2.3 with PSP is working
All checks were successful
continuous-integration/drone/push Build is passing
continuous-integration/drone/pr Build is passing

This commit is contained in:
Adrien Reslinger 2020-11-04 00:28:20 +01:00
parent f2455cf712
commit 68588b80ac
3 changed files with 5 additions and 8 deletions

View file

@ -13,7 +13,7 @@ traefik_memory_limit: 300Mi
traefik_entrypoints:
- { name: "http", port: 8000, proto: "TCP", hostport: 80 }
- { name: "https", port: 4443, proto: "TCP", hostport: 443, tls: true }
# - { name: "traefik", port: 8080, proto: "TCP" }
- { name: "traefik", port: 8080, proto: "TCP" }
basic_auth: false
#traefik_dashboard_certificate: wildcard-cluster

View file

@ -13,8 +13,7 @@ spec:
# Match is the rule corresponding to an underlying router.
# Later on, match could be the simple form of a path prefix, e.g. just "/bar",
# but for now we only support a traefik style matching rule.
# - match: PathPrefix(`/dashboard`) || PathPrefix(`/api`)
- match: Host(`traefik.{{ traefik_domain }}`)
- match: Host(`traefik.{{ traefik_domain }}`) && (PathPrefix(`/dashboard`) || PathPrefix(`/api`))
# kind could eventually be one of "Rule", "Path", "Host", "Method", "Header",
# "Parameter", etc, to support simpler forms of rule matching, but for now we
# only support "Rule".

View file

@ -19,7 +19,7 @@ spec:
- secret
- emptyDir
- projected
# - persistentVolumeClaim
# - persistentVolumeClaim
hostNetwork: false
hostIPC: false
hostPID: false
@ -39,13 +39,11 @@ spec:
- min: 1
max: 65535
hostPorts:
- max: 65535
min: 1
readOnlyRootFilesystem: true
seLinux:
rule: 'RunAsAny'
hostPorts:
- max: 65535
min: 1
# allowedUnsafeSysctls:
# - kernel.net.ipv4.ip_unprivileged_port_start
#allowedUnsafeSysctls:
# - kernel.net.ipv4.ip_unprivileged_port_start