Skip to content

Commit 820c3d8

Browse files
another-rextymzd
authored andcommitted
chore: Remove priviledged security context from our pods (google#4983)
\
1 parent 61766a9 commit 820c3d8

16 files changed

Lines changed: 0 additions & 32 deletions

deployment/clouddeploy/gke-indexer/base/indexer-controller.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,8 +44,6 @@ spec:
4444
volumeMounts:
4545
- mountPath: "/tmp"
4646
name: "ssd"
47-
securityContext:
48-
privileged: true
4947
resources:
5048
requests:
5149
cpu: 5

deployment/clouddeploy/gke-indexer/base/indexer-worker.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -46,8 +46,6 @@ spec:
4646
volumeMounts:
4747
- mountPath: "/tmp"
4848
name: "ssd"
49-
securityContext:
50-
privileged: true
5149
resources:
5250
requests:
5351
cpu: 1

deployment/clouddeploy/gke-workers/base/alpine-cve-convert.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,6 @@ spec:
2020
- name: alpine-cve-convert
2121
image: alpine-cve-convert
2222
imagePullPolicy: Always
23-
securityContext:
24-
privileged: true
2523
resources:
2624
requests:
2725
cpu: "2"

deployment/clouddeploy/gke-workers/base/combine-to-osv.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,8 +21,6 @@ spec:
2121
- name: combine-to-osv
2222
image: combine-to-osv
2323
imagePullPolicy: Always
24-
securityContext:
25-
privileged: true
2624
resources:
2725
requests:
2826
cpu: "30"

deployment/clouddeploy/gke-workers/base/cpe-repo-gen.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,8 +16,6 @@ spec:
1616
- name: cpe-repo-gen
1717
image: cpe-repo-gen
1818
imagePullPolicy: Always
19-
securityContext:
20-
privileged: true
2119
resources:
2220
requests:
2321
cpu: "1"

deployment/clouddeploy/gke-workers/base/cve5-to-osv.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,8 +17,6 @@ spec:
1717
- name: cve5-to-osv
1818
image: cve5-to-osv
1919
imagePullPolicy: Always
20-
securityContext:
21-
privileged: true
2220
resources:
2321
requests:
2422
cpu: "8"

deployment/clouddeploy/gke-workers/base/debian-convert.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,8 +21,6 @@ spec:
2121
volumeMounts:
2222
- mountPath: "/work"
2323
name: "ssd"
24-
securityContext:
25-
privileged: true
2624
resources:
2725
requests:
2826
cpu: "1"

deployment/clouddeploy/gke-workers/base/debian-copyright-mirror.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,8 +16,6 @@ spec:
1616
- name: debian-copyright-mirror
1717
image: debian-copyright-mirror
1818
imagePullPolicy: Always
19-
securityContext:
20-
privileged: true
2119
resources:
2220
requests:
2321
cpu: "1"

deployment/clouddeploy/gke-workers/base/debian-cve-convert.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,6 @@ spec:
2020
- name: debian-cve-convert
2121
image: debian-cve-convert
2222
imagePullPolicy: Always
23-
securityContext:
24-
privileged: true
2523
resources:
2624
requests:
2725
cpu: "2"

deployment/clouddeploy/gke-workers/base/debian-first-version.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,8 +21,6 @@ spec:
2121
volumeMounts:
2222
- mountPath: "/work"
2323
name: "ssd"
24-
securityContext:
25-
privileged: true
2624
resources:
2725
requests:
2826
cpu: "1"

0 commit comments

Comments
 (0)