[kube-state-metrics] Allows to run as non-root with runAsUser: nobody security context

Bug #1906303 reported by Jorge Niedbalski
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
CDK Addons
Fix Released
Medium
Jorge Niedbalski

Bug Description

[Version]

Charmed-kubernetes 1.18/1.19, with cdk-addons 1.18.10

[Description]

In order to allow PSP policies, a security context needs to be added to the example deployment.

This has been merged upstream here: https://github.com/kubernetes/kube-state-metrics/issues/1031

An example policy would be: https://pastebin.ubuntu.com/p/xT7ZwsPgPH/

[Upstream references]

* https://github.com/kubernetes/kube-state-metrics/issues/1031
* https://github.com/kubernetes/kube-state-metrics/pull/1034/commits/7977a4af0460e61e03e2d2debe3100a321e57715

[Required]

* Please backport the mentioned patches into 1.18/stable and 1.19

Revision history for this message
Jorge Niedbalski (niedbalski) wrote :
Changed in cdk-addons:
assignee: nobody → Jorge Niedbalski (niedbalski)
status: New → In Progress
George Kraft (cynerva)
tags: added: review-needed
Changed in cdk-addons:
importance: Undecided → Medium
George Kraft (cynerva)
Changed in cdk-addons:
milestone: none → 1.20+ck1
Revision history for this message
George Kraft (cynerva) wrote :

This will need to be backported to release-1.20, release-1.19, and release-1.18.

Changed in cdk-addons:
status: In Progress → Fix Committed
tags: added: backport-needed
removed: review-needed
Revision history for this message
George Kraft (cynerva) wrote :
tags: removed: backport-needed
Changed in cdk-addons:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.