- Sort Score
- Result 10 results
- Languages All
Results 11 - 20 of 28 for fsGroup (0.2 sec)
-
tests/integration/pilot/testdata/external-forward-proxy-deployment.yaml
app: external-forward-proxy template: metadata: labels: app: external-forward-proxy spec: securityContext: runAsUser: 65534 runAsGroup: 65534 fsGroup: 65534 containers: - name: external-forward-proxy image: envoyproxy/envoy:v1.21.0 imagePullPolicy: IfNotPresent volumeMounts: - name: external-forward-proxy-config
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue Jul 11 08:07:45 UTC 2023 - 701 bytes - Viewed (0) -
cluster/addons/calico-policy-controller/typha-horizontal-autoscaler-deployment.yaml
template: metadata: labels: k8s-app: calico-typha-autoscaler spec: priorityClassName: system-cluster-critical securityContext: supplementalGroups: [ 65534 ] fsGroup: 65534 containers: - image: registry.k8s.io/cluster-proportional-autoscaler-amd64:1.7.1 name: autoscaler command: - /cluster-proportional-autoscaler
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Tue May 31 14:16:53 UTC 2022 - 1K bytes - Viewed (0) -
pkg/volume/fc/disk_manager.go
DetachBlockFCDisk(disk fcDiskUnmapper, mntPath, devicePath string) error } // utility to mount a disk based filesystem func diskSetUp(manager diskManager, b fcDiskMounter, volPath string, mounter mount.Interface, fsGroup *int64, fsGroupChangePolicy *v1.PodFSGroupChangePolicy) error { globalPDPath := manager.MakeGlobalPDName(*b.fcDisk) noMnt, err := mounter.IsLikelyNotMountPoint(volPath) if err != nil && !os.IsNotExist(err) {
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Apr 03 19:34:37 UTC 2023 - 3K bytes - Viewed (0) -
pkg/volume/iscsi/disk_manager.go
// volPath: pod volume dir path like, /var/lib/kubelet/pods/{podUID}/volumes/kubernetes.io~iscsi/{volumeName} func diskSetUp(manager diskManager, b iscsiDiskMounter, volPath string, mounter mount.Interface, fsGroup *int64, fsGroupChangePolicy *v1.PodFSGroupChangePolicy) error { notMnt, err := mounter.IsLikelyNotMountPoint(volPath) if err != nil && !os.IsNotExist(err) { klog.Errorf("cannot validate mountpoint: %s", volPath) return err
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Apr 03 19:34:37 UTC 2023 - 3.4K bytes - Viewed (0) -
samples/security/psp/sidecar-psp.yaml
spec: # Allow the istio sidecar injector to work allowedCapabilities: - NET_ADMIN - NET_RAW seLinux: rule: RunAsAny supplementalGroups: rule: RunAsAny runAsUser: rule: RunAsAny fsGroup: rule: RunAsAny volumes: - '*' --- kind: ClusterRole apiVersion: rbac.authorization.k8s.io/v1 metadata: name: istio-sidecar-psp rules: - apiGroups: - extensions resources:
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Mon Nov 27 17:55:37 UTC 2023 - 881 bytes - Viewed (0) -
pkg/volume/volume_unsupported.go
limitations under the License. */ package volume import ( v1 "k8s.io/api/core/v1" "k8s.io/kubernetes/pkg/volume/util/types" ) func SetVolumeOwnership(mounter Mounter, dir string, fsGroup *int64, fsGroupChangePolicy *v1.PodFSGroupChangePolicy, completeFunc func(types.CompleteFuncParam)) error { return nil
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Apr 03 19:34:37 UTC 2023 - 886 bytes - Viewed (0) -
pkg/kubelet/kuberuntime/security_context.go
if err != nil { return nil, err } synthesized.NamespaceOptions = namespaceOptions podSc := pod.Spec.SecurityContext if podSc != nil { if podSc.FSGroup != nil { synthesized.SupplementalGroups = append(synthesized.SupplementalGroups, int64(*podSc.FSGroup)) } if podSc.SupplementalGroups != nil { for _, sg := range podSc.SupplementalGroups {
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Wed May 29 22:40:29 UTC 2024 - 5.2K bytes - Viewed (0) -
helm/minio/templates/deployment.yaml
securityContext: runAsUser: {{ .Values.securityContext.runAsUser }} runAsGroup: {{ .Values.securityContext.runAsGroup }} fsGroup: {{ .Values.securityContext.fsGroup }} {{- if and (ge .Capabilities.KubeVersion.Major "1") (ge .Capabilities.KubeVersion.Minor "20") }} fsGroupChangePolicy: {{ .Values.securityContext.fsGroupChangePolicy }} {{- end }}
Registered: Sun Jun 16 00:44:34 UTC 2024 - Last Modified: Sun Mar 03 17:50:39 UTC 2024 - 8.7K bytes - Viewed (0) -
cluster/addons/dns-horizontal-autoscaler/dns-horizontal-autoscaler.yaml
spec: priorityClassName: system-cluster-critical securityContext: seccompProfile: type: RuntimeDefault supplementalGroups: [ 65534 ] fsGroup: 65534 nodeSelector: kubernetes.io/os: linux containers: - name: autoscaler image: registry.k8s.io/cpa/cluster-proportional-autoscaler:1.8.4 resources: requests:
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Tue May 31 14:16:53 UTC 2022 - 3.3K bytes - Viewed (0) -
pkg/kube/inject/testdata/inject/explicit-security-context.yaml.injected
- ALL privileged: false readOnlyRootFilesystem: false runAsGroup: 0 runAsNonRoot: false runAsUser: 0 securityContext: fsGroup: 1234 volumes: - name: workload-socket - name: credential-socket - name: workload-certs - emptyDir: medium: Memory name: istio-envoy - emptyDir: {}
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue Feb 27 16:55:16 UTC 2024 - 6.4K bytes - Viewed (0)