Commit ea99edba authored by William Tucker's avatar William Tucker
Browse files

Reordered securityContext values for clarity

parent c921b215
Loading
Loading
Loading
Loading
+20 −20
Original line number Diff line number Diff line
@@ -117,14 +117,14 @@ auth:
          scope: openid profile email
  # Security context for auth container.
  securityContext:
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL
    # Run with a read-only root filesystem by default
    readOnlyRootFilesystem: true
    # The containers will run as the ESGF user by default
    runAsNonRoot: true
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL

###
# OPA server configuration
@@ -165,14 +165,14 @@ opa:
  restrictedPaths: []
  # Security context for OPA container.
  securityContext:
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL
    # Run with a read-only root filesystem by default
    readOnlyRootFilesystem: true
    # The containers will run as the ESGF user by default
    runAsNonRoot: true
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL

###
# Data node configuration
@@ -225,14 +225,14 @@ data:
    runAsGroup: 1000
    fsGroup: 1000
  securityContext:
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL
    # Run with a read-only root filesystem by default
    readOnlyRootFilesystem: true
    # The containers will run as the ESGF user by default
    runAsNonRoot: true
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL

  # Configuration for the access log sidecar
  accessLogSidecar:
@@ -404,14 +404,14 @@ index:
      fsGroup: 1000
    # The container security context for all Solr containers
    securityContext:
      allowPrivilegeEscalation: false
      capabilities:
        drop:
          - ALL
      # Run with a read-only root filesystem by default
      readOnlyRootFilesystem: true
      # The containers will run as the ESGF user by default
      runAsNonRoot: true
      allowPrivilegeEscalation: false
      capabilities:
        drop:
          - ALL
    # The default resource allocations for all Solr containers
    # Can be overridden on a per-shard basis
    # See https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
@@ -509,11 +509,11 @@ index:
  # Security context for search container.

    securityContext:
      allowPrivilegeEscalation: false
      capabilities:
        drop:
          - ALL
      # Run with a read-only root filesystem by default
      readOnlyRootFilesystem: true
      # The containers will run as the ESGF user by default
      runAsNonRoot: true
      allowPrivilegeEscalation: false
      capabilities:
        drop:
          - ALL