-
Notifications
You must be signed in to change notification settings - Fork 690
Open
Labels
Description
Please confirm the following
- I agree to follow this project's code of conduct.
- I have checked the current issues for duplicates.
- I understand that the AWX Operator is open source software provided for free and that I might not receive a timely response.
Bug Summary
The docs for security_context_settings show container-level only settings allowPrivilegeEscalation and capabilities, which do not get rendered into the Deployment templates for awx-web and awx-task because these settings are applied only at the pod level.
AWX Operator version
2.19.1
AWX version
24.6.1
Kubernetes platform
kubernetes
Kubernetes/Platform version
1.32
Modifications
no
Steps to reproduce
This gets rendered at the pod-level:
spec:
security_context_settings:
runAsUser: 0
runAsGroup: 0
fsGroup: 2000
fsGroupChangePolicy: OnRootMismatchThis (from the docs) gets rendered no where:
spec:
security_context_settings:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALLExpected results
Fix the example in the docs and explicitly state whether security_context_settings (and postgres_security_context_settings) apply at the pod-level or at the container-level.
Actual results
spec.security_context_settings.allowPrivilegeEscalation and spec.security_context_settings.capabilities do not get applied to container-level securityContext.
Additional information
No response
Operator Logs
No response