From 294b274139566c2dbe6a2886a26c041666ad025d Mon Sep 17 00:00:00 2001 From: umagnus Date: Thu, 13 Jun 2024 07:07:17 +0000 Subject: [PATCH] Fix shield guard issues for KSM --- charts/latest/csi-driver-smb-v0.0.0.tgz | Bin 4943 -> 4973 bytes .../templates/csi-smb-controller.yaml | 9 +++++++++ 2 files changed, 9 insertions(+) diff --git a/charts/latest/csi-driver-smb-v0.0.0.tgz b/charts/latest/csi-driver-smb-v0.0.0.tgz index 92fcb3ff302220ad9bf7a6bece5397d0b983574d..6a0a322c1d56ef0f754f8888c2da672c9cd31b3a 100644 GIT binary patch delta 4959 zcmV-l6QJzRChaDWJAYk!Z`(MwpT7-CNg57pmZuUG!t>mLuk>mME;3|!#jZA!Sn z?7QC9yvmjPMiP$6AHX=Fk&9;i7LMcWYk&oC(eiF9*AP<|F_;i8*t~Q16Ymh(D_qa#?4b6PZ(MRR-yo&I1o zPY0w59Co!Y88b7 z)!rPpT5N>9vdA*G8X4tq*wVe?<{x%EPE1d>T4TT>VM^s7!lM9w0r3Y7k`RUh3vNiZ zax!M5s4RzD3AE`a?^7=IW4AY%F}<>CSaLN5`XVG>B*NDl}u zI)gDz0`aP@RPjX%p%4Tk9>1bYxM=Xd$A^b@qnZK^#B`BOY6nZA%ji9pBCc9 zv#S6{uy_^F$?q_Oz(q$bgg#MrN21AlsSsy`xv1S0Vcb?t!D+%g;F`6~yGR*BB6#{u zR(~W^Du2-Hy(i`=gMTN$^SQh@aZ$e)R*DVMQkJ^cGwW~3Ec4R!ECyS#z~eEAh?u+R z;n7&b5CZT7W#*Bf0Wd6Kqao{{JD9tut!#zS06GirA$>`xI=pQ-(pZ+3)Y|9wgbSX& zfbkeS;iC2h9ePvnlK|R{=o_nurS3dA7k_69HZA2_qz&Qw4^d`|+JK9?-oT&^8uV5x zAW?F^a5;YFxO{$5a4oVZdWn1tA&oc)<$0ddugKO8K)9$o!>k*SQP(_?@7U<*6nj%R zBTQ9Jc2rx6n|@d0!5y#>Fv_Kq_8}4k2gsAfULgo$F-Kf55=~GDIO53H68=!;*MCjP zbbmCguNaKUy7Yc||=_jgm+=RX>wSDx3z-qeP$(&m~;Wv=xOoN^lU&5e_(2#Pcet zc-HA-QJ3^kQyF`ZMB7Z`)%L{=dh_At*URg7H-FyV4*wk9oWE~peU=STrhgII6=ihO z%C%Zv!UYX~$0GpZ6bI2U!cjzp7EXeG?EC6Z5FjxH6jPtKV(PzH!M7^MP@=7@t3a;U?I z8*-7qX2XkyINhd7{fP;O3nDdQMAt=0`i-W0sMa%t_y1QrQ@h2j7(2Who# z%K#Qn1juou|K~CG;D6-d0d=lHZTvJT8N{3Ios7Ga``>kw630{F4)-Nf1at$3W=r&5&hH*UADzoqwS$ zIcZhE>uQlnvMoPzRUw9>2`nuq=gPX*WaH&4VE-t^`G3*|UrM$9zcAZV^T&;Y!Ylm$ zLGN|R{||bHy~Dl#e~whLj=H6)$Hy0~I}-UWI#aX$A&3{P{N529$Gki1zi5RZu#W|H zUu0n^X&iO*_2L4O^mTTH|8yA}EPNr|3yHiS@k_qEllLq#BagvTQY5jD1q=nl0w#0y z2q8v;fPX}j59*zHR$Xz=iLREzitmls2$>0Ho}_${;#NaGlyKCn4x|im9Iw$psd=UZ z7j503RgN=p*Jq57X-%mwpNN>&m&>gI8jnr?|fkB^micCv1LK7l6^KAA=iI5d@F zOMgy=wAr2J3Q45^2!T49ztKa~jJ@M3sWLJnRC!*{ZPD$u3;_UJJ+z z@ufUEs{v=$YG#LH@%}T4asz&WUT&&dB%KS0 zEz0C#X|83$Un*9B8TpBE1}v*cCRhC&o+-nbdNfmJV}Wbtd2Z{9z4@~Y3tGiJiWOi~ ze4V4Upim5OE~|bC9IjJkz2u$`nYu`A^{G>(ysa!Y;pONp-@N6bcDt-q^?F-omVe*e z*MMbVr`1x%uWXF%0owX1onLf zoS%IE!<)0S>+|98M@z;4un)`uvwz!Rb&dvcJPQ%H7YsXk(00-RQ*DOIXNG82uAtT{ zQ-Q)eq&F10Na9xcufwT#x9+Sb-};5QPma(`ZN*lbiz^+VHdb9>G1YREBsAN-sdop$ z@d?W>NMyUCY#yTkU`)o6xH&J<9~1>H`=o+Y46uJ01@mi4#m^)Fz5k;yJb&us;TVrd zKm>tOwGr|ejmys*^yc^9D=s13_T}iK5e+;-VWZe?9l{dQRog6P-q0QFienRJP&E5G zv(PzJZ#aU4KofCtz$+Q1Lc|V4eoRRuP6F!TK%yzvj+cs(FZLrBh1Qg3Cxf-Dv`Bjs zBVA&KGS%Dg21Z(t_8YNL9)FIS7^VaWJ2l4&!Kz8fEE}5MCe+Jjwpu$=)MV31`-tt# zPHK$E?DMY~LQ`A({)f}yyN~A=XIGc+E^cgtx;coGxdL?xx6`Y!-Q2MqJ7>LElTk1SxMrI^{ zN$yC?B0ZC5eIn3UDu3M6o~#T+7;g_rc{r*W<8=Kkb3|*!)S(!4a_`}>QlctpA^VqJ zPyN=?%JqNa*|)h7VAcNL!JxeV_w{kFzhD1NRKE*jIz=zZ=;(wA7!IWgSpXiA~gQZ687AYz% z3ooF3!+F!Gdw*LubJF(?sTsq5wfVVLn@fvQ8>~00RSGAjOq`V6^X99|+b=+@ee4lhrC`*`){=6}~8n=N9(y@pl!&ZaUL&U;@t5f<}wemAZM$-ova1!na0Q;-@3hR z%m3t`$H&`SJt*?q+uE7?3i*Ef@b>)U#pT)g$BQ@b&uxX@Heu!am~n z(kzYjZ4z;-j}TTeN(qR6^8F7*qb_GuK}R_ub|xSkZ95JZSn#}5=JLXh?dC#z?erx@ zYN;vI*AzLvx~IrV^hHG{78kelW~1$5hHGKWbbppn6P0_m&|!n%pzYmPAM$H9T0X^S zRJs?tnxVmPwR(U_am&)dVaX8x_;~vi1J~m0@0dF=iNUEfL5|SvZRb{Iy3G~Kf~n<_ zRTk3nH{l`6m5RJXVhS9TIdFs-ATCG{q-zzvIY1u9SP&J?oxhSL=6_>=60YuF%M+tf zFn^bWqPp;a`XEO~Ls32&fxyTdzEAH$I32!2i#u zY!Dh=p@iyyrxd#Aj@Hx2rrNkBvyy7=Of7e$lIy7BHqBh5wU%CP)Zli0OHlYSF3Y{H znL&L_@8K@GVI3>TE+MUmWOw_UOS2Yp>wnm=bxSOnN-mS`lAY?aTVL@N8UNL(QT%ty z--B2Y|2^zg_kRoyj`#83=SZbMlsX)?%jmBrxR3qX+v2Grzg12;{S^+5?j+7DOSBe4 zWAkI9rscOiF>@7pw z+J`JwAG&7sp7?o|vY%!u75=)9aIOXFzJK~i?&<;IYmMUW=4}3wbEwaJIJ7*5S_c$HV?4q7 zH=o}U{qt#rMmVrapvov;k)K*dU@^qv&$FR+yE;8-Ciddz*LF~WOtMV=iYH%h6kRLc z*)aIBKKN-Ad1;_dn~S)S1SNIaSwm&fy3NF@AhC`0eBGK<>227zwR*k}zkmHjQ*Hc@ zjj-pKAmEe6|9S_9uU}W=fBWBmdX`jKnlD~lsoaS23gv_1*~#!>p~&)R;EH=OcNrRd z3V9b%nO#cy@Q`}pau7}0;IckY?{Olgl#&0aajAN4U;kj&H4R{SRTV9R8yvV7a>5wo z?{8FBa5kPuMEezL z2ZXD?>Sw*=2i-LClP`yQP~|pY=mnUBjk)SzvyE5r@&p@alfw%z=MC%Guud?8NNmt@ zrZ%roJFa85x>_D5(l&Nlp{)pdlro=0d7H5DP*(dijb`nA6B4xW`&gGU?yAwgC6P~} zNprJrZseu=S)Gw#)p+woGWtL8gt2m~b6p_MbuLG4;#{ROGL!zQquboQp{x^^G;_{l df9c_SpY~~=_G#nv{{a91|Nm`=`&|H#007uoz4HJ7 delta 4929 zcmV-H6Ta;2CeJ32JAXZEZyPtZ{VX8=flvyx-J8+Fuk;S!4~d<&K{vKxIb9U%ML^9Q zNxYsJ&XOF(TG#*mf{%G~q|w7px)p)M(hPadA$eXrhon4C9G{UnFo%cZ{@DyO(Ocj! z_-1!yFc=I@j*isd!C+ARI~blEd^0>c8NNO~IXoPmd@~px4Sx;~zCnW>($H8EE-?FM zur;n~=l&!G$K*F)oY2Tc^I-?aarQO90=Ve-z&%D{p`MLCyhUfD_vl=)44P1eeoe-} zA`rkk5e~scWtQs9Gw_4npf~7z=^pP(u~g)Lj)MgFjupUi`5z7rUmsWH|KRoOz5G8% zAt9cE+d*iIIe%P3OkKoaO1NN)-rbM9M`)juslx?jcnTeacsQ2T5n>QiP6TBO7fn4T zYu^3H9WL;cL{q2Gs?Wo593)c`sfGeiUF6{ivxWK|CqZyU1L7@Q^nP+d#T5e%k?0_) zO0F246RALe)$uMNwJ$k4&Ku{b=SNBptw0@+IYhwu6@Q~+SPygBG?q;Zcn^BRgVl&5 z>VsCV*BS@jpyLuqD%UIpQzoUw7b30FA*k@s)*I z(4>b(Ab*gcXo3R{h)m=|^chF$VZuRvXNZ1|dJ-Rv1fxL!Oj|P^j-C9O!?BsB{H+>q zjyoMT#$J_VSzB2~X%0JjR@~ylp2vxq$xdeiSR_ob97K2=z|SClqd^kFNMOMY$WDRA z3{;)gj+(ZBc$m9r*g?pTcslB5LBa*Fp9tgPAAdy5exY1kfI#Ra!gEXli5qEy;G%Pw z;3N>Qnp%}#bPx(bFyiqm%7lv!{`chQ$Szbfz=4?M)g*VYB)W_~U=Qi za0L0QfKLAoa|m2?+(GCwWp^Z+evk}tPMC|jeG$f8H58mC%mc1b+q8?MF(iVg-(*KZ z#eedLgTV)4o-+7%0=!tuixU?O2Vt$*LE6gF_hw|nEsOB8jLiSttGVXyL-X~PhY@f z0-kVD_kxbR8Td&6-B$38RK${Zo*av_1%H~3(k)Vk@cqXqlSM7SWnOO~P=_sMs}qnY zxzAOOpD8Y%UzAjfY>HkYA45nZ4nk?3=hQ25v;z<>>d!Ij2V~qgPvko`K0d?V49*Et zos$#QmE@-1l|8rvHU>tyRMI{~g5Usove_#HVJsGi3r3+}l=(lIpIE`-0pH|6rj3ZML3++F=L?5F7I9FZ- z4j5p6fo9m3VuF;G#^?Ns?Qge%Gj1HVDuq(^0wxl9zkJ9BU6 znB4|sd}|(lr`RE+a~OSi`vJ!>iGQZ&iDa{nQK56ird{f1_6>A=EG>J#s zu;!L1pN=&Rin427W6zYMq^Fy*pQ$7nPCL)zM4%8aq`RDPD++Ox;2>Ba9B`_D7gvX(?3mX0%k0H>wU%o_V(g*e=IfzaWjv^{Fank9>zOViS0TMGnG4**Trv96}mK{u> zP%ME^ra>BOxhz8%T`@u#5sR|`a|Hk*o-niYkgX9<*qqEElNQ8hlnFcqEJyHpMofK(1G)gE=9HE)ilNu(+)(7rz`Luq)_P1}k?>b24ghnIQtNh% z!{UhmIgZr-JjNcJK7Tx*-ZiLty^HiIdVG{LXkd=RjUhPg;yA9jBoa~$2zq?%BFFiR zg*V$v`Lfa||DR?M#K3q@#M`C=SG_+(g-|C6J`;a>iqqdYwH|AyuybfsxV(q2kq zc^b-L@n+znzx5vI7%jRG2L}?U=aE0vnI_rWpcGW zgCNY88^}tRuC9UU&(g=ND;MP!N1k+5Z7RmvCd3h*g71tMl~yAYt8Qv&eBy@(luBW7 z5POa7vIMKbrhmuwO_s+s&E%-`_^huct5nr=#>t^1&CB=R8==s*p>1}A6JIg0k@kQs3M81p8)vA94;zg&pcLc{V@6U%XIw1(`V}acl zSz1a8M-zMDMB2_YYb2-o+-e5 ztXquANk;Dah!HZQDf#6y5wqrYg&0r)VKFlFqG%#=`hGOio2t#UX?2C4_rc)4j8nKM zD>KT)6{8+-lQAv6%%TVvEBP}GR-r%8zY{9d%6}vUHPb1I&y?Mjag>5rZN{wFAZ7A4 z15|^om^6*J6~-_N!mT;>mJm^4v}$h)qm)8W3Z}@JB?H~Sp1F}POsZ4Ja;sr`k=phd z<~sL+y8Uk1V&`L=Z(k_M0YZ8UjCP4iP17wg=<%`k&JNaXt|#zRx=&`10}gGe*b-A| zI)5`nSB2dd&5-gv8YT8{C>kAuhdafk`6mG_>>P+B$REmy;e<>ckb@F3_8;N_(B`#HH^wfxMJo zDtc!P&Y88FnNL=B$=Z5kjSiU=S;3~}PJerrb4u5mmF0K-{tpxt41Nh-VX0aMT}X)K zZ3?+G*RtTRG%L9o#f5R^Sk^t6LiY>)Ox2xf_GYSREbf|lUf8-~AO5UD4y(LJvE~?+ zUl(BI5XuS8W!~%(qo!#edCx zEl`$rS}n!Axfk295?)!66xpJhjI2vzwXszuD-zkn8s)W?WvR6ev#jN**B$jHKRw%k z-OgDr?8q#8ygTsN8(~|$>0)i;Qx~20mcILraF(SSA^oB-P%J(P6YOS z2ArRM`~92q^Xqq`(GQl20bn1P1Ak_>!|EC>@^}^?a4#5kw9$4_gQ+${6)QtDuXa%L zmFYm~9nu>LT_pWh`LD;Rcen1Ur#SkhwNC-iTy4cxn~Q4`pf*-rVKLKmR46pty{UHx z!tn_!1|+iGQ8tZHa$row3b_R>GCU{~T-8Y>su*DZG71*gl!~870DAvN$$vcN1D|f% za`eH57V=!$=CxaKUIMx?(b3iGZowh`sB&^9r(uBm3j5hMhfh|@z}t1uHHb|CU& zN+NL@P!9*v7jo_1PMPw2H*uM04S9Zgu$GLKVQ(U0ON2<4W(nLt#7fjYi-hrT+(xXV zao(vg)d1ERT2|Rma5jNn6@QY|yp?(^Hjc7eOJ{!CAOdEOeS`T*CF$Gm&qnV*y}LNS zx_p0eV>77c5KJb>>I7_W&>(q*BQti)I#84Ccrg(4({zz&X=V<@I7&FA&@^s zET*h3j+y_b&l|Mqm(?noDwTIJqk?)gaM8`#RpFg=_pmM#OoD{L&3}vmpV7eA$0YJ1 zb>YuYkx{)ibWx@nt8{3EqIKbasxO!Hysa*ki&=t$a|rNa1Rjli?xMp%sg6WdkflK`fL<0N@$r5B&b-KsQhD-BizB8<0p z=6E=6urIp*merNDV}I&6i8}N4@K|e6r?gc4OGhI2fDYwt%h3{~aG3998pwuaA!Q@_+vvrD6Y9w(YCB>udeo zU)6{?KXPDYWzn6y(QZ>D9lsfII{bHyVqG35i zzgq!WiJ;E3wk8`2%Tr))CpcvuU0;~Yg%81e)ntOxgCX@9UC;W?C$`fzFoRWT+FVb+u7 zVb&c7QkQ9v9GtEDcCZ$A&kRQK_}1-hSN;r_}4J0zcKH$J(n)360eK&VhJ;UD^;vbCO1zr7MzDNt;>Cn zw0VgeSAPL1R^GxISO#FFP1t80zg*T)yEIGljhkfsnzNL(ijo52pMLv&S*WWORpL`F zh@B}2N6U`G1s1$WmASmIXS=!3-aCCskqR}1`kErgSN9Y-iN2`l)S}{+-fXm8-f}G; zGhJmgWCoutec2*GX?yq8rybi_%crnLm3y)46@OZotJMZ3^;?!2hb1Qd@$vR43|D^k zcfy^R#NgD1paAIhws$Kl-4>c<3EgVTItnTIo8XY`DotJ@F#`@t95})Z5Emo}(pZIW z4v>d27Gz8UA{MV?i^X>gP{P&yYeir*3Kr5RstXUO57Igsi1N`G1V-lYeR>zd+2}pW z?|-~)Gp-WK7K2-FzI24w$EJt5+HPI9WP=3v3MNzsJSEX(b+jHww&lh(kyTi8XKcA6 zmRyG&w;AR#thM-ZqXD<$TjGT;!?IlKnibTi^d9cA8rHdj>=M!%Np`irIW=n`x7voS zM`FoRav61(>`b5C`iif}_^&Rl^1oaD9)HA&{O{4AzW?Lkc(Bj^K1Zn}qSWEAU1onZ zz}_zL^p20pE=uI z8x1`}U-ik!ZS&!6c0=#8;r~6Sx3@>i4cUKQd$ZWF}c=ot2vDQ>Mp^5{d~L?8N%(TB~>g6}qsyuoSJO_Ip{jZ(-} zwY*Ot?-R&tpL1=>AzPt7K@$0njgKAui%X|rvQ>F3OeT;N1r|zrIbsR9A4e?i5P`?c_Mp3ICbVB<3#qXSe&WPQ{!0 zXE&Dp;Q}IIoFh|d4s5I{On*UiU!iV5xcaMp)=PfSLnA-=($s@$w*f*gz$9#qRVSNm zxXPC&*f5(KUVu4o+0T}Jf;mKDgOM}6d4;-h6S~#i@;H&QvC|H11<<3E`6MdJgbjz1 z+NT*b>+GA9patK*lyKLD_AQBg5>4BSeS0CV+|TNa4XW0gFOu>9fjTFQlv|Z+?s=|r zIdU82DwUC0^w$;L=IRY)lelD<3mW@No9}(umwnlnjm!TB00960(l0Z|0FVFx;NzJU diff --git a/charts/latest/csi-driver-smb/templates/csi-smb-controller.yaml b/charts/latest/csi-driver-smb/templates/csi-smb-controller.yaml index 5f86404efa5..3d2eda96d3e 100755 --- a/charts/latest/csi-driver-smb/templates/csi-smb-controller.yaml +++ b/charts/latest/csi-driver-smb/templates/csi-smb-controller.yaml @@ -74,6 +74,9 @@ spec: resources: {{- toYaml .Values.controller.resources.csiProvisioner | nindent 12 }} securityContext: readOnlyRootFilesystem: true + capabilities: + drop: + - ALL - name: liveness-probe {{- if hasPrefix "/" .Values.image.livenessProbe.repository }} image: "{{ .Values.image.baseRepo }}{{ .Values.image.livenessProbe.repository }}:{{ .Values.image.livenessProbe.tag }}" @@ -92,6 +95,9 @@ spec: resources: {{- toYaml .Values.controller.resources.livenessProbe | nindent 12 }} securityContext: readOnlyRootFilesystem: true + capabilities: + drop: + - ALL - name: smb {{- if hasPrefix "/" .Values.image.smb.repository }} image: "{{ .Values.image.baseRepo }}{{ .Values.image.smb.repository }}:{{ .Values.image.smb.tag }}" @@ -124,6 +130,9 @@ spec: securityContext: privileged: true readOnlyRootFilesystem: true + capabilities: + drop: + - ALL volumeMounts: - mountPath: /csi name: socket-dir