gcloud-lab/infrastructure/controllers/base/tailscale/release-operator.yaml
sirius0xdev fbf3e4a55b Fix Tailscale operator: run as root (no longer needs restricted PodSecurity)
The Tailscale operator requires /.config and root-level paths.
Namespace 'tailscale' had its pod-security.kubernetes.io/enforce label
removed, so runAsNonRoot is no longer required.
2026-05-04 02:54:30 +00:00

44 lines
971 B
YAML

apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: tailscale-operator
namespace: tailscale
spec:
interval: 1h
timeout: 15m
chart:
spec:
chart: tailscale-operator
version: "1.96.x"
sourceRef:
kind: HelmRepository
name: tailscale
namespace: tailscale
interval: 12h
targetNamespace: tailscale
install:
createNamespace: true
crds: Create
upgrade:
crds: CreateReplace
values:
operatorConfig:
tags: [tailnet]
operatorSecretRef:
name: tailscale-operator-authkey
key: authkey
logFile: "/var/log/tailscale.log"
waitForLinkLocal: false
useOAuth: false
useOIDC: false
podSecurityContext:
runAsUser: 0
securityContext:
allowPrivilegeEscalation: false
seccompProfile:
type: RuntimeDefault
capabilities:
drop:
- ALL
webhook:
enabled: false