Fix Tailscale operator: add securityContext for PodSecurity restricted policy

The merged PR was missing securityContext/podSecurityContext values
required by the namespace's restricted:latest PodSecurity policy.
Without these, pods fail to create with FailedCreate errors.
This commit is contained in:
sirius0xdev 2026-05-04 02:26:09 +00:00
parent 21cebbc763
commit 2ab4a78825

View file

@ -22,17 +22,24 @@ spec:
upgrade: upgrade:
crds: CreateReplace crds: CreateReplace
values: values:
# Operator configuration
operatorConfig: operatorConfig:
# Tag to use for pods created by the operator (e.g., tailnet)
tags: [tailnet] tags: [tailnet]
# Auth key from secret - PLACEHOLDER, replace with real key
operatorSecretRef: operatorSecretRef:
name: tailscale-operator-authkey name: tailscale-operator-authkey
key: authkey key: authkey
logFile: "/var/log/tailscale.log" logFile: "/var/log/tailscale.log"
# Don't block pod startup if Tailscale auth fails
waitForLinkLocal: false waitForLinkLocal: false
# Disable webhook (optional) useOAuth: false
useOIDC: false
podSecurityContext:
runAsNonRoot: true
securityContext:
allowPrivilegeEscalation: false
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
capabilities:
drop:
- ALL
webhook: webhook:
enabled: false enabled: false