Skip to content

Commit 8ea3323

Browse files
Merge pull request #20 from mfojtik/add-locking-2
fix selinux errors in lock dirs
2 parents 57e4a3e + af64106 commit 8ea3323

File tree

2 files changed

+5
-2
lines changed

2 files changed

+5
-2
lines changed

bindata/bootkube/bootstrap-manifests/kube-controller-manager-pod.yaml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,6 @@ spec:
1313
hostNetwork: true
1414
securityContext:
1515
supplementalGroups: [65534]
16-
privileged: true
1716
initContainers:
1817
- name: setup-lock-dir
1918
image: {{ .Image }}
@@ -32,6 +31,10 @@ spec:
3231
name: var-lock
3332
containers:
3433
- name: kube-controller-manager
34+
securityContext:
35+
runAsNonRoot: true
36+
runAsUser: 65534
37+
privileged: true
3538
image: {{ .Image }}
3639
imagePullPolicy: {{ .ImagePullPolicy }}
3740
command: ["/usr/bin/flock", "--exclusive", "--timeout=60", "/var/lock/controller-manager.lock", "-c"]

bindata/bootkube/manifests/kube-controller-manager-daemonset.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ spec:
3131
imagePullPolicy: {{ .ImagePullPolicy }}
3232
command: ["/usr/bin/flock", "--exclusive", "--timeout=60", "/var/lock/controller-manager.lock", "-c"]
3333
args:
34-
- exec hyperkube kube-controller-manager --openshift-config=/etc/kubernetes/config/{{ .ConfigFileName }} --kubeconfig=/etc/kubernetes/secrets/kubeconfig --master=https://kubernetes.default.svc
34+
- exec hyperkube kube-controller-manager --openshift-config=/etc/kubernetes/config/{{ .ConfigFileName }} --kubeconfig=/etc/kubernetes/secrets/kubeconfig
3535
securityContext:
3636
runAsNonRoot: true
3737
runAsUser: 65534

0 commit comments

Comments
 (0)