Flux Patch Replace SecurityContext
Due to the issues with the default PSPs in RKE2 this patches out the seccompProfile
by using the Kustomize replace strategy instead of a merge. Flux pods will function roughly the same although technically they may have the Unrestricted
seccomp profile set by default depending on the cluster (slightly more access than RuntimeDefault
).
Closes https://repo1.dso.mil/platform-one/big-bang/bigbang/-/issues/1075
Merge request reports
Activity
added flux test-ciinfra labels
assigned to @micah.nagel
changed milestone to %1.28.0
removed test-ciinfra label
requested review from @michaelmcleroy, @ryan.j.garcia, and @BrandenCobb
added statusreview label
- Resolved by Micah Nagel
See pipeline history for proof this works on RKE2. Used this MR to test some changes needed for the test stage so that's why there's some failures and weirdness, but the important part is that Flux and BB are coming up
mentioned in commit b62bc48a