Skip to content

Commit c2a9884

Browse files
authoredNov 7, 2023
[bitnami/minio] feat: ✨ Add support for PSA restricted policy (#20501)
Signed-off-by: Javier Salmeron Garcia <jsalmeron@vmware.com> Signed-off-by: Javier J. Salmerón-García <jsalmeron@vmware.com>
1 parent aeb337c commit c2a9884

File tree

3 files changed

+124
-89
lines changed

3 files changed

+124
-89
lines changed
 

‎bitnami/minio/Chart.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -34,4 +34,4 @@ maintainers:
3434
name: minio
3535
sources:
3636
- https://github.com/bitnami/charts/tree/main/bitnami/minio
37-
version: 12.8.19
37+
version: 12.9.0

‎bitnami/minio/README.md

+92-82
Large diffs are not rendered by default.

‎bitnami/minio/values.yaml

+31-6
Original file line numberDiff line numberDiff line change
@@ -393,14 +393,27 @@ provisioning:
393393
fsGroup: 1001
394394
## MinIO&reg; container Security Context
395395
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
396-
## @param provisioning.containerSecurityContext.enabled Enable container Security Context
397-
## @param provisioning.containerSecurityContext.runAsUser User ID for the container
398-
## @param provisioning.containerSecurityContext.runAsNonRoot Avoid running as root User
396+
## @param provisioning.containerSecurityContext.enabled Enabled containers' Security Context
397+
## @param provisioning.containerSecurityContext.runAsUser Set containers' Security Context runAsUser
398+
## @param provisioning.containerSecurityContext.runAsNonRoot Set container's Security Context runAsNonRoot
399+
## @param provisioning.containerSecurityContext.privileged Set container's Security Context privileged
400+
## @param provisioning.containerSecurityContext.readOnlyRootFilesystem Set container's Security Context readOnlyRootFilesystem
401+
## @param provisioning.containerSecurityContext.allowPrivilegeEscalation Set container's Security Context allowPrivilegeEscalation
402+
## @param provisioning.containerSecurityContext.capabilities.drop List of capabilities to be dropped
403+
## @param provisioning.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
399404
##
400405
containerSecurityContext:
401406
enabled: true
402407
runAsUser: 1001
403408
runAsNonRoot: true
409+
privileged: false
410+
readOnlyRootFilesystem: false
411+
allowPrivilegeEscalation: false
412+
capabilities:
413+
drop: ["ALL"]
414+
seccompProfile:
415+
type: "RuntimeDefault"
416+
404417
## Automatic Cleanup for Finished Jobs
405418
## @param provisioning.cleanupAfterFinished.enabled Enables Cleanup for Finished Jobs
406419
## @param provisioning.cleanupAfterFinished.seconds Sets the value of ttlSecondsAfterFinished
@@ -429,14 +442,26 @@ podSecurityContext:
429442
fsGroup: 1001
430443
## MinIO&reg; container Security Context
431444
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
432-
## @param containerSecurityContext.enabled Enable container Security Context
433-
## @param containerSecurityContext.runAsUser User ID for the container
434-
## @param containerSecurityContext.runAsNonRoot Avoid running as root User
445+
## @param containerSecurityContext.enabled Enabled containers' Security Context
446+
## @param containerSecurityContext.runAsUser Set containers' Security Context runAsUser
447+
## @param containerSecurityContext.runAsNonRoot Set container's Security Context runAsNonRoot
448+
## @param containerSecurityContext.privileged Set container's Security Context privileged
449+
## @param containerSecurityContext.readOnlyRootFilesystem Set container's Security Context readOnlyRootFilesystem
450+
## @param containerSecurityContext.allowPrivilegeEscalation Set container's Security Context allowPrivilegeEscalation
451+
## @param containerSecurityContext.capabilities.drop List of capabilities to be dropped
452+
## @param containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
435453
##
436454
containerSecurityContext:
437455
enabled: true
438456
runAsUser: 1001
439457
runAsNonRoot: true
458+
privileged: false
459+
readOnlyRootFilesystem: false
460+
allowPrivilegeEscalation: false
461+
capabilities:
462+
drop: ["ALL"]
463+
seccompProfile:
464+
type: "RuntimeDefault"
440465
## @param podLabels Extra labels for MinIO&reg; pods
441466
## Ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
442467
##

0 commit comments

Comments
 (0)
Please sign in to comment.