From f1b271c904f70efed8f3b007d1b7cce49a8aab3f Mon Sep 17 00:00:00 2001 From: duhow Date: Sat, 23 Oct 2021 12:44:17 +0200 Subject: [PATCH] Add security features to test template file Signed-off-by: duhow --- pkg/chartutil/create.go | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/pkg/chartutil/create.go b/pkg/chartutil/create.go index ca79e7ab2..28b4dc902 100644 --- a/pkg/chartutil/create.go +++ b/pkg/chartutil/create.go @@ -500,7 +500,18 @@ spec: - name: wget image: busybox command: ['wget'] - args: ['{{ include ".fullname" . }}:{{ .Values.service.port }}'] + args: ['-O', '/dev/null', '{{ include ".fullname" . }}:{{ .Values.service.port }}'] + securityContext: + runAsUser: 1000 + runAsNonRoot: true + readOnlyRootFilesystem: true + resources: + limits: + memory: 60Mi + cpu: 200m + requests: + memory: 10Mi + cpu: 10m restartPolicy: Never `