Skip to content

Commit 392697b

Browse files
Merge pull request #306 from kramaranya/AUTH-482
AUTH-482: set required-scc for openshift workloads
2 parents e35645a + 9d93337 commit 392697b

File tree

10 files changed

+16
-0
lines changed

10 files changed

+16
-0
lines changed

assets/overlays/aws-efs/generated/standalone/controller.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@ spec:
3333
metadata:
3434
annotations:
3535
cluster-autoscaler.kubernetes.io/safe-to-evict-local-volumes: socket-dir
36+
openshift.io/required-scc: privileged
3637
target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}'
3738
labels:
3839
app: aws-efs-csi-driver-controller

assets/overlays/aws-efs/patches/controller_add_driver.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,7 @@ spec:
2020
labels:
2121
app: aws-efs-csi-driver-controller
2222
annotations:
23+
openshift.io/required-scc: privileged
2324
target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}'
2425
spec:
2526
hostNetwork: true

assets/overlays/azure-disk/generated/hypershift/controller.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,7 @@ spec:
4848
metadata:
4949
annotations:
5050
cluster-autoscaler.kubernetes.io/safe-to-evict-local-volumes: socket-dir
51+
openshift.io/required-scc: restricted-v2
5152
target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}'
5253
labels:
5354
app: azure-disk-csi-driver-controller

assets/overlays/azure-disk/generated/standalone/controller.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,7 @@ spec:
4444
metadata:
4545
annotations:
4646
cluster-autoscaler.kubernetes.io/safe-to-evict-local-volumes: socket-dir
47+
openshift.io/required-scc: restricted-v2
4748
target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}'
4849
labels:
4950
app: azure-disk-csi-driver-controller

assets/overlays/azure-disk/patches/controller_add_driver.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,9 @@ metadata:
66
config.openshift.io/inject-proxy-cabundle: csi-driver
77
spec:
88
template:
9+
metadata:
10+
annotations:
11+
openshift.io/required-scc: restricted-v2
912
spec:
1013
containers:
1114
- name: csi-driver

assets/overlays/azure-file/generated/hypershift/controller.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,7 @@ spec:
4949
metadata:
5050
annotations:
5151
cluster-autoscaler.kubernetes.io/safe-to-evict-local-volumes: socket-dir
52+
openshift.io/required-scc: restricted-v2
5253
target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}'
5354
labels:
5455
app: azure-file-csi-driver-controller

assets/overlays/azure-file/generated/standalone/controller.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,7 @@ spec:
4444
metadata:
4545
annotations:
4646
cluster-autoscaler.kubernetes.io/safe-to-evict-local-volumes: socket-dir
47+
openshift.io/required-scc: restricted-v2
4748
target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}'
4849
labels:
4950
app: azure-file-csi-driver-controller

assets/overlays/azure-file/patches/controller_add_driver.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,9 @@ metadata:
66
config.openshift.io/inject-proxy-cabundle: csi-driver
77
spec:
88
template:
9+
metadata:
10+
annotations:
11+
openshift.io/required-scc: restricted-v2
912
spec:
1013
## Removing this for now
1114
# hostNetwork: true # although not needed for other drivers, this is required for the Azure File driver

assets/overlays/samba/generated/standalone/controller.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,7 @@ spec:
3131
metadata:
3232
annotations:
3333
cluster-autoscaler.kubernetes.io/safe-to-evict-local-volumes: socket-dir
34+
openshift.io/required-scc: privileged
3435
target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}'
3536
labels:
3637
app: smb-csi-driver-controller

assets/overlays/samba/patches/controller_add_driver.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,9 @@ kind: Deployment
22
apiVersion: apps/v1
33
spec:
44
template:
5+
metadata:
6+
annotations:
7+
openshift.io/required-scc: privileged
58
spec:
69
containers:
710
- name: csi-driver

0 commit comments

Comments
 (0)