diff --git a/platform-specific-configs/openshift/README.md b/platform-specific-configs/openshift/README.md new file mode 100644 index 0000000..759eb4a --- /dev/null +++ b/platform-specific-configs/openshift/README.md @@ -0,0 +1,3 @@ +# Openshift specific configuration + +Use override files when deploying ClearML. Proposed files in this folder require setup of `` and `` values to uids accepted by specific openshift configuration. diff --git a/platform-specific-configs/openshift/values-clearml-agent.yaml b/platform-specific-configs/openshift/values-clearml-agent.yaml new file mode 100644 index 0000000..f10b09f --- /dev/null +++ b/platform-specific-configs/openshift/values-clearml-agent.yaml @@ -0,0 +1,6 @@ +agentk8sglue: + podSecurityContext: + runAsUser: 0 + basePodTemplate: + podSecurityContext: + runAsUser: 0 diff --git a/platform-specific-configs/openshift/values-clearml.yaml b/platform-specific-configs/openshift/values-clearml.yaml new file mode 100644 index 0000000..5ffda11 --- /dev/null +++ b/platform-specific-configs/openshift/values-clearml.yaml @@ -0,0 +1,36 @@ +apiserver: + podSecurityContext: + fsGroup: + runAsUser: + runAsNonRoot: true +fileserver: + podSecurityContext: + fsGroup: + runAsUser: + runAsNonRoot: true +webserver: + podSecurityContext: + fsGroup: + runAsUser: + runAsNonRoot: true +elasticsearch: + securityContext: + runAsUser: + podSecurityContext: + fsGroup: + runAsUser: + sysctlInitContainer: + enabled: false + volumeClaimTemplate: +redis: + securityContext: + fsGroup: + runAsUser: +mongodb: + podSecurityContext: + enabled: true + fsGroup: + containerSecurityContext: + enabled: true + runAsUser: + runAsNonRoot: true diff --git a/platform-specific-configs/tanzu/README.md b/platform-specific-configs/tanzu/README.md new file mode 100644 index 0000000..ef9ac33 --- /dev/null +++ b/platform-specific-configs/tanzu/README.md @@ -0,0 +1,3 @@ +# Tanzu specific configuration + +Before installing any ClearML chart, apply `rolebinding.yaml` file after setting needed `` in it. diff --git a/platform-specific-configs/tanzu/rolebinding.yaml b/platform-specific-configs/tanzu/rolebinding.yaml index fe227cf..2fa13bc 100644 --- a/platform-specific-configs/tanzu/rolebinding.yaml +++ b/platform-specific-configs/tanzu/rolebinding.yaml @@ -2,7 +2,7 @@ kind: RoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: clearml-tanzu-rolebinding - namespace: clearml + namespace: roleRef: kind: ClusterRole name: psp:vmware-system-privileged