Skip to content

Commit f3ac6a4

Browse files
committed
Allow privileged on gitlab runners
1 parent 7c1c399 commit f3ac6a4

File tree

1 file changed

+9
-1
lines changed

1 file changed

+9
-1
lines changed

k8s/gitlab/gitlab.cue

+9-1
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,14 @@ let nodeAffinity = {
2929
kustomizations: $default: #dependsOn: [dcsi.kustomizations.helm, cnpg.kustomizations.helm, rook.kustomizations.cluster]
3030
kustomizations: $default: manifest: {
3131
ns: #AppNamespace
32-
runnerNs: c8s.#Namespace & {#name: "gitlab-runners"}
32+
runnerNs: c8s.#Namespace & {
33+
#name: "gitlab-runners"
34+
metadata: labels: {
35+
"pod-security.kubernetes.io/enforce": "privileged"
36+
"pod-security.kubernetes.io/audit": "privileged"
37+
"pod-security.kubernetes.io/warn": "privileged"
38+
}
39+
}
3340
"gitlab-db": clusters.#Cluster & {
3441
spec: {
3542
instances: 3
@@ -245,6 +252,7 @@ kustomizations: helm: manifest: {
245252
[runners.kubernetes]
246253
namespace = "\(kustomizations.$default.manifest.runnerNs.metadata.name)"
247254
image = "alpine"
255+
privileged = true
248256
[runners.kubernetes.node_selector]
249257
"kubernetes.io/arch" = "amd64"
250258
"kubernetes.io/os" = "linux"

0 commit comments

Comments
 (0)