Skip to content

Commit 3ef44df

Browse files
Update main.tf - 4.10.1 + runAsNonRoot
1 parent 62e1608 commit 3ef44df

File tree

1 file changed

+36
-1
lines changed

1 file changed

+36
-1
lines changed

modules/base/main.tf

Lines changed: 36 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -171,7 +171,7 @@ resource "helm_release" "ingress_nginx" {
171171
repository = "https://kubernetes.github.io/ingress-nginx"
172172

173173
chart = "ingress-nginx"
174-
version = "4.10.0"
174+
version = "4.10.1"
175175
wait = true
176176
timeout = 600
177177

@@ -187,5 +187,40 @@ resource "helm_release" "ingress_nginx" {
187187
value = var.ingress_nginx_min_unavailable
188188
}
189189

190+
set {
191+
name = "controller.containerSecurityContext.runAsUser"
192+
value = 101
193+
}
194+
195+
set {
196+
name = "controller.containerSecurityContext.runAsGroup"
197+
value = 101
198+
}
199+
200+
set {
201+
name = "controller.containerSecurityContext.allowPrivilegeEscalation"
202+
value = false
203+
}
204+
205+
set {
206+
name = "controller.containerSecurityContext.readOnlyRootFilesystem"
207+
value = false
208+
}
209+
210+
set {
211+
name = "controller.containerSecurityContext.runAsNonRoot"
212+
value = true
213+
}
214+
215+
set_list {
216+
name = "controller.containerSecurityContext.capabilities.drop"
217+
value = ["ALL"]
218+
}
219+
220+
set_list {
221+
name = "controller.containerSecurityContext.capabilities.add"
222+
value = ["NET_BIND_SERVICE"]
223+
}
224+
190225
depends_on = [module.aws_eks.eks_managed_node_groups]
191226
}

0 commit comments

Comments
 (0)