityContext.runAsUser in root values.yaml works in helm but not in the operator. Most likely because the older version of helm is used in operator-sdk. I submitted a bug report to operator sdk and made a workaround to remove the default key(s) from the dependency.

Checklist (Definition of Done)

  • Unit and integration tests added
  • Added test description under Test manual
  • Documentation added if necessary (i.e. changes to dev setup, test execution, ...)
  • CI and all relevant tests are passing
  • Add the ticket number to the PR title if available, i.e. ROX-12345: ...
  • Discussed security and business related topics privately. Will move any security and business related topics that arise to private communication channel.
  • Add secret to app-interface Vault or Secrets Manager if necessary
  • RDS changes were e2e tested manually
  • Check AWS limits are reasonable for changes provisioning new resources

Test manual

TODO: Add manual testing efforts

# To run tests locally run:
make db/teardown db/setup db/migrate
make ocm/setup OCM_OFFLINE_TOKEN=<ocm-offline-token> OCM_ENV=development
make verify lint binary test test/integration

Copy link
Contributor

openshift-ci bot commented Nov 20, 2023

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ebensh, kovayur

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kovayur kovayur merged commit b1ab5f2 into main Nov 20, 2023
5 checks passed
@kovayur kovayur deleted the yury/helm-install-dependencies branch November 20, 2023 10:01
johannes94 pushed a commit that referenced this pull request Jan 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants