From f12d1347b27568835c77ca0ab8a59428fa45ea2d Mon Sep 17 00:00:00 2001 From: Paulo Gomes Date: Wed, 4 Sep 2019 21:49:31 +0100 Subject: [PATCH] Update .in and .sed files. --- cluster/addons/dns/kube-dns/kube-dns.yaml.in | 21 +++++++++++++++++++ cluster/addons/dns/kube-dns/kube-dns.yaml.sed | 21 +++++++++++++++++++ 2 files changed, 42 insertions(+) diff --git a/cluster/addons/dns/kube-dns/kube-dns.yaml.in b/cluster/addons/dns/kube-dns/kube-dns.yaml.in index b677a232d3c..dfc4ec6241b 100644 --- a/cluster/addons/dns/kube-dns/kube-dns.yaml.in +++ b/cluster/addons/dns/kube-dns/kube-dns.yaml.in @@ -88,6 +88,7 @@ spec: spec: priorityClassName: system-cluster-critical securityContext: + runAsNonRoot: true supplementalGroups: [ 65534 ] fsGroup: 65534 tolerations: @@ -150,6 +151,11 @@ spec: volumeMounts: - name: kube-dns-config mountPath: /kube-dns-config + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + runAsUser: 1001 + runAsGroup: 2001 - name: dnsmasq image: k8s.gcr.io/k8s-dns-dnsmasq-nanny:1.14.13 livenessProbe: @@ -190,6 +196,16 @@ spec: volumeMounts: - name: kube-dns-config mountPath: /etc/k8s/dns/dnsmasq-nanny + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: false + runAsNonRoot: false + capabilities: + drop: + - all + add: + - NET_BIND_SERVICE + - SETGID - name: sidecar image: k8s.gcr.io/k8s-dns-sidecar:1.14.13 livenessProbe: @@ -214,5 +230,10 @@ spec: requests: memory: 20Mi cpu: 10m + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + runAsUser: 1001 + runAsGroup: 2001 dnsPolicy: Default # Don't use cluster DNS. serviceAccountName: kube-dns diff --git a/cluster/addons/dns/kube-dns/kube-dns.yaml.sed b/cluster/addons/dns/kube-dns/kube-dns.yaml.sed index ea5e6bae54a..97ef30e8de0 100644 --- a/cluster/addons/dns/kube-dns/kube-dns.yaml.sed +++ b/cluster/addons/dns/kube-dns/kube-dns.yaml.sed @@ -88,6 +88,7 @@ spec: spec: priorityClassName: system-cluster-critical securityContext: + runAsNonRoot: true supplementalGroups: [ 65534 ] fsGroup: 65534 tolerations: @@ -150,6 +151,11 @@ spec: volumeMounts: - name: kube-dns-config mountPath: /kube-dns-config + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + runAsUser: 1001 + runAsGroup: 2001 - name: dnsmasq image: k8s.gcr.io/k8s-dns-dnsmasq-nanny:1.14.13 livenessProbe: @@ -190,6 +196,16 @@ spec: volumeMounts: - name: kube-dns-config mountPath: /etc/k8s/dns/dnsmasq-nanny + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: false + runAsNonRoot: false + capabilities: + drop: + - all + add: + - NET_BIND_SERVICE + - SETGID - name: sidecar image: k8s.gcr.io/k8s-dns-sidecar:1.14.13 livenessProbe: @@ -214,5 +230,10 @@ spec: requests: memory: 20Mi cpu: 10m + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + runAsUser: 1001 + runAsGroup: 2001 dnsPolicy: Default # Don't use cluster DNS. serviceAccountName: kube-dns