[Promtail] enables configuring psp in helm chart (#2659)

* makes pod security policy configurable

* bump promtail chart version

* bump loki-stack chart version
pull/2614/head^2
RS Krishna 5 years ago committed by GitHub
parent d8e571e313
commit bffd9a5c98
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
  1. 2
      production/helm/loki-stack/Chart.yaml
  2. 2
      production/helm/promtail/Chart.yaml
  3. 26
      production/helm/promtail/templates/podsecuritypolicy.yaml
  4. 25
      production/helm/promtail/values.yaml

@ -1,6 +1,6 @@
apiVersion: "v1"
name: loki-stack
version: 0.40.1
version: 0.41.0
appVersion: v1.6.0
kubeVersion: "^1.10.0-0"
description: "Loki: like Prometheus, but for logs."

@ -1,6 +1,6 @@
apiVersion: "v1"
name: promtail
version: 0.24.0
version: 0.25.0
appVersion: v1.6.0
kubeVersion: "^1.10.0-0"
description: "Responsible for gathering logs and sending them to Loki"

@ -9,27 +9,5 @@ metadata:
heritage: {{ .Release.Service }}
release: {{ .Release.Name }}
spec:
privileged: false
allowPrivilegeEscalation: false
volumes:
- 'secret'
- 'configMap'
- 'hostPath'
- 'projected'
- 'downwardAPI'
- 'emptyDir'
hostNetwork: false
hostIPC: false
hostPID: false
runAsUser:
rule: 'RunAsAny'
seLinux:
rule: 'RunAsAny'
supplementalGroups:
rule: 'RunAsAny'
fsGroup:
rule: 'RunAsAny'
readOnlyRootFilesystem: true
requiredDropCapabilities:
- ALL
{{- end }}
{{- toYaml .Values.podSecurityPolicy | nindent 2 }}
{{- end }}

@ -58,6 +58,31 @@ rbac:
create: true
pspEnabled: true
podSecurityPolicy:
privileged: false
allowPrivilegeEscalation: false
volumes:
- 'secret'
- 'configMap'
- 'hostPath'
- 'projected'
- 'downwardAPI'
- 'emptyDir'
hostNetwork: false
hostIPC: false
hostPID: false
runAsUser:
rule: 'RunAsAny'
seLinux:
rule: 'RunAsAny'
supplementalGroups:
rule: 'RunAsAny'
fsGroup:
rule: 'RunAsAny'
readOnlyRootFilesystem: true
requiredDropCapabilities:
- ALL
readinessProbe:
failureThreshold: 5
httpGet:

Loading…
Cancel
Save