Skip to content

tbot Helm Chart: Add ability to configure securityContext#51817

Merged
strideynet merged 2 commits intomasterfrom
strideynet/tbot-pod-security-context
Feb 5, 2025
Merged

tbot Helm Chart: Add ability to configure securityContext#51817
strideynet merged 2 commits intomasterfrom
strideynet/tbot-pod-security-context

Conversation

@strideynet
Copy link
Copy Markdown
Contributor

By default, we will continue to use an empty securityContext as I don't want to make a breaking change here. Perhaps we make a breaking change in v18 at a later date to introduce a securityContext by default that is compatible with the restricted PSS.

changelog: Added securityContext value to the tbot Helm chart.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Feb 4, 2025

Amplify deployment status

Branch Commit Job ID Status Preview Updated (UTC)
strideynet/tbot-pod-security-context a742638 2 ✅SUCCEED strideynet-tbot-pod-security-context 2025-02-04 09:34:59

@hugoShaka
Copy link
Copy Markdown
Contributor

hugoShaka commented Feb 4, 2025

@strideynet I'm 100% for defaulting to unprivileged in v18. Do you want to do it in this PR or in a followup?

Also, would you mind trying to deploy tbot in a restricted PSS namespace and see if it works by default with your change?

kubectl label namespace tbot 'pod-security.kubernetes.io/enforce=restricted'

@strideynet
Copy link
Copy Markdown
Contributor Author

@strideynet I'm 100% for defaulting to unprivileged in v18. Do you want to do it in this PR or in a followup?

Plan was to pursue this in v18 - so in a seperate PR so this one can be backported. In that follow up PR, we can also include testing/evidence that tbot functions correctly.

@strideynet strideynet added this pull request to the merge queue Feb 5, 2025
Merged via the queue into master with commit 62c28bb Feb 5, 2025
@strideynet strideynet deleted the strideynet/tbot-pod-security-context branch February 5, 2025 09:21
@public-teleport-github-review-bot
Copy link
Copy Markdown

@strideynet See the table below for backport results.

Branch Result
branch/v15 Failed
branch/v16 Failed
branch/v17 Create PR

strideynet added a commit that referenced this pull request Feb 6, 2025
* Add ability to configure securityContext of tbot pods

* Newline at end of file
strideynet added a commit that referenced this pull request Feb 6, 2025
* Add ability to configure securityContext of tbot pods

* Newline at end of file
github-merge-queue Bot pushed a commit that referenced this pull request Feb 6, 2025
…51909)

* Add ability to configure securityContext of tbot pods

* Newline at end of file
github-merge-queue Bot pushed a commit that referenced this pull request Feb 6, 2025
…51910)

* Add ability to configure securityContext of tbot pods

* Newline at end of file
carloscastrojumo pushed a commit to carloscastrojumo/teleport that referenced this pull request Feb 19, 2025
…ional#51817)

* Add ability to configure securityContext of tbot pods

* Newline at end of file
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants