From 49f88d7945473ebe9862d69710a2f7788e4187d1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Javier=20J=2E=20Salmer=C3=B3n-Garc=C3=ADa?= Date: Wed, 24 Jan 2024 10:38:17 +0100 Subject: [PATCH] [bitnami/elasticsearch] fix: :bug: Set seLinuxOptions to null for Openshift compatibility (#22583) Signed-off-by: Javier Salmeron Garcia --- bitnami/elasticsearch/Chart.yaml | 2 +- bitnami/elasticsearch/README.md | 10 +++++----- bitnami/elasticsearch/values.yaml | 20 ++++++++++---------- 3 files changed, 16 insertions(+), 16 deletions(-) diff --git a/bitnami/elasticsearch/Chart.yaml b/bitnami/elasticsearch/Chart.yaml index e1f982e75a..13f7871664 100644 --- a/bitnami/elasticsearch/Chart.yaml +++ b/bitnami/elasticsearch/Chart.yaml @@ -34,4 +34,4 @@ maintainers: name: elasticsearch sources: - https://github.com/bitnami/charts/tree/main/bitnami/elasticsearch -version: 19.17.0 +version: 19.17.1 diff --git a/bitnami/elasticsearch/README.md b/bitnami/elasticsearch/README.md index 93ea9240ef..f11e55a2a5 100644 --- a/bitnami/elasticsearch/README.md +++ b/bitnami/elasticsearch/README.md @@ -192,7 +192,7 @@ helm delete --purge my-release | `master.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` | | `master.podSecurityContext.fsGroup` | Set master-elegible pod's Security Context fsGroup | `1001` | | `master.containerSecurityContext.enabled` | Enabled master-elegible containers' Security Context | `true` | -| `master.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` | +| `master.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `nil` | | `master.containerSecurityContext.runAsUser` | Set master-elegible containers' Security Context runAsUser | `1001` | | `master.containerSecurityContext.runAsNonRoot` | Set master-elegible containers' Security Context runAsNonRoot | `true` | | `master.containerSecurityContext.seccompProfile.type` | Set container's Security Context seccomp profile | `RuntimeDefault` | @@ -285,7 +285,7 @@ helm delete --purge my-release | `data.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` | | `data.podSecurityContext.fsGroup` | Set data pod's Security Context fsGroup | `1001` | | `data.containerSecurityContext.enabled` | Enabled data containers' Security Context | `true` | -| `data.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` | +| `data.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `nil` | | `data.containerSecurityContext.runAsUser` | Set data containers' Security Context runAsUser | `1001` | | `data.containerSecurityContext.runAsNonRoot` | Set data containers' Security Context runAsNonRoot | `true` | | `data.containerSecurityContext.seccompProfile.type` | Set container's Security Context seccomp profile | `RuntimeDefault` | @@ -378,7 +378,7 @@ helm delete --purge my-release | `coordinating.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` | | `coordinating.podSecurityContext.fsGroup` | Set coordinating-only pod's Security Context fsGroup | `1001` | | `coordinating.containerSecurityContext.enabled` | Enabled coordinating-only containers' Security Context | `true` | -| `coordinating.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` | +| `coordinating.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `nil` | | `coordinating.containerSecurityContext.runAsUser` | Set coordinating-only containers' Security Context runAsUser | `1001` | | `coordinating.containerSecurityContext.runAsNonRoot` | Set coordinating-only containers' Security Context runAsNonRoot | `true` | | `coordinating.containerSecurityContext.seccompProfile.type` | Set container's Security Context seccomp profile | `RuntimeDefault` | @@ -466,7 +466,7 @@ helm delete --purge my-release | `ingest.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` | | `ingest.podSecurityContext.fsGroup` | Set ingest-only pod's Security Context fsGroup | `1001` | | `ingest.containerSecurityContext.enabled` | Enabled ingest-only containers' Security Context | `true` | -| `ingest.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` | +| `ingest.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `nil` | | `ingest.containerSecurityContext.runAsUser` | Set ingest-only containers' Security Context runAsUser | `1001` | | `ingest.containerSecurityContext.runAsNonRoot` | Set ingest-only containers' Security Context runAsNonRoot | `true` | | `ingest.containerSecurityContext.seccompProfile.type` | Set container's Security Context seccomp profile | `RuntimeDefault` | @@ -617,7 +617,7 @@ helm delete --purge my-release | `metrics.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` | | `metrics.podSecurityContext.fsGroup` | Set Elasticsearch metrics exporter pod's Security Context fsGroup | `1001` | | `metrics.containerSecurityContext.enabled` | Enabled Elasticsearch metrics exporter containers' Security Context | `true` | -| `metrics.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` | +| `metrics.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `nil` | | `metrics.containerSecurityContext.runAsUser` | Set Elasticsearch metrics exporter containers' Security Context runAsUser | `1001` | | `metrics.containerSecurityContext.runAsNonRoot` | Set Elasticsearch metrics exporter container's Security Context runAsNonRoot | `true` | | `metrics.containerSecurityContext.seccompProfile.type` | Set container's Security Context seccomp profile | `RuntimeDefault` | diff --git a/bitnami/elasticsearch/values.yaml b/bitnami/elasticsearch/values.yaml index cac41b3acc..2471f14c13 100644 --- a/bitnami/elasticsearch/values.yaml +++ b/bitnami/elasticsearch/values.yaml @@ -543,14 +543,14 @@ master: ## Configure Container Security Context ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod ## @param master.containerSecurityContext.enabled Enabled master-elegible containers' Security Context - ## @param master.containerSecurityContext.seLinuxOptions Set SELinux options in container + ## @param master.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container ## @param master.containerSecurityContext.runAsUser Set master-elegible containers' Security Context runAsUser ## @param master.containerSecurityContext.runAsNonRoot Set master-elegible containers' Security Context runAsNonRoot ## @param master.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile ## containerSecurityContext: enabled: true - seLinuxOptions: {} + seLinuxOptions: null runAsUser: 1001 runAsNonRoot: true seccompProfile: @@ -868,14 +868,14 @@ data: ## Configure Container Security Context ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod ## @param data.containerSecurityContext.enabled Enabled data containers' Security Context - ## @param data.containerSecurityContext.seLinuxOptions Set SELinux options in container + ## @param data.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container ## @param data.containerSecurityContext.runAsUser Set data containers' Security Context runAsUser ## @param data.containerSecurityContext.runAsNonRoot Set data containers' Security Context runAsNonRoot ## @param data.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile ## containerSecurityContext: enabled: true - seLinuxOptions: {} + seLinuxOptions: null runAsUser: 1001 runAsNonRoot: true seccompProfile: @@ -1194,14 +1194,14 @@ coordinating: ## Configure Container Security Context ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod ## @param coordinating.containerSecurityContext.enabled Enabled coordinating-only containers' Security Context - ## @param coordinating.containerSecurityContext.seLinuxOptions Set SELinux options in container + ## @param coordinating.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container ## @param coordinating.containerSecurityContext.runAsUser Set coordinating-only containers' Security Context runAsUser ## @param coordinating.containerSecurityContext.runAsNonRoot Set coordinating-only containers' Security Context runAsNonRoot ## @param coordinating.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile ## containerSecurityContext: enabled: true - seLinuxOptions: {} + seLinuxOptions: null runAsUser: 1001 runAsNonRoot: true seccompProfile: @@ -1489,14 +1489,14 @@ ingest: ## Configure Container Security Context ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod ## @param ingest.containerSecurityContext.enabled Enabled ingest-only containers' Security Context - ## @param ingest.containerSecurityContext.seLinuxOptions Set SELinux options in container + ## @param ingest.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container ## @param ingest.containerSecurityContext.runAsUser Set ingest-only containers' Security Context runAsUser ## @param ingest.containerSecurityContext.runAsNonRoot Set ingest-only containers' Security Context runAsNonRoot ## @param ingest.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile ## containerSecurityContext: enabled: true - seLinuxOptions: {} + seLinuxOptions: null runAsUser: 1001 runAsNonRoot: true seccompProfile: @@ -2096,14 +2096,14 @@ metrics: ## Configure Container Security Context ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod ## @param metrics.containerSecurityContext.enabled Enabled Elasticsearch metrics exporter containers' Security Context - ## @param metrics.containerSecurityContext.seLinuxOptions Set SELinux options in container + ## @param metrics.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container ## @param metrics.containerSecurityContext.runAsUser Set Elasticsearch metrics exporter containers' Security Context runAsUser ## @param metrics.containerSecurityContext.runAsNonRoot Set Elasticsearch metrics exporter container's Security Context runAsNonRoot ## @param metrics.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile ## containerSecurityContext: enabled: true - seLinuxOptions: {} + seLinuxOptions: null runAsUser: 1001 runAsNonRoot: true seccompProfile: