Allow passthrough of securityContext.readOnlyRootFilesystem in Helm chart - #43332
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
WalkthroughThe changes make the 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@tnichols89 Thanks for your contribution! I've just merged the change in. Additionally, I'm going to work on getting the changes referenced in the issue into place as well as bump the Chart version |
|
Thank you so much! @BCTBB |
Issue
Closes #43330
Description
This PR allows self-hosted, Kubernetes-based Fleet users to configure
securityContext.readOnlyRootFilesysteminvalues.yaml, which is then propagated down to thedeployment.yamltemplate.This change provides a convenient mechanism for users to fix a known issue while preserving the current default behavior.
Testing
The underlying
deployment.yamlchange has been tested in a standard Google Kubernetes Engine cluster, and is confirmed to fix the linked issue when using either Ubuntu-based or Container-Optimized OS (COS)-basedcontainerdcontainer runtimes in GKE.Summary by CodeRabbit
Release Notes