Skip to content

Commit 0f44d42

Browse files
committed
Set readOnlyRootFilesystem for deployments to true
Signed-off-by: David Kwon <[email protected]>
1 parent b61eaed commit 0f44d42

File tree

7 files changed

+15
-0
lines changed

7 files changed

+15
-0
lines changed

deploy/bundle/manifests/devworkspace-operator.clusterserviceversion.yaml

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

deploy/deployment/kubernetes/combined.yaml

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

deploy/deployment/kubernetes/objects/devworkspace-controller-manager.Deployment.yaml

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

deploy/deployment/openshift/combined.yaml

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

deploy/deployment/openshift/objects/devworkspace-controller-manager.Deployment.yaml

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

deploy/templates/components/manager/manager.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -51,6 +51,8 @@ spec:
5151
requests:
5252
cpu: 250m
5353
memory: 100Mi
54+
securityContext:
55+
readOnlyRootFilesystem: true
5456
env:
5557
- name: WATCH_NAMESPACE
5658
value: ""

pkg/webhook/deployment.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -187,6 +187,9 @@ func getSpecDeployment(webhooksSecretName, namespace string) (*appsv1.Deployment
187187
Name: "WATCH_NAMESPACE",
188188
},
189189
},
190+
SecurityContext: &corev1.SecurityContext{
191+
ReadOnlyRootFilesystem: pointer.Bool(true),
192+
},
190193
},
191194
},
192195
RestartPolicy: "Always",

0 commit comments

Comments
 (0)