Add security context for permission

Signed-off-by: Benedith Mulongo <benedith@sunet.se>
This commit is contained in:
Benedith Mulongo 2025-01-30 17:53:01 +01:00
parent 9c7b302e0a
commit 85d0b5e73a
Signed by: benedith
GPG key ID: 62D68B584B4B3EB3
2 changed files with 4 additions and 13 deletions

View file

@ -23,12 +23,6 @@ spec:
- "start" - "start"
- "--hostname=keycloak-test.streams.sunet.se" - "--hostname=keycloak-test.streams.sunet.se"
- "--verbose" - "--verbose"
# args: [ "start" ]
# args:
# - "start"
# # - "--https-certificate-file=/etc/ssl/certs/cert.pem"+
# # - "--https-certificate-key-file=/etc/ssl/certs/key.pem"
# - "--verbose"
env: env:
- name: KC_HTTP_ENABLED - name: KC_HTTP_ENABLED
value: "true" value: "true"
@ -78,12 +72,9 @@ spec:
- name: keycloak-tls-secret - name: keycloak-tls-secret
mountPath: /etc/ssl/certs mountPath: /etc/ssl/certs
readOnly: true readOnly: true
# command: securityContext:
# # - /opt/keycloak/bin/kc.sh runAsUser: 1000
# - start runAsGroup: 1000
# - --https-certificate-file=/etc/ssl/certs/cert.pem
# - --https-certificate-key-file=/etc/ssl/certs/key.pem
# - --verbose
volumes: volumes:
- name: storage - name: storage
persistentVolumeClaim: persistentVolumeClaim:

View file

@ -7,7 +7,7 @@ spec:
project: default project: default
source: source:
repoURL: https://platform.sunet.se/streams/streams-manifests.git repoURL: https://platform.sunet.se/streams/streams-manifests.git
targetRevision: streams-manifests-2025-01-30-v53 targetRevision: streams-manifests-2025-01-30-v56
path: keycloak/overlays/test path: keycloak/overlays/test
destination: destination:
server: https://kubernetes.default.svc server: https://kubernetes.default.svc