File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -32,10 +32,27 @@ spec:
3232 {{- end }}
3333 nodeSelector :
3434 {{- toYaml .Values.operator.nodeSelector | nindent 8 }}
35+ {{- with .Values.operator.securityContext }}
36+ securityContext :
37+ {{- toYaml . | nindent 8 }}
38+ {{- end }}
39+ {{- if .Values.operator.dnsPolicy }}
40+ dnsPolicy : {{ .Values.operator.dnsPolicy }}
41+ {{- end }}
42+ {{- with .Values.operator.dnsConfig }}
43+ dnsConfig :
44+ {{- toYaml . | nindent 8 }}
45+ {{- end }}
3546 containers :
3647 - name : cleanup-crd
3748 image : {{ include "gpu-operator.fullimage" . }}
3849 imagePullPolicy : {{ .Values.operator.imagePullPolicy }}
50+ securityContext :
51+ allowPrivilegeEscalation : false
52+ readOnlyRootFilesystem : true
53+ capabilities :
54+ drop :
55+ - ALL
3956 command :
4057 - /usr/bin/manage-crds
4158 args :
Original file line number Diff line number Diff line change @@ -37,10 +37,27 @@ spec:
3737 {{- end }}
3838 nodeSelector :
3939 {{- toYaml .Values.operator.nodeSelector | nindent 8 }}
40+ {{- with .Values.operator.securityContext }}
41+ securityContext :
42+ {{- toYaml . | nindent 8 }}
43+ {{- end }}
44+ {{- if .Values.operator.dnsPolicy }}
45+ dnsPolicy : {{ .Values.operator.dnsPolicy }}
46+ {{- end }}
47+ {{- with .Values.operator.dnsConfig }}
48+ dnsConfig :
49+ {{- toYaml . | nindent 8 }}
50+ {{- end }}
4051 containers :
4152 - name : cleanup-gpucluster
4253 image : {{ include "gpu-operator.fullimage" . }}
4354 imagePullPolicy : {{ .Values.operator.imagePullPolicy }}
55+ securityContext :
56+ allowPrivilegeEscalation : false
57+ readOnlyRootFilesystem : true
58+ capabilities :
59+ drop :
60+ - ALL
4461 command :
4562 - /usr/bin/cleanup-gpuclusters
4663 - --gpucluster-name
Original file line number Diff line number Diff line change 3333 {{- if .Values.operator.priorityClassName }}
3434 priorityClassName : {{ .Values.operator.priorityClassName }}
3535 {{- end }}
36+ {{- with .Values.operator.securityContext }}
37+ securityContext :
38+ {{- toYaml . | nindent 8 }}
39+ {{- end }}
40+ {{- if .Values.operator.dnsPolicy }}
41+ dnsPolicy : {{ .Values.operator.dnsPolicy }}
42+ {{- end }}
43+ {{- with .Values.operator.dnsConfig }}
44+ dnsConfig :
45+ {{- toYaml . | nindent 8 }}
46+ {{- end }}
3647 containers :
3748 - name : gpu-operator
3849 image : {{ include "gpu-operator.fullimage" . }}
8394 resources :
8495 {{- toYaml . | nindent 10 }}
8596 {{- end }}
97+ securityContext :
98+ allowPrivilegeEscalation : false
99+ readOnlyRootFilesystem : true
100+ capabilities :
101+ drop :
102+ - ALL
86103 ports :
87104 - name : metrics
88105 containerPort : 8080
Original file line number Diff line number Diff line change @@ -81,10 +81,27 @@ spec:
8181 {{- end }}
8282 nodeSelector :
8383 {{- toYaml .Values.operator.nodeSelector | nindent 8 }}
84+ {{- with .Values.operator.securityContext }}
85+ securityContext :
86+ {{- toYaml . | nindent 8 }}
87+ {{- end }}
88+ {{- if .Values.operator.dnsPolicy }}
89+ dnsPolicy : {{ .Values.operator.dnsPolicy }}
90+ {{- end }}
91+ {{- with .Values.operator.dnsConfig }}
92+ dnsConfig :
93+ {{- toYaml . | nindent 8 }}
94+ {{- end }}
8495 containers :
8596 - name : upgrade-crd
8697 image : {{ include "gpu-operator.fullimage" . }}
8798 imagePullPolicy : {{ .Values.operator.imagePullPolicy }}
99+ securityContext :
100+ allowPrivilegeEscalation : false
101+ readOnlyRootFilesystem : true
102+ capabilities :
103+ drop :
104+ - ALL
88105 command :
89106 - /usr/bin/manage-crds
90107 args :
Original file line number Diff line number Diff line change @@ -121,6 +121,17 @@ operator:
121121 requests :
122122 cpu : 200m
123123 memory : 100Mi
124+ # Restricted defaults for the operator Deployment (not operand DaemonSets).
125+ # Do not pin runAsUser/runAsGroup/fsGroup: the image already uses USER 1000:1000
126+ # on vanilla Kubernetes, and a hardcoded UID fails OpenShift namespaces whose
127+ # allocated range does not include 1000 (restricted-readonly SCC is MustRunAsRange).
128+ securityContext :
129+ runAsNonRoot : true
130+ seccompProfile :
131+ type : RuntimeDefault
132+ # Empty dnsPolicy keeps the cluster default (ClusterFirst).
133+ dnsPolicy : " "
134+ dnsConfig : {}
124135 # metrics:
125136 # serviceMonitor:
126137 # interval: 15s
You can’t perform that action at this time.
0 commit comments