Apply docker-default AppArmorProfile for etcd pod

Change-Id: Ia086ca3d28f1a1e4ac013d0f29018faf027b914e
This commit is contained in:
Alexander Vlasov 2019-05-14 18:33:21 -05:00
parent 09ce03160a
commit 1f5c57d1de
2 changed files with 7 additions and 0 deletions

View File

@ -30,6 +30,7 @@ metadata:
{{ tuple $envAll $applicationName "etcd" | include "helm-toolkit.snippets.kubernetes_metadata_labels" | indent 4 }}
annotations:
{{ tuple $envAll | include "helm-toolkit.snippets.release_uuid" }}
{{- dict "envAll" $envAll "podName" .Values.service.name "containerNames" (list "etcd") | include "helm-toolkit.snippets.kubernetes_mandatory_access_control_annotation" | indent 4 }}
spec:
hostNetwork: true
containers:

View File

@ -58,6 +58,7 @@ network:
enable_node_port: false
service:
# requires override for a specific use case e.g. calico-etcd or kubernetes-etcd
name: example-etcd
ip: null
@ -142,6 +143,11 @@ pod:
requests:
memory: "128Mi"
cpu: "100m"
mandatory_access_control:
type: apparmor
# requires override for a specific use case e.g. calico-etcd or kubernetes-etcd
example-etcd:
etcd: localhost/docker-default
jobs:
etcd_backup: