Fix Tailscale operator: add securityContext for PodSecurity restricted policy
The merged PR was missing securityContext/podSecurityContext values required by the namespace's restricted:latest PodSecurity policy. Without these, pods fail to create with FailedCreate errors.
This commit is contained in:
parent
21cebbc763
commit
2ab4a78825
1 changed files with 12 additions and 5 deletions
|
|
@ -22,17 +22,24 @@ spec:
|
||||||
upgrade:
|
upgrade:
|
||||||
crds: CreateReplace
|
crds: CreateReplace
|
||||||
values:
|
values:
|
||||||
# Operator configuration
|
|
||||||
operatorConfig:
|
operatorConfig:
|
||||||
# Tag to use for pods created by the operator (e.g., tailnet)
|
|
||||||
tags: [tailnet]
|
tags: [tailnet]
|
||||||
# Auth key from secret - PLACEHOLDER, replace with real key
|
|
||||||
operatorSecretRef:
|
operatorSecretRef:
|
||||||
name: tailscale-operator-authkey
|
name: tailscale-operator-authkey
|
||||||
key: authkey
|
key: authkey
|
||||||
logFile: "/var/log/tailscale.log"
|
logFile: "/var/log/tailscale.log"
|
||||||
# Don't block pod startup if Tailscale auth fails
|
|
||||||
waitForLinkLocal: false
|
waitForLinkLocal: false
|
||||||
# Disable webhook (optional)
|
useOAuth: false
|
||||||
|
useOIDC: false
|
||||||
|
podSecurityContext:
|
||||||
|
runAsNonRoot: true
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
runAsNonRoot: true
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
webhook:
|
webhook:
|
||||||
enabled: false
|
enabled: false
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue