mirror of
https://github.com/kubernetes-sigs/node-feature-discovery.git
synced 2025-03-30 19:54:46 +00:00
Merge pull request #395 from marquiz/devel/read-only-mounts
Make all mounts in deployment templates read-only
This commit is contained in:
commit
8ca1bdc54d
3 changed files with 9 additions and 0 deletions
|
@ -98,10 +98,13 @@ spec:
|
||||||
readOnly: true
|
readOnly: true
|
||||||
- name: host-sys
|
- name: host-sys
|
||||||
mountPath: "/host-sys"
|
mountPath: "/host-sys"
|
||||||
|
readOnly: true
|
||||||
- name: source-d
|
- name: source-d
|
||||||
mountPath: "/etc/kubernetes/node-feature-discovery/source.d/"
|
mountPath: "/etc/kubernetes/node-feature-discovery/source.d/"
|
||||||
|
readOnly: true
|
||||||
- name: features-d
|
- name: features-d
|
||||||
mountPath: "/etc/kubernetes/node-feature-discovery/features.d/"
|
mountPath: "/etc/kubernetes/node-feature-discovery/features.d/"
|
||||||
|
readOnly: true
|
||||||
volumes:
|
volumes:
|
||||||
- name: host-boot
|
- name: host-boot
|
||||||
hostPath:
|
hostPath:
|
||||||
|
|
|
@ -50,10 +50,13 @@ spec:
|
||||||
readOnly: true
|
readOnly: true
|
||||||
- name: host-sys
|
- name: host-sys
|
||||||
mountPath: "/host-sys"
|
mountPath: "/host-sys"
|
||||||
|
readOnly: true
|
||||||
- name: source-d
|
- name: source-d
|
||||||
mountPath: "/etc/kubernetes/node-feature-discovery/source.d/"
|
mountPath: "/etc/kubernetes/node-feature-discovery/source.d/"
|
||||||
|
readOnly: true
|
||||||
- name: features-d
|
- name: features-d
|
||||||
mountPath: "/etc/kubernetes/node-feature-discovery/features.d/"
|
mountPath: "/etc/kubernetes/node-feature-discovery/features.d/"
|
||||||
|
readOnly: true
|
||||||
## Enable TLS authentication (2/3)
|
## Enable TLS authentication (2/3)
|
||||||
# - name: nfd-ca-cert
|
# - name: nfd-ca-cert
|
||||||
# mountPath: "/etc/kubernetes/node-feature-discovery/trust"
|
# mountPath: "/etc/kubernetes/node-feature-discovery/trust"
|
||||||
|
|
|
@ -52,10 +52,13 @@ spec:
|
||||||
readOnly: true
|
readOnly: true
|
||||||
- name: host-sys
|
- name: host-sys
|
||||||
mountPath: "/host-sys"
|
mountPath: "/host-sys"
|
||||||
|
readOnly: true
|
||||||
- name: source-d
|
- name: source-d
|
||||||
mountPath: "/etc/kubernetes/node-feature-discovery/source.d/"
|
mountPath: "/etc/kubernetes/node-feature-discovery/source.d/"
|
||||||
|
readOnly: true
|
||||||
- name: features-d
|
- name: features-d
|
||||||
mountPath: "/etc/kubernetes/node-feature-discovery/features.d/"
|
mountPath: "/etc/kubernetes/node-feature-discovery/features.d/"
|
||||||
|
readOnly: true
|
||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
volumes:
|
volumes:
|
||||||
- name: host-boot
|
- name: host-boot
|
||||||
|
|
Loading…
Add table
Reference in a new issue