Skip to content

Commit

Permalink
Add namespace for all sample CNFs
Browse files Browse the repository at this point in the history
Else they would be deployed vs default which has no labels.

Signed-off-by: Cédric Ollivier <cedric.ollivier@orange.com>
  • Loading branch information
collivier committed Nov 13, 2024
1 parent d92c831 commit 2b4c16b
Show file tree
Hide file tree
Showing 18 changed files with 183 additions and 3 deletions.
12 changes: 11 additions & 1 deletion sample-cnfs/k8s-multiple-processes/chart/templates/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: sidecar-container-demo
namespace: cnfspace
spec:
containers:
- image: busybox
Expand All @@ -23,4 +33,4 @@ spec:
dnsPolicy: Default
volumes:
- name: var-logs
emptyDir: {}
emptyDir: {}
12 changes: 11 additions & 1 deletion sample-cnfs/k8s-non-helm-no-image-policy/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: sidecar-container-demo
namespace: cnfspace
spec:
containers:
- image: busybox
Expand All @@ -23,4 +33,4 @@ spec:
dnsPolicy: Default
volumes:
- name: var-logs
emptyDir: {}
emptyDir: {}
10 changes: 10 additions & 0 deletions sample-cnfs/k8s-non-helm/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: sidecar-container-demo
namespace: cnfspace
spec:
containers:
- image: busybox:1.33.1
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: sidecar-container-demo
namespace: cnfspace
spec:
containers:
- image: busybox
Expand All @@ -23,4 +33,4 @@ spec:
dnsPolicy: Default
volumes:
- name: var-logs
emptyDir: {}
emptyDir: {}
10 changes: 10 additions & 0 deletions sample-cnfs/sample-alpha-apis/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
containers:
- image: bitnami/nginx:1.20
Expand Down
10 changes: 10 additions & 0 deletions sample-cnfs/sample-fluentbit/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
containers:
- image: bitnami/nginx:1.20
Expand Down
10 changes: 10 additions & 0 deletions sample-cnfs/sample-hostpath/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
containers:
- image: bitnami/nginx:1.20
Expand Down
10 changes: 10 additions & 0 deletions sample-cnfs/sample-immutable-fs/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
volumes:
- name: root-tmp
Expand Down
11 changes: 11 additions & 0 deletions sample-cnfs/sample-init-systems/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx-tini-sample
namespace: cnfspace
spec:
dnsPolicy: Default

Expand All @@ -28,6 +37,7 @@ apiVersion: v1
kind: Pod
metadata:
name: nginx-dumb-init-sample
namespace: cnfspace
spec:
dnsPolicy: Default

Expand All @@ -53,6 +63,7 @@ apiVersion: v1
kind: Pod
metadata:
name: nginx-s6-overlay-sample
namespace: cnfspace
spec:
dnsPolicy: Default

Expand Down
10 changes: 10 additions & 0 deletions sample-cnfs/sample-nonroot-containers/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
securityContext:
runAsNonRoot: true
Expand Down
10 changes: 10 additions & 0 deletions sample-cnfs/sample-nonroot/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: security-context-demo
namespace: cnfspace
spec:
securityContext:
runAsUser: 1000 # we make sure this is greater than 999 and
Expand Down
10 changes: 10 additions & 0 deletions sample-cnfs/sample-statefulsets/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
securityContext:
runAsNonRoot: true
Expand Down
10 changes: 10 additions & 0 deletions sample-cnfs/sample_container_sock_mount/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
containers:
- image: bitnami/nginx:1.20
Expand Down
11 changes: 11 additions & 0 deletions sample-cnfs/sample_external_ips/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
labels:
app: nginx
spec:
Expand All @@ -28,6 +38,7 @@ apiVersion: v1
kind: Service
metadata:
name: nginx-service
namespace: cnfspace
spec:
selector:
app: nginx
Expand Down
10 changes: 10 additions & 0 deletions sample-cnfs/sample_no_logs/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: python-server
namespace: cnfspace
labels:
k8s-app: python3-server
spec:
Expand Down
10 changes: 10 additions & 0 deletions sample-cnfs/sample_nonroot/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
containers:
- image: bitnami/nginx:1.20
Expand Down
9 changes: 9 additions & 0 deletions sample-cnfs/sample_sysctls/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
securityContext:
sysctls:
Expand Down
9 changes: 9 additions & 0 deletions sample-cnfs/sample_valid_selinux_options/manifests/pod.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,17 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cnfspace
labels:
pod-security.kubernetes.io/enforce: privileged

---
apiVersion: v1
kind: Pod
metadata:
name: nginx
namespace: cnfspace
spec:
containers:
- image: bitnami/nginx:latest
Expand Down

0 comments on commit 2b4c16b

Please sign in to comment.