Skip to content

Commit ff9d9c1

Browse files
committed
Enable user namespaces for the operands
Use restricted-v3 SCC policy for all operand deployments.
1 parent da1e14c commit ff9d9c1

File tree

2 files changed

+4
-4
lines changed

2 files changed

+4
-4
lines changed

bindata/assets/openshift-controller-manager/deploy.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,13 +33,13 @@ spec:
3333
name: openshift-controller-manager
3434
annotations:
3535
target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}'
36-
openshift.io/required-scc: restricted-v2
36+
openshift.io/required-scc: restricted-v3
3737
labels:
3838
app: openshift-controller-manager-a
3939
controller-manager: "true"
4040
spec:
41+
hostUsers: false
4142
securityContext:
42-
runAsNonRoot: true
4343
seccompProfile:
4444
type: RuntimeDefault
4545
priorityClassName: system-node-critical

bindata/assets/openshift-controller-manager/route-controller-manager-deploy.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,13 +23,13 @@ spec:
2323
name: route-controller-manager
2424
annotations:
2525
target.workload.openshift.io/management: '{"effect": "PreferredDuringScheduling"}'
26-
openshift.io/required-scc: restricted-v2
26+
openshift.io/required-scc: restricted-v3
2727
labels:
2828
app: route-controller-manager
2929
route-controller-manager: "true"
3030
spec:
31+
hostUsers: false
3132
securityContext:
32-
runAsNonRoot: true
3333
seccompProfile:
3434
type: RuntimeDefault
3535
priorityClassName: system-node-critical

0 commit comments

Comments
 (0)