mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-21 19:40:35 +00:00
Fix broken globalnet helm jobs
Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com>
This commit is contained in:
committed by
Stephen Kitt
parent
9946eeb071
commit
54b9fab7f0
@@ -29,33 +29,33 @@ spec:
|
||||
nodeSelector:
|
||||
submariner.io/gateway: 'true'
|
||||
containers:
|
||||
- name: {{ template "submariner.fullname" . }}-globalnet
|
||||
image: {{ .Values.globalnet.image.repository }}:{{ default .Chart.AppVersion .Values.globalnet.image.tag }}
|
||||
imagePullPolicy: {{ .Values.globalnet.image.pullPolicy }}
|
||||
env:
|
||||
- name: SUBMARINER_CLUSTERID
|
||||
value: '{{ .Values.submariner.clusterId }}'
|
||||
- name: SUBMARINER_EXCLUDENS
|
||||
value: 'submariner-operator,kube-system,operators,openshift-monitoring,openshift-dns'
|
||||
- name: SUBMARINER_NAMESPACE
|
||||
value: '{{ .Release.Namespace }}'
|
||||
- name: NODE_NAME
|
||||
valueFrom:
|
||||
- name: {{ template "submariner.fullname" . }}-globalnet
|
||||
image: {{ .Values.globalnet.image.repository }}:{{ default .Chart.AppVersion .Values.globalnet.image.tag }}
|
||||
imagePullPolicy: {{ .Values.globalnet.image.pullPolicy }}
|
||||
env:
|
||||
- name: SUBMARINER_CLUSTERID
|
||||
value: '{{ .Values.submariner.clusterId }}'
|
||||
- name: SUBMARINER_EXCLUDENS
|
||||
value: 'submariner-operator,kube-system,operators,openshift-monitoring,openshift-dns'
|
||||
- name: SUBMARINER_NAMESPACE
|
||||
value: '{{ .Release.Namespace }}'
|
||||
- name: NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: "spec.nodeName"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: true
|
||||
capabilities:
|
||||
add:
|
||||
- ALL
|
||||
privileged: true
|
||||
readOnlyRootFilesystem: false
|
||||
runAsNonRoot: false
|
||||
volumeMounts:
|
||||
# Because we don't actually run iptables locally, but chroot in to the host
|
||||
- mountPath: /host
|
||||
name: host-slash
|
||||
readOnly: true
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: true
|
||||
capabilities:
|
||||
add:
|
||||
- ALL
|
||||
privileged: true
|
||||
readOnlyRootFilesystem: false
|
||||
runAsNonRoot: false
|
||||
volumeMounts:
|
||||
# Because we don't actually run iptables locally, but chroot in to the host
|
||||
- mountPath: /host
|
||||
name: host-slash
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: host-slash
|
||||
hostPath:
|
||||
|
||||
Reference in New Issue
Block a user