85 lines
2.0 KiB
YAML
85 lines
2.0 KiB
YAML
{{- if and (index .Values "alloy-logs").enabled (eq .Values.global.platform "openshift") }}
|
|
{{- $usesHostPathVolumes := (index .Values "alloy-logs").alloy.mounts.varlog }}
|
|
---
|
|
apiVersion: security.openshift.io/v1
|
|
kind: SecurityContextConstraints
|
|
metadata:
|
|
name: {{ include "alloy.fullname" (index .Subcharts "alloy-logs") }}
|
|
allowHostDirVolumePlugin: {{ $usesHostPathVolumes }}
|
|
allowHostIPC: false
|
|
allowHostNetwork: false
|
|
allowHostPID: false
|
|
allowHostPorts: false
|
|
allowPrivilegeEscalation: false
|
|
allowPrivilegedContainer: false
|
|
allowedCapabilities:
|
|
- CHOWN
|
|
- DAC_OVERRIDE
|
|
- FOWNER
|
|
- FSETID
|
|
- KILL
|
|
- SETGID
|
|
- SETUID
|
|
- SETPCAP
|
|
- NET_BIND_SERVICE
|
|
- NET_RAW
|
|
- SYS_CHROOT
|
|
- MKNOD
|
|
- AUDIT_WRITE
|
|
- SETFCAP
|
|
defaultAddCapabilities: null
|
|
defaultAllowPrivilegeEscalation: false
|
|
forbiddenSysctls:
|
|
- '*'
|
|
fsGroup:
|
|
type: RunAsAny
|
|
groups: []
|
|
priority: null
|
|
readOnlyRootFilesystem: false # Set because Grafana Alloy needs to write to /tmp/alloy
|
|
requiredDropCapabilities: null
|
|
runAsUser:
|
|
type: RunAsAny
|
|
seLinuxContext:
|
|
type: RunAsAny
|
|
seccompProfiles:
|
|
- runtime/default
|
|
supplementalGroups:
|
|
type: RunAsAny
|
|
users: []
|
|
volumes:
|
|
- configMap
|
|
- emptyDir
|
|
{{- if $usesHostPathVolumes }}
|
|
- hostPath
|
|
{{- end }}
|
|
- projected
|
|
- secret
|
|
---
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: ClusterRole
|
|
metadata:
|
|
name: {{ include "alloy.fullname" (index .Subcharts "alloy-logs") }}-scc
|
|
rules:
|
|
- verbs:
|
|
- use
|
|
apiGroups:
|
|
- security.openshift.io
|
|
resources:
|
|
- securitycontextconstraints
|
|
resourceNames:
|
|
- {{ include "alloy.fullname" (index .Subcharts "alloy-logs") }}
|
|
---
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: ClusterRoleBinding
|
|
metadata:
|
|
name: {{ include "alloy.fullname" (index .Subcharts "alloy-logs") }}-scc
|
|
roleRef:
|
|
apiGroup: rbac.authorization.k8s.io
|
|
kind: ClusterRole
|
|
name: {{ include "alloy.fullname" (index .Subcharts "alloy-logs") }}-scc
|
|
subjects:
|
|
- kind: ServiceAccount
|
|
name: {{ include "alloy.fullname" (index .Subcharts "alloy-logs") }}
|
|
namespace: {{ .Release.Namespace }}
|
|
{{- end }}
|