Search Options

Results per page
Sort
Preferred Languages
Advance

Results 1 - 10 of 330 for fsGroup (0.15 sec)

  1. releasenotes/notes/fsgroup.yaml

    apiVersion: release-notes/v2
    kind: feature
    area: installation
    issue:
    - 26882
    releaseNotes:
    - |
      **Improved** sidecar injection to not modify the pod `securityPolicy.fsGroup` which could conflict with existing settings and secret mounts.
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Wed Sep 23 01:09:13 UTC 2020
    - 338 bytes
    - Viewed (0)
  2. releasenotes/notes/drop-legacy-fsgroup-injection.yaml

    John Howard <******@****.***> 1682631570 -0700
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Thu Apr 27 21:39:30 UTC 2023
    - 227 bytes
    - Viewed (0)
  3. pkg/volume/volume_linux.go

    )
    
    // SetVolumeOwnership modifies the given volume to be owned by
    // fsGroup, and sets SetGid so that newly created files are owned by
    // fsGroup. If fsGroup is nil nothing is done.
    func SetVolumeOwnership(mounter Mounter, dir string, fsGroup *int64, fsGroupChangePolicy *v1.PodFSGroupChangePolicy, completeFunc func(types.CompleteFuncParam)) error {
    	if fsGroup == nil {
    		return nil
    	}
    
    	timer := time.AfterFunc(30*time.Second, func() {
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Mon Apr 03 19:34:37 UTC 2023
    - 6.5K bytes
    - Viewed (0)
  4. pkg/volume/csi/csi_mounter_test.go

    			fsType:   "",
    		},
    		{
    			name: "default fstype  with fsgroup (should not apply fsgroup)",
    			accessModes: []corev1.PersistentVolumeAccessMode{
    				corev1.ReadWriteOnce,
    			},
    			readOnly:   false,
    			fsType:     "",
    			setFsGroup: true,
    			fsGroup:    3000,
    		},
    		{
    			name: "fstype, fsgroup, RWM, ROM provided (should not apply fsgroup)",
    			accessModes: []corev1.PersistentVolumeAccessMode{
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed Apr 24 18:25:29 UTC 2024
    - 50.1K bytes
    - Viewed (0)
  5. helm/minio/templates/securitycontextconstraints.yaml

    allowedCapabilities: []
    readOnlyRootFilesystem: false
    defaultAddCapabilities: []
    requiredDropCapabilities:
    - KILL
    - MKNOD
    - SETUID
    - SETGID
    fsGroup:
      type: MustRunAs
      ranges:
      - max: {{ .Values.securityContext.fsGroup }}
        min: {{ .Values.securityContext.fsGroup }}
    runAsUser:
      type: MustRunAs
      uid: {{ .Values.securityContext.runAsUser }}
    seLinuxContext:
      type: MustRunAs
    supplementalGroups:
      type: RunAsAny
    Registered: Sun Jun 16 00:44:34 UTC 2024
    - Last Modified: Fri Aug 20 22:30:54 UTC 2021
    - 1.1K bytes
    - Viewed (0)
  6. pkg/volume/volume_linux_test.go

    	fsGroup := int64(3000)
    	currentUid := os.Geteuid()
    	if currentUid != 0 {
    		t.Skip("running as non-root")
    	}
    	currentGid := os.Getgid()
    
    	tests := []struct {
    		description string
    		fsGroup     *int64
    		setupFunc   func(path string) error
    		assertFunc  func(path string) error
    	}{
    		{
    			description: "fsGroup=nil",
    			fsGroup:     nil,
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Mon Apr 03 19:34:37 UTC 2023
    - 12.1K bytes
    - Viewed (0)
  7. pkg/volume/local/local_linux_test.go

    	}
    	fsGroup1 := int64(s.Gid)
    	fsGroup2 := fsGroup1 + 1
    	pod1 := &v1.Pod{ObjectMeta: metav1.ObjectMeta{UID: types.UID("poduid")}}
    	pod1.Spec.SecurityContext = &v1.PodSecurityContext{
    		FSGroup: &fsGroup1,
    	}
    	pod2 := &v1.Pod{ObjectMeta: metav1.ObjectMeta{UID: types.UID("poduid")}}
    	pod2.Spec.SecurityContext = &v1.PodSecurityContext{
    		FSGroup: &fsGroup2,
    	}
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Tue Aug 24 19:47:49 UTC 2021
    - 2K bytes
    - Viewed (0)
  8. pkg/volume/flexvolume/mounter.go

    		os.Remove(dir)
    		return err
    	}
    
    	// Implicit parameters
    	if mounterArgs.FsGroup != nil {
    		extraOptions[optionFSGroup] = strconv.FormatInt(int64(*mounterArgs.FsGroup), 10)
    	}
    
    	call.AppendSpec(f.spec, f.plugin.host, extraOptions)
    
    	_, err = call.Run()
    	if isCmdNotSupportedErr(err) {
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Mon Apr 03 19:34:37 UTC 2023
    - 2.9K bytes
    - Viewed (0)
  9. pkg/volume/csi/csi_mounter.go

    	}
    
    	if driverSupportsCSIVolumeMountGroup {
    		klog.V(3).Infof("Driver %s supports applying FSGroup (has VOLUME_MOUNT_GROUP node capability). Delegating FSGroup application to the driver through NodePublishVolume.", c.driverName)
    		nodePublishFSGroupArg = mounterArgs.FsGroup
    	}
    
    	var selinuxLabelMount bool
    	if utilfeature.DefaultFeatureGate.Enabled(features.SELinuxMountReadWriteOncePod) {
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Tue Jan 30 10:47:59 UTC 2024
    - 21K bytes
    - Viewed (0)
  10. pkg/volume/flexvolume/mounter_test.go

    		// first call without mounterArgs.FsGroup
    		assertDriverCall(t, successOutput(), mountCmd, rootDir+"/mount-dir",
    			specJSON(plugin, spec, map[string]string{
    				optionKeyPodName:            "my-pod",
    				optionKeyPodNamespace:       "my-ns",
    				optionKeyPodUID:             "my-uid",
    				optionKeyServiceAccountName: "my-sa",
    			})),
    
    		// second test has mounterArgs.FsGroup
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Thu Sep 17 04:51:24 UTC 2020
    - 2.3K bytes
    - Viewed (0)
Back to top