[issue-2401] Added pod security context for Fission Components (#2449)

Following component has been updated with securityContext -
1. buildermgr
2. controller
3. executor
4. kubewatcher
5. router
6. timer
7. storagesvc

* Removed the security context from fetcher as per the offline discussion
This commit is contained in:
Yatish Sharma
2022-06-09 16:25:09 +05:30
committed by GitHub
parent 709af6e432
commit 7be3e4f410
9 changed files with 111 additions and 0 deletions
@@ -19,6 +19,9 @@ spec:
prometheus.io/path: "/metrics" prometheus.io/path: "/metrics"
prometheus.io/port: "8080" prometheus.io/port: "8080"
spec: spec:
{{- if .Values.buildermgr.securityContext.enabled }}
securityContext: {{- omit .Values.buildermgr.securityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
containers: containers:
- name: buildermgr - name: buildermgr
image: {{ include "fission-bundleImage" . | quote }} image: {{ include "fission-bundleImage" . | quote }}
@@ -22,6 +22,9 @@ spec:
prometheus.io/path: "/metrics" prometheus.io/path: "/metrics"
prometheus.io/port: "8080" prometheus.io/port: "8080"
spec: spec:
{{- if .Values.controller.securityContext.enabled }}
securityContext: {{- omit .Values.controller.securityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
containers: containers:
- name: controller - name: controller
image: {{ include "fission-bundleImage" . | quote }} image: {{ include "fission-bundleImage" . | quote }}
@@ -19,6 +19,9 @@ spec:
prometheus.io/path: "/metrics" prometheus.io/path: "/metrics"
prometheus.io/port: "8080" prometheus.io/port: "8080"
spec: spec:
{{- if .Values.executor.securityContext.enabled }}
securityContext: {{- omit .Values.executor.securityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
containers: containers:
- name: executor - name: executor
image: {{ include "fission-bundleImage" . | quote }} image: {{ include "fission-bundleImage" . | quote }}
@@ -15,6 +15,9 @@ spec:
labels: labels:
svc: kubewatcher svc: kubewatcher
spec: spec:
{{- if .Values.kubewatcher.securityContext.enabled }}
securityContext: {{- omit .Values.kubewatcher.securityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
containers: containers:
- name: kubewatcher - name: kubewatcher
image: {{ include "fission-bundleImage" . | quote }} image: {{ include "fission-bundleImage" . | quote }}
@@ -28,6 +28,9 @@ spec:
prometheus.io/path: "/metrics" prometheus.io/path: "/metrics"
prometheus.io/port: "8080" prometheus.io/port: "8080"
spec: spec:
{{- if .Values.router.securityContext.enabled }}
securityContext: {{- omit .Values.router.securityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
containers: containers:
- name: router - name: router
image: {{ include "fission-bundleImage" . | quote }} image: {{ include "fission-bundleImage" . | quote }}
@@ -22,6 +22,9 @@ spec:
prometheus.io/path: "/metrics" prometheus.io/path: "/metrics"
prometheus.io/port: "8080" prometheus.io/port: "8080"
spec: spec:
{{- if .Values.storagesvc.securityContext.enabled }}
securityContext: {{- omit .Values.storagesvc.securityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
containers: containers:
- name: storagesvc - name: storagesvc
image: {{ include "fission-bundleImage" . | quote }} image: {{ include "fission-bundleImage" . | quote }}
@@ -15,6 +15,9 @@ spec:
labels: labels:
svc: timer svc: timer
spec: spec:
{{- if .Values.timer.securityContext.enabled }}
securityContext: {{- omit .Values.timer.securityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
containers: containers:
- name: timer - name: timer
image: {{ include "fission-bundleImage" . | quote }} image: {{ include "fission-bundleImage" . | quote }}
+84
View File
@@ -143,6 +143,18 @@ executor:
## ##
resources: {} resources: {}
## Security Context
## It holds pod-level and container level security configuration.
## This is an experimental section, please verify before enabling in production.
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
securityContext:
enabled: false
## Mark it false, if you want to stop the non root user validation
runAsNonRoot: true
fsGroup: 10001
runAsUser: 10001
runAsGroup: 10001
## router is responsible for routing function calls to the appropriate function. ## router is responsible for routing function calls to the appropriate function.
## ##
router: router:
@@ -248,6 +260,18 @@ router:
## ##
resources: {} resources: {}
## Security Context
## It holds pod-level and container level security configuration.
## This is an experimental section, please verify before enabling in production.
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
securityContext:
enabled: false
## Mark it false, if you want to stop the non root user validation
runAsNonRoot: true
fsGroup: 10001
runAsUser: 10001
runAsGroup: 10001
## The builder manager watches the package & environments CRD changes and manages the builds of function source code. ## The builder manager watches the package & environments CRD changes and manages the builds of function source code.
## ##
buildermgr: buildermgr:
@@ -262,6 +286,18 @@ buildermgr:
## ##
resources: {} resources: {}
## Security Context
## It holds pod-level and container level security configuration.
## This is an experimental section, please verify before enabling in production.
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
securityContext:
enabled: false
## Mark it false, if you want to stop the non root user validation
runAsNonRoot: true
fsGroup: 10001
runAsUser: 10001
runAsGroup: 10001
## controller is the component that the client talks to. ## controller is the component that the client talks to.
## It contains CRUD APIs for functions, triggers, environments, Kubernetes event watches, etc. and proxy APIs to internal 3rd-party services. ## It contains CRUD APIs for functions, triggers, environments, Kubernetes event watches, etc. and proxy APIs to internal 3rd-party services.
## ##
@@ -277,6 +313,18 @@ controller:
## ##
resources: {} resources: {}
## Security Context
## It holds pod-level and container level security configuration.
## This is an experimental section, please verify before enabling in production.
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
securityContext:
enabled: false
## Mark it false, if you want to stop the non root user validation
runAsNonRoot: true
fsGroup: 10001
runAsUser: 10001
runAsGroup: 10001
## kubewatcher watches the Kubernetes API and invokes functions associated with watches, sending the watch event to the function. ## kubewatcher watches the Kubernetes API and invokes functions associated with watches, sending the watch event to the function.
## ##
kubewatcher: kubewatcher:
@@ -291,6 +339,18 @@ kubewatcher:
## ##
resources: {} resources: {}
## Security Context
## It holds pod-level and container level security configuration.
## This is an experimental section, please verify before enabling in production.
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
securityContext:
enabled: false
## Mark it false, if you want to stop the non root user validation
runAsNonRoot: true
fsGroup: 10001
runAsUser: 10001
runAsGroup: 10001
## The storage service is the home for all archives of packages with sizes larger than 256KB. ## The storage service is the home for all archives of packages with sizes larger than 256KB.
## ##
storagesvc: storagesvc:
@@ -305,6 +365,18 @@ storagesvc:
## ##
resources: {} resources: {}
## Security Context
## It holds pod-level and container level security configuration.
## This is an experimental section, please verify before enabling in production.
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
securityContext:
enabled: false
## Mark it false, if you want to stop the non root user validation
runAsNonRoot: true
fsGroup: 10001
runAsUser: 10001
runAsGroup: 10001
## The timer works like kubernetes CronJob but instead of creating a pod to do the task ## The timer works like kubernetes CronJob but instead of creating a pod to do the task
## It sends a request to router to invoke the function. ## It sends a request to router to invoke the function.
## ##
@@ -320,6 +392,18 @@ timer:
## ##
resources: {} resources: {}
## Security Context
## It holds pod-level and container level security configuration.
## This is an experimental section, please verify before enabling in production.
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
securityContext:
enabled: false
## Mark it false, if you want to stop the non root user validation
runAsNonRoot: true
fsGroup: 10001
runAsUser: 10001
runAsGroup: 10001
## Kafka: enable and configure the details ## Kafka: enable and configure the details
## ##
kafka: kafka:
+6
View File
@@ -56,6 +56,12 @@ deploy:
# Use /var/log directory for kind logs export # Use /var/log directory for kind logs export
terminationMessagePath: /var/log/termination-log terminationMessagePath: /var/log/termination-log
terminationMessagePolicy: FallbackToLogsOnError terminationMessagePolicy: FallbackToLogsOnError
executor.securityContext.enabled: true
router.securityContext.enabled: true
buildermgr.securityContext.enabled: true
controller.securityContext.enabled: true
kubewatcher.securityContext.enabled: true
storagesvc.securityContext.enabled: true
wait: true wait: true
flags: flags:
install: install: