mirror of
https://github.com/suitenumerique/meet.git
synced 2026-08-16 21:48:48 +00:00
🔒️(helm) add pod and container securityContext
This commit aim at adding a securityContext for pod and container in Deployment and Job, it include livekit pods as well It adds 2 values : - podSecurityContext : for pods - securityContext : for containers Please note that `celeryBackend` Deployment does not have any values defined in `values.meet.yaml` at the moment.
This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
.podSecurityContext: &podSecurityContext
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
fsGroupChangePolicy: "OnRootMismatch"
|
||||
runAsNonRoot: true
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
|
||||
.securityContext: &securityContext
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
|
||||
frontend:
|
||||
podSecurityContext: *podSecurityContext
|
||||
securityContext: *securityContext
|
||||
|
||||
backend:
|
||||
podSecurityContext: *podSecurityContext
|
||||
securityContext: *securityContext
|
||||
|
||||
summary:
|
||||
podSecurityContext: *podSecurityContext
|
||||
securityContext: *securityContext
|
||||
|
||||
celeryTranscribe:
|
||||
podSecurityContext: *podSecurityContext
|
||||
securityContext: *securityContext
|
||||
|
||||
celerySummarize:
|
||||
podSecurityContext: *podSecurityContext
|
||||
securityContext: *securityContext
|
||||
|
||||
agents:
|
||||
podSecurityContext: *podSecurityContext
|
||||
securityContext: *securityContext
|
||||
@@ -28,7 +28,6 @@ livekit:
|
||||
urls:
|
||||
- https://meet.127.0.0.1.nip.io/api/v1.0/rooms/webhooks-livekit/
|
||||
|
||||
|
||||
loadBalancer:
|
||||
type: nginx
|
||||
annotations:
|
||||
|
||||
@@ -174,7 +174,7 @@ ingressWebhook:
|
||||
posthog:
|
||||
ingress:
|
||||
enabled: false
|
||||
|
||||
|
||||
ingressAssets:
|
||||
enabled: false
|
||||
|
||||
|
||||
@@ -28,7 +28,6 @@ livekit:
|
||||
urls:
|
||||
- https://meet.127.0.0.1.nip.io/api/v1.0/rooms/webhooks-livekit/
|
||||
|
||||
|
||||
loadBalancer:
|
||||
type: nginx
|
||||
annotations:
|
||||
|
||||
@@ -126,7 +126,6 @@ backend:
|
||||
CELERY_ENABLED: True
|
||||
CELERY_BROKER_URL: redis://default:pass@redis-master:6379/1
|
||||
|
||||
|
||||
migrate:
|
||||
command:
|
||||
- "/bin/sh"
|
||||
@@ -194,7 +193,7 @@ ingressWebhook:
|
||||
posthog:
|
||||
ingress:
|
||||
enabled: false
|
||||
|
||||
|
||||
ingressAssets:
|
||||
enabled: false
|
||||
|
||||
|
||||
Reference in New Issue
Block a user