Skip to content

Allow passthrough of securityContext.readOnlyRootFilesystem in Helm chart - #43332

Merged
BCTBB merged 3 commits into
fleetdm:mainfrom
tnichols89:helm-chart-ro-fs
Apr 23, 2026
Merged

BCTBB merged 3 commits into
fleetdm:mainfrom
tnichols89:helm-chart-ro-fs

Conversation

@tnichols89

@tnichols89 tnichols89 commented Apr 9, 2026 •

Copy link
Copy Markdown
Contributor

Issue

Closes #43330

Description

This PR allows self-hosted, Kubernetes-based Fleet users to configure securityContext.readOnlyRootFilesystem in values.yaml, which is then propagated down to the deployment.yaml template.

This change provides a convenient mechanism for users to fix a known issue while preserving the current default behavior.

Testing

The underlying deployment.yaml change has been tested in a standard Google Kubernetes Engine cluster, and is confirmed to fix the linked issue when using either Ubuntu-based or Container-Optimized OS (COS)-based containerd container runtimes in GKE.

Summary by CodeRabbit

Release Notes

  • Chores
    • Enhanced fleet container security by making the read-only root filesystem setting configurable. Deployments can now customize this security parameter to meet specific requirements, while secure defaults are automatically applied for standard installations that don't require custom configuration.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This pull request is from a fork — automated review is disabled. A repository maintainer can comment @claude review to run a one-time review.

@coderabbitai

coderabbitai Bot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 953813d9-05a4-4c40-8191-b728e7cb47e5

📥 Commits

Reviewing files that changed from the base of the PR and between 11aa1c1 and 98b17c3.

📒 Files selected for processing (2)
  • charts/fleet/templates/deployment.yaml
  • charts/fleet/values.yaml

Walkthrough

The changes make the readOnlyRootFilesystem security context setting configurable in the Fleet Helm chart. Previously hardcoded as true in the deployment template, this setting now accepts a value from the Helm values configuration with a default fallback to true. The values file was updated to include this new configuration option with the same default value, enabling users to override the read-only filesystem behavior when deploying Fleet via Helm.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and accurately describes the main change: allowing configuration of securityContext.readOnlyRootFilesystem in the Helm chart.
Description check ✅ Passed The description adequately covers the issue, solution, and testing performed, though it does not follow the full template structure which appears optional for infrastructure changes.
Linked Issues check ✅ Passed The PR directly addresses the requirements from issue #43330 by adding values.yaml configuration for securityContext.readOnlyRootFilesystem and propagating it to deployment.yaml as proposed.
Out of Scope Changes check ✅ Passed All changes are directly related to the stated objective: updating Helm chart files to allow configuration and passthrough of the readOnlyRootFilesystem setting.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@BCTBB
BCTBB merged commit c5c77e3 into fleetdm:main Apr 23, 2026
7 checks passed
@BCTBB

BCTBB commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

@tnichols89 Thanks for your contribution! I've just merged the change in. Additionally, I'm going to work on getting the changes referenced in the issue into place as well as bump the Chart version

@tnichols89

Copy link
Copy Markdown
Contributor Author

Thank you so much! @BCTBB

@tnichols89
tnichols89 deleted the helm-chart-ro-fs branch April 24, 2026 02:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Read-only file system error on software installation in web UI due to Helm chart deployment.yaml template

3 participants