From fb0ffb07a76dd34c4b83d1e7a9b49ab1334a1bf5 Mon Sep 17 00:00:00 2001 From: Paco Xu Date: Fri, 20 Oct 2023 17:05:59 +0800 Subject: [PATCH] kubeadm coredns use drop ALL instead of all --- cmd/kubeadm/app/phases/addons/dns/dns_test.go | 4 ++-- cmd/kubeadm/app/phases/addons/dns/manifests.go | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/cmd/kubeadm/app/phases/addons/dns/dns_test.go b/cmd/kubeadm/app/phases/addons/dns/dns_test.go index 3cc0c88caf2..487b547673c 100644 --- a/cmd/kubeadm/app/phases/addons/dns/dns_test.go +++ b/cmd/kubeadm/app/phases/addons/dns/dns_test.go @@ -742,7 +742,7 @@ spec: add: - NET_BIND_SERVICE drop: - - all + - ALL readOnlyRootFilesystem: true dnsPolicy: Default volumes: @@ -1007,7 +1007,7 @@ spec: add: - NET_BIND_SERVICE drop: - - all + - ALL readOnlyRootFilesystem: true dnsPolicy: Default volumes: diff --git a/cmd/kubeadm/app/phases/addons/dns/manifests.go b/cmd/kubeadm/app/phases/addons/dns/manifests.go index 931897b16e2..905a2e050e6 100644 --- a/cmd/kubeadm/app/phases/addons/dns/manifests.go +++ b/cmd/kubeadm/app/phases/addons/dns/manifests.go @@ -141,7 +141,7 @@ spec: add: - NET_BIND_SERVICE drop: - - all + - ALL readOnlyRootFilesystem: true dnsPolicy: Default volumes: