commit | 517332653f7fd5a5b27c6f274f8ebce27793982e | [log] [tgz] |
---|---|---|
author | Thomas Draebing <thomas.draebing@sap.com> | Thu Jun 22 10:15:30 2023 +0200 |
committer | Thomas Dräbing <thomas.draebing@sap.com> | Wed Jul 12 12:58:29 2023 +0000 |
tree | 22c838d32c8ca36237c885ce21aa694186867688 | |
parent | 5423672a21e5741bee13127eabcede7aee3fb8ff [diff] |
Disable PodSecurityPolicies by default to support Kubernetes 1.25+ PodSecurityPolicies were removed in favour of Pod security standards that are configured on a cluster or namespace level [1]. [1] https://kubernetes.io/blog/2022/08/25/pod-security-admission-stable/ Change-Id: Ia1e55c09bfad30fd209e96b3eddbda339edc31aa
diff --git a/charts/grafana/grafana.yaml b/charts/grafana/grafana.yaml index af41105..16e073b 100644 --- a/charts/grafana/grafana.yaml +++ b/charts/grafana/grafana.yaml
@@ -4,8 +4,8 @@ create: true ## Use an existing ClusterRole/Role (depending on rbac.namespaced false/true) # useExistingRole: name-of-some-(cluster)role - pspEnabled: true - pspUseAppArmor: true + pspEnabled: false + pspUseAppArmor: false namespaced: false extraRoleRules: [] # - apiGroups: []
diff --git a/charts/loki/loki.yaml b/charts/loki/loki.yaml index d91343e..fe44174 100644 --- a/charts/loki/loki.yaml +++ b/charts/loki/loki.yaml
@@ -144,7 +144,7 @@ rbac: create: true - pspEnabled: true + pspEnabled: false readinessProbe: httpGet:
diff --git a/charts/prometheus/prometheus.yaml b/charts/prometheus/prometheus.yaml index 94250bb..94a3b04 100644 --- a/charts/prometheus/prometheus.yaml +++ b/charts/prometheus/prometheus.yaml
@@ -4,7 +4,7 @@ create: true podSecurityPolicy: - enabled: true + enabled: false imagePullSecrets: # - name: "image-pull-secret"
diff --git a/charts/promtail/promtail.yaml b/charts/promtail/promtail.yaml index b3adf2b..161a84d 100644 --- a/charts/promtail/promtail.yaml +++ b/charts/promtail/promtail.yaml
@@ -52,7 +52,7 @@ rbac: create: true - pspEnabled: true + pspEnabled: false readinessProbe: failureThreshold: 5