mirror of https://git.rancher.io/rke2-charts
7b841da6e9
Before this change, wait-for-node-init container was not able to execute properly with SELinux enabled, due to lack of ability to access the bind mounted file. Due to lack of ability to set the container_file_t label through Kubernetes, the other possible solution, done in this commit, is making the container privileged. All the other containers accessing the bootstrap file are already privileged as well, so it should not be that harmful. Signed-off-by: Michal Rostecki <mrostecki@opensuse.org> |
||
---|---|---|
.. | ||
_clustermesh-apiserver-generate-certs-job-spec.tpl.patch | ||
_helpers.tpl.patch | ||
_hubble-generate-certs-job-spec.tpl.patch | ||
cilium-agent-daemonset.yaml.patch | ||
cilium-etcd-operator-deployment.yaml.patch | ||
cilium-nodeinit-daemonset.yaml.patch | ||
cilium-operator-deployment.yaml.patch | ||
cilium-preflight-daemonset.yaml.patch | ||
cilium-preflight-deployment.yaml.patch | ||
clustermesh-apiserver-deployment.yaml.patch | ||
hubble-relay-deployment.yaml.patch | ||
hubble-ui-deployment.yaml.patch |