{{- if and (index .Values "alloy-profiles").enabled (eq .Values.global.platform "openshift") }} --- apiVersion: security.openshift.io/v1 kind: SecurityContextConstraints metadata: name: {{ include "alloy.fullname" (index .Subcharts "alloy-profiles") }} allowHostDirVolumePlugin: false allowHostIPC: false allowHostNetwork: false allowHostPID: true allowHostPorts: false allowPrivilegeEscalation: true allowPrivilegedContainer: true allowedCapabilities: - CHOWN - DAC_OVERRIDE - FOWNER - FSETID - KILL - SETGID - SETUID - SETPCAP - NET_BIND_SERVICE - NET_RAW - SYS_CHROOT - MKNOD - AUDIT_WRITE - SETFCAP defaultAddCapabilities: null defaultAllowPrivilegeEscalation: false forbiddenSysctls: - '*' fsGroup: type: RunAsAny groups: [] priority: null readOnlyRootFilesystem: false # Set because Grafana Alloy needs to write to /tmp/alloy requiredDropCapabilities: null runAsUser: type: RunAsAny seLinuxContext: type: RunAsAny seccompProfiles: - runtime/default supplementalGroups: type: RunAsAny users: [] volumes: - configMap - emptyDir - projected - secret --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: {{ include "alloy.fullname" (index .Subcharts "alloy-profiles") }}-scc rules: - verbs: - use apiGroups: - security.openshift.io resources: - securitycontextconstraints resourceNames: - {{ include "alloy.fullname" (index .Subcharts "alloy-profiles") }} --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: {{ include "alloy.fullname" (index .Subcharts "alloy-profiles") }}-scc roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: {{ include "alloy.fullname" (index .Subcharts "alloy-profiles") }}-scc subjects: - kind: ServiceAccount name: {{ include "alloy.fullname" (index .Subcharts "alloy-profiles") }} namespace: {{ .Release.Namespace }} {{- end }}