Skip to content

Commit 3fc63e2

Browse files
authored
Merge pull request #2843 from dundysm/fix/operator-securitycontext
Add configurable securityContext and dnsConfig for the operator Deployment
2 parents 9f85a2a + acf5b99 commit 3fc63e2

5 files changed

Lines changed: 79 additions & 0 deletions

File tree

‎deployments/gpu-operator/templates/cleanup_crd.yaml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,10 +32,27 @@ spec:
3232
{{- end }}
3333
nodeSelector:
3434
{{- toYaml .Values.operator.nodeSelector | nindent 8 }}
35+
{{- with .Values.operator.securityContext }}
36+
securityContext:
37+
{{- toYaml . | nindent 8 }}
38+
{{- end }}
39+
{{- if .Values.operator.dnsPolicy }}
40+
dnsPolicy: {{ .Values.operator.dnsPolicy }}
41+
{{- end }}
42+
{{- with .Values.operator.dnsConfig }}
43+
dnsConfig:
44+
{{- toYaml . | nindent 8 }}
45+
{{- end }}
3546
containers:
3647
- name: cleanup-crd
3748
image: {{ include "gpu-operator.fullimage" . }}
3849
imagePullPolicy: {{ .Values.operator.imagePullPolicy }}
50+
securityContext:
51+
allowPrivilegeEscalation: false
52+
readOnlyRootFilesystem: true
53+
capabilities:
54+
drop:
55+
- ALL
3956
command:
4057
- /usr/bin/manage-crds
4158
args:

‎deployments/gpu-operator/templates/cleanup_gpucluster.yaml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,10 +37,27 @@ spec:
3737
{{- end }}
3838
nodeSelector:
3939
{{- toYaml .Values.operator.nodeSelector | nindent 8 }}
40+
{{- with .Values.operator.securityContext }}
41+
securityContext:
42+
{{- toYaml . | nindent 8 }}
43+
{{- end }}
44+
{{- if .Values.operator.dnsPolicy }}
45+
dnsPolicy: {{ .Values.operator.dnsPolicy }}
46+
{{- end }}
47+
{{- with .Values.operator.dnsConfig }}
48+
dnsConfig:
49+
{{- toYaml . | nindent 8 }}
50+
{{- end }}
4051
containers:
4152
- name: cleanup-gpucluster
4253
image: {{ include "gpu-operator.fullimage" . }}
4354
imagePullPolicy: {{ .Values.operator.imagePullPolicy }}
55+
securityContext:
56+
allowPrivilegeEscalation: false
57+
readOnlyRootFilesystem: true
58+
capabilities:
59+
drop:
60+
- ALL
4461
command:
4562
- /usr/bin/cleanup-gpuclusters
4663
- --gpucluster-name

‎deployments/gpu-operator/templates/operator.yaml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,17 @@ spec:
3333
{{- if .Values.operator.priorityClassName }}
3434
priorityClassName: {{ .Values.operator.priorityClassName }}
3535
{{- end }}
36+
{{- with .Values.operator.securityContext }}
37+
securityContext:
38+
{{- toYaml . | nindent 8 }}
39+
{{- end }}
40+
{{- if .Values.operator.dnsPolicy }}
41+
dnsPolicy: {{ .Values.operator.dnsPolicy }}
42+
{{- end }}
43+
{{- with .Values.operator.dnsConfig }}
44+
dnsConfig:
45+
{{- toYaml . | nindent 8 }}
46+
{{- end }}
3647
containers:
3748
- name: gpu-operator
3849
image: {{ include "gpu-operator.fullimage" . }}
@@ -83,6 +94,12 @@ spec:
8394
resources:
8495
{{- toYaml . | nindent 10 }}
8596
{{- end }}
97+
securityContext:
98+
allowPrivilegeEscalation: false
99+
readOnlyRootFilesystem: true
100+
capabilities:
101+
drop:
102+
- ALL
86103
ports:
87104
- name: metrics
88105
containerPort: 8080

‎deployments/gpu-operator/templates/upgrade_crd.yaml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -81,10 +81,27 @@ spec:
8181
{{- end }}
8282
nodeSelector:
8383
{{- toYaml .Values.operator.nodeSelector | nindent 8 }}
84+
{{- with .Values.operator.securityContext }}
85+
securityContext:
86+
{{- toYaml . | nindent 8 }}
87+
{{- end }}
88+
{{- if .Values.operator.dnsPolicy }}
89+
dnsPolicy: {{ .Values.operator.dnsPolicy }}
90+
{{- end }}
91+
{{- with .Values.operator.dnsConfig }}
92+
dnsConfig:
93+
{{- toYaml . | nindent 8 }}
94+
{{- end }}
8495
containers:
8596
- name: upgrade-crd
8697
image: {{ include "gpu-operator.fullimage" . }}
8798
imagePullPolicy: {{ .Values.operator.imagePullPolicy }}
99+
securityContext:
100+
allowPrivilegeEscalation: false
101+
readOnlyRootFilesystem: true
102+
capabilities:
103+
drop:
104+
- ALL
88105
command:
89106
- /usr/bin/manage-crds
90107
args:

‎deployments/gpu-operator/values.yaml‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -121,6 +121,17 @@ operator:
121121
requests:
122122
cpu: 200m
123123
memory: 100Mi
124+
# Restricted defaults for the operator Deployment (not operand DaemonSets).
125+
# Do not pin runAsUser/runAsGroup/fsGroup: the image already uses USER 1000:1000
126+
# on vanilla Kubernetes, and a hardcoded UID fails OpenShift namespaces whose
127+
# allocated range does not include 1000 (restricted-readonly SCC is MustRunAsRange).
128+
securityContext:
129+
runAsNonRoot: true
130+
seccompProfile:
131+
type: RuntimeDefault
132+
# Empty dnsPolicy keeps the cluster default (ClusterFirst).
133+
dnsPolicy: ""
134+
dnsConfig: {}
124135
# metrics:
125136
# serviceMonitor:
126137
# interval: 15s

0 commit comments

Comments
 (0)