File tree 4 files changed +11
-21
lines changed
helm-chart/katafygio/templates
4 files changed +11
-21
lines changed Original file line number Diff line number Diff line change @@ -7,11 +7,9 @@ RUN make build
7
7
8
8
FROM alpine:3.7
9
9
RUN apk upgrade --no-cache && \
10
- apk --no-cache add ca-certificates git openssh-client su-exec
11
- RUN addgroup -S katafygio && \
12
- adduser -S -G katafygio katafygio
13
- RUN install -d -o katafygio -g katafygio /var/lib/katafygio/data
10
+ apk --no-cache add ca-certificates git openssh-client
11
+ RUN install -d -o nobody -g nobody /var/lib/katafygio/data
14
12
COPY --from=builder /go/src/github.com/bpineau/katafygio/katafygio /usr/bin/
15
- COPY entrypoint.sh /
16
13
VOLUME /var/lib/katafygio
17
- ENTRYPOINT ["/entrypoint.sh" ]
14
+ USER nobody
15
+ ENTRYPOINT ["/usr/bin/katafygio" ]
Original file line number Diff line number Diff line change 1
1
FROM alpine:3.7
2
2
RUN apk upgrade --no-cache && \
3
- apk --no-cache add ca-certificates git openssh-client su-exec
4
- RUN addgroup -S katafygio && \
5
- adduser -S -G katafygio katafygio
6
- RUN install -d -o katafygio -g katafygio /var/lib/katafygio/data
3
+ apk --no-cache add ca-certificates git openssh-client
4
+ RUN install -d -o nobody -g nobody /var/lib/katafygio/data
7
5
COPY katafygio /usr/bin/
8
- COPY entrypoint.sh /
9
6
VOLUME /var/lib/katafygio
10
- ENTRYPOINT ["/entrypoint.sh"]
7
+ USER nobody
8
+ ENTRYPOINT ["/usr/bin/katafygio"]
Original file line number Diff line number Diff line change 15
15
labels :
16
16
{{ include "katafygio.labels.standard" . | indent 8 }}
17
17
spec :
18
+ securityContext :
19
+ fsGroup : 65534
18
20
serviceAccountName : {{ template "katafygio.serviceAccountName" . }}
19
21
containers :
20
22
- name : {{ .Chart.Name }}
69
71
{{- if and .Values.gitSshKey .Values.gitUrl }}
70
72
volumeMounts :
71
73
- name : katafygio-gitssh
72
- mountPath : " /gitssh-secret "
74
+ mountPath : " /.ssh "
73
75
readOnly : true
74
76
{{- end }}
75
77
resources :
Load Diff This file was deleted.
You can’t perform that action at this time.
0 commit comments