-
Notifications
You must be signed in to change notification settings - Fork 272
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: tighten securityContext to comply with restricted PSS #600
Conversation
makes argocd-image-updater compatible with restricted Pod Security Standard Signed-off-by: Takeo Sawada <[email protected]>
58ed91e
to
a9ba028
Compare
We've been running 0.12.2 with this securityContext for a few weeks and things seem to be okay. All other components in ArgoCD have the same securityContext since argoproj/argo-cd#9765 , and I think it is preferable for argocd-image-updater to align with them. @jannfis please let me know if I can do anything to help this getting merged. Thanks in advance! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Thanks a lot!
…labs#600) makes argocd-image-updater compatible with restricted Pod Security Standard Signed-off-by: Takeo Sawada <[email protected]> Signed-off-by: Jarvis Yang <[email protected]>
…labs#600) makes argocd-image-updater compatible with restricted Pod Security Standard Signed-off-by: Takeo Sawada <[email protected]> Signed-off-by: Jesse Bye <[email protected]>
Signed-off-by: satoru <[email protected]> Signed-off-by: Jesse Bye <[email protected]> docs: Fixed typo (argoproj-labs#589) Signed-off-by: Jesse Bye <[email protected]> chore: Preallocate space for slices with known size (argoproj-labs#575) Signed-off-by: satoru <[email protected]> Signed-off-by: Jesse Bye <[email protected]> ci: Fix codegen and update kustomize to post-2.0 (argoproj-labs#590) * ci: Fix codegen Signed-off-by: jannfis <[email protected]> * Fix tar call Signed-off-by: jannfis <[email protected]> --------- Signed-off-by: jannfis <[email protected]> Signed-off-by: Jesse Bye <[email protected]> feat: Respect original parameter overrides with git write-back (argoproj-labs#573) * Fix original override not respected Signed-off-by: KS. Yim <[email protected]> * Add writeOverrides unittest Signed-off-by: KS. Yim <[email protected]> * Add helm override commit test Signed-off-by: KS. Yim <[email protected]> * lint Signed-off-by: KS. Yim <[email protected]> * fix shadowed err Signed-off-by: KS. Yim <[email protected]> --------- Signed-off-by: KS. Yim <[email protected]> Co-authored-by: KS. Yim <[email protected]> Signed-off-by: Jesse Bye <[email protected]> chore: Update to newer argocd version for better API compatibility (argoproj-labs#594) * fix: update go mods to use newer argocd app definition Signed-off-by: Jesse Bye <[email protected]> * fix deps and tests Signed-off-by: Jesse Bye <[email protected]> * fix spelling Signed-off-by: Jesse Bye <[email protected]> --------- Signed-off-by: Jesse Bye <[email protected]> chore(deps): upgrade dependencies for fix vulnerabilities (argoproj-labs#599) Signed-off-by: Viacheslav Sychov <[email protected]> Signed-off-by: Jesse Bye <[email protected]> fix: tighten securityContext to comply with restricted PSS (argoproj-labs#600) makes argocd-image-updater compatible with restricted Pod Security Standard Signed-off-by: Takeo Sawada <[email protected]> Signed-off-by: Jesse Bye <[email protected]> feat: Add possibility to specify write-back GIT repository as annotation (argoproj-labs#424) * Add possibility to specify write-back GIT repository as annotation. Signed-off-by: flozzone <[email protected]> * Update golangci-lint to 1.52.2. Signed-off-by: flozzone <[email protected]> * Replace deprecated golangci linters with 'unused' linter. Signed-off-by: flozzone <[email protected]> * Fix Goimport issues. Signed-off-by: flozzone <[email protected]> --------- Signed-off-by: flozzone <[email protected]> Signed-off-by: Jesse Bye <[email protected]> fix: support ocischema.DeserializedImageIndex in registry client Signed-off-by: Jesse Bye <[email protected]> fix test Signed-off-by: Jesse Bye <[email protected]> fix: update go mods to use newer argocd app definition Signed-off-by: Jesse Bye <[email protected]> fix deps and tests Signed-off-by: Jesse Bye <[email protected]> merge master Signed-off-by: Jesse Bye <[email protected]> fix go mods Signed-off-by: Jesse Bye <[email protected]> refactor: use shared function to reduce duplication Signed-off-by: Jesse Bye <[email protected]> fix: update go mods to use newer argocd app definition Signed-off-by: Jesse Bye <[email protected]> fix deps and tests Signed-off-by: Jesse Bye <[email protected]> merge master Signed-off-by: Jesse Bye <[email protected]> fix go mods Signed-off-by: Jesse Bye <[email protected]> Fix after rebase Signed-off-by: Jesse Bye <[email protected]> chore: Fix spell checking config (argoproj-labs#577) Signed-off-by: satoru <[email protected]> docs: Fixed typo (argoproj-labs#589) chore: Preallocate space for slices with known size (argoproj-labs#575) Signed-off-by: satoru <[email protected]> ci: Fix codegen and update kustomize to post-2.0 (argoproj-labs#590) * ci: Fix codegen Signed-off-by: jannfis <[email protected]> * Fix tar call Signed-off-by: jannfis <[email protected]> --------- Signed-off-by: jannfis <[email protected]> feat: Respect original parameter overrides with git write-back (argoproj-labs#573) * Fix original override not respected Signed-off-by: KS. Yim <[email protected]> * Add writeOverrides unittest Signed-off-by: KS. Yim <[email protected]> * Add helm override commit test Signed-off-by: KS. Yim <[email protected]> * lint Signed-off-by: KS. Yim <[email protected]> * fix shadowed err Signed-off-by: KS. Yim <[email protected]> --------- Signed-off-by: KS. Yim <[email protected]> Co-authored-by: KS. Yim <[email protected]> chore: Update to newer argocd version for better API compatibility (argoproj-labs#594) * fix: update go mods to use newer argocd app definition Signed-off-by: Jesse Bye <[email protected]> * fix deps and tests Signed-off-by: Jesse Bye <[email protected]> * fix spelling Signed-off-by: Jesse Bye <[email protected]> --------- Signed-off-by: Jesse Bye <[email protected]> chore(deps): upgrade dependencies for fix vulnerabilities (argoproj-labs#599) Signed-off-by: Viacheslav Sychov <[email protected]> fix: tighten securityContext to comply with restricted PSS (argoproj-labs#600) makes argocd-image-updater compatible with restricted Pod Security Standard Signed-off-by: Takeo Sawada <[email protected]>
…labs#600) makes argocd-image-updater compatible with restricted Pod Security Standard Signed-off-by: Takeo Sawada <[email protected]> Signed-off-by: Francesc Arbona <[email protected]>
…labs#600) makes argocd-image-updater compatible with restricted Pod Security Standard Signed-off-by: Takeo Sawada <[email protected]>
…labs#600) makes argocd-image-updater compatible with restricted Pod Security Standard Signed-off-by: Takeo Sawada <[email protected]>
makes argocd-image-updater compatible with restricted Pod Security Standard