ci: Fix pod UIDs/GIDs
Now that we have _democratic-csi_ for storage management, the old manual iSCSI volumes are being replaced with dynamically provisioned volumes. ThiThe new _buildroot-airplaypi_ volume is completely blank, so _root_ owns everything. The old volume had the correct ownership because it was originally mounted in a pod that had the default `securityContext`, before we changed the merge strategy. We now need to explicitly set the UIDs and GIDs, since we're not inheriting the default `securityContext` anymore.dev/new
parent
fa7548cacc
commit
87dded162e
|
@ -25,6 +25,9 @@ spec:
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
kubernetes.io/arch: amd64
|
kubernetes.io/arch: amd64
|
||||||
securityContext:
|
securityContext:
|
||||||
|
runAsUser: 1000
|
||||||
|
runAsGroup: 1000
|
||||||
|
fsGroup: 1000
|
||||||
fsGroupChangePolicy: OnRootMismatch
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
seLinuxOptions:
|
seLinuxOptions:
|
||||||
level: s0:c596,c675
|
level: s0:c596,c675
|
||||||
|
|
Loading…
Reference in New Issue