Skip to content

Commit

Permalink
[chart] use security context under container level to allow setting a…
Browse files Browse the repository at this point in the history
…dditional permissions
  • Loading branch information
atoulme committed Feb 3, 2025
1 parent 56f18c7 commit 4453e8b
Show file tree
Hide file tree
Showing 37 changed files with 336 additions and 10 deletions.
12 changes: 12 additions & 0 deletions .chloggen/movesecuritycontexttocontainers.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# One of 'breaking', 'deprecation', 'new_component', 'enhancement', 'bug_fix'
change_type: enhancement
# The name of the component, or a single word describing the area of concern, (e.g. agent, clusterReceiver, gateway, operator, chart, other)
component: chart
# A brief description of the change. Surround your text with quotes ("") if it needs to start with a backtick (`).
note: use security context under container level to allow setting additional permissions
# One or more tracking issues related to the change
issues: []
# (Optional) One or more lines of additional information to render under the primary note.
# These lines will be padded with 2 spaces and then inserted directly into the document.
# Use pipe (|) for multiline entries.
subtext:
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "8192"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "4096"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,15 @@ spec:
- --config=/splunk-messages/config.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "8192"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,15 @@ spec:
- --config=/conf/relay.yaml
image: quay.io/signalfx/splunk-otel-collector:0.117.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsGroup: 20000
runAsNonRoot: true
runAsUser: 20000
env:
- name: SPLUNK_MEMORY_TOTAL_MIB
value: "500"
Expand Down
Loading

0 comments on commit 4453e8b

Please sign in to comment.