Skip to content

Commit

Permalink
Merge branch 'main' into qrkourier-patch-1
Browse files Browse the repository at this point in the history
  • Loading branch information
qrkourier authored Nov 19, 2024
2 parents aab2478 + ae748de commit ad78ab6
Show file tree
Hide file tree
Showing 3 changed files with 8 additions and 4 deletions.
4 changes: 4 additions & 0 deletions .github/workflows/pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -617,6 +617,8 @@ jobs:
do
curl -s -X GET http://productpage.ziti:9080/productpage?u=test | grep reviews >> testcase_curl_output.log
done
cat testcase_curl_output.log
cat testcase_pods.log
test/verify_test_results.py
kubectl logs `kubectl get pods -n ziti --context $AWS_CLUSTER -o name | grep ziti-admission-wh` -n ziti --context $AWS_CLUSTER
kubectl logs `kubectl get pods -n ziti --context $GKE_CLUSTER -o name | grep ziti-admission-wh` -n ziti --context $GKE_CLUSTER
Expand Down Expand Up @@ -647,6 +649,8 @@ jobs:
do
curl -s -X GET http://productpage.ziti:9080/productpage?u=test | grep reviews >> testcase_curl_output.log
done
cat testcase_curl_output.log
cat testcase_pods.log
test/verify_test_results.py
kubectl logs `kubectl get pods -n ziti --context $AWS_CLUSTER -o name | grep ziti-admission-wh` -n ziti --context $AWS_CLUSTER
kubectl logs `kubectl get pods -n ziti --context $GKE_CLUSTER -o name | grep ziti-admission-wh` -n ziti --context $GKE_CLUSTER
Expand Down
4 changes: 2 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@ All notable changes to this project will be documented in this file. The format

```shell
Capabilities: &corev1.Capabilities{
Add: []corev1.Capability{"NET_ADMIN"},
Drop: []corev1.Capability{"ALL"},
Add: []corev1.Capability{"NET_ADMIN", "NET_BIND_SERVICE"},
Drop: []corev1.Capability{"ALL"},
},
RunAsUser: &rootUser, (deafault = true)
Privileged: &isPrivileged, (default = false)
Expand Down
4 changes: 2 additions & 2 deletions ziti-agent/cmd/webhook/pods.go
Original file line number Diff line number Diff line change
Expand Up @@ -151,7 +151,7 @@ func zitiTunnel(ar admissionv1.AdmissionReview) *admissionv1.AdmissionResponse {

sidecarSecurityContext = &corev1.SecurityContext{
Capabilities: &corev1.Capabilities{
Add: []corev1.Capability{"NET_ADMIN"},
Add: []corev1.Capability{"NET_ADMIN", "NET_BIND_SERVICE"},
Drop: []corev1.Capability{"ALL"},
},
RunAsUser: &rootUser,
Expand All @@ -161,7 +161,7 @@ func zitiTunnel(ar admissionv1.AdmissionReview) *admissionv1.AdmissionResponse {
if pod.Spec.SecurityContext != nil && pod.Spec.SecurityContext.RunAsUser != nil {
sidecarSecurityContext = &corev1.SecurityContext{
Capabilities: &corev1.Capabilities{
Add: []corev1.Capability{"NET_ADMIN"},
Add: []corev1.Capability{"NET_ADMIN", "NET_BIND_SERVICE"},
Drop: []corev1.Capability{"ALL"},
},
RunAsUser: &rootUser,
Expand Down

0 comments on commit ad78ab6

Please sign in to comment.