Grafana: Add pod security context for grafana user

This updates the Grafana chart to include the pod security context
on the grafana pod. This changes the pod's user from root to the
grafana user instead

Change-Id: Id64853640f1941001b83566865defe93227b4291
This commit is contained in:
Steve Wilkerson 2019-01-03 12:42:52 -06:00
parent 8dba8cb648
commit 680f920312
2 changed files with 4 additions and 0 deletions

View File

@ -44,6 +44,7 @@ spec:
configmap-bin-hash: {{ tuple "configmap-bin.yaml" . | include "helm-toolkit.utils.hash" }}
configmap-etc-hash: {{ tuple "configmap-etc.yaml" . | include "helm-toolkit.utils.hash" }}
spec:
{{ dict "envAll" $envAll "application" "grafana" | include "helm-toolkit.snippets.kubernetes_pod_security_context" | indent 6 }}
serviceAccountName: {{ $serviceAccountName }}
nodeSelector:
{{ .Values.labels.grafana.node_selector_key }}: {{ .Values.labels.grafana.node_selector_value | quote }}

View File

@ -43,6 +43,9 @@ labels:
node_selector_value: enabled
pod:
user:
grafana:
uid: 104
affinity:
anti:
type: