deploy(dns): roll non-root GX10 images
This commit is contained in:
@@ -137,7 +137,7 @@ spec:
|
|||||||
prometheus.io/scrape: "true"
|
prometheus.io/scrape: "true"
|
||||||
prometheus.io/port: "5320"
|
prometheus.io/port: "5320"
|
||||||
prometheus.io/path: "/metrics/prometheus"
|
prometheus.io/path: "/metrics/prometheus"
|
||||||
flowercore.io/source-sha: "8b4c1fcdcf25b476fa6fad76309ba69e38c21e8b"
|
flowercore.io/source-sha: "0cdea666a09dea526fb701d06c2ce17b90664a0f"
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: dns-web
|
serviceAccountName: dns-web
|
||||||
securityContext:
|
securityContext:
|
||||||
@@ -148,7 +148,7 @@ spec:
|
|||||||
fsGroupChangePolicy: OnRootMismatch
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
containers:
|
containers:
|
||||||
- name: dns-web
|
- name: dns-web
|
||||||
image: localhost/fc-dns-web:v20260617-gx10-f3-8b4c1fc
|
image: localhost/fc-dns-web:v20260617-sec5-0cdea66
|
||||||
imagePullPolicy: Never
|
imagePullPolicy: Never
|
||||||
securityContext:
|
securityContext:
|
||||||
readOnlyRootFilesystem: true
|
readOnlyRootFilesystem: true
|
||||||
@@ -357,7 +357,7 @@ spec:
|
|||||||
app.kubernetes.io/name: dns-acme-webhook
|
app.kubernetes.io/name: dns-acme-webhook
|
||||||
app.kubernetes.io/part-of: flowercore
|
app.kubernetes.io/part-of: flowercore
|
||||||
annotations:
|
annotations:
|
||||||
flowercore.io/source-sha: "8b4c1fcdcf25b476fa6fad76309ba69e38c21e8b"
|
flowercore.io/source-sha: "0cdea666a09dea526fb701d06c2ce17b90664a0f"
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: dns-acme-webhook
|
serviceAccountName: dns-acme-webhook
|
||||||
securityContext:
|
securityContext:
|
||||||
@@ -368,7 +368,7 @@ spec:
|
|||||||
fsGroupChangePolicy: OnRootMismatch
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
containers:
|
containers:
|
||||||
- name: dns-acme-webhook
|
- name: dns-acme-webhook
|
||||||
image: localhost/fc-dns-acme-webhook:v20260617-gx10-f3-8b4c1fc
|
image: localhost/fc-dns-acme-webhook:v20260617-sec5-0cdea66
|
||||||
imagePullPolicy: Never
|
imagePullPolicy: Never
|
||||||
securityContext:
|
securityContext:
|
||||||
readOnlyRootFilesystem: true
|
readOnlyRootFilesystem: true
|
||||||
|
|||||||
Reference in New Issue
Block a user