Browse Source

Error in nginx when starting registry-proxy (#4785)

Error starting nginx because in requiredDropCapabilities is dropped all capabilities.

The nginx requires the following capabilities:
- CHOWN
- SETGID
- SETUID

Signed-off-by: André R. de Miranda <andre@miranda.work>
pull/4791/head
André R. de Miranda 5 years ago
committed by Kubernetes Prow Robot
parent
commit
4bc204925a
1 changed files with 10 additions and 1 deletions
  1. 11
      roles/kubernetes-apps/registry/templates/registry-proxy-psp.yml.j2

11
roles/kubernetes-apps/registry/templates/registry-proxy-psp.yml.j2

@ -17,7 +17,16 @@ spec:
privileged: false privileged: false
allowPrivilegeEscalation: false allowPrivilegeEscalation: false
requiredDropCapabilities: requiredDropCapabilities:
- ALL
- SETPCAP
- MKNOD
- AUDIT_WRITE
- NET_RAW
- DAC_OVERRIDE
- FOWNER
- FSETID
- KILL
- SYS_CHROOT
- SETFCAP
volumes: volumes:
- 'configMap' - 'configMap'
- 'emptyDir' - 'emptyDir'

Loading…
Cancel
Save