From 77d07dfab796d3bee81bb683812150229a100805 Mon Sep 17 00:00:00 2001 From: David Eads Date: Tue, 23 Apr 2024 14:28:20 -0400 Subject: [PATCH] OCPBUGS-28230: enforce termination message policy on all platform pods --- bindata/network/iptables-alerter/003-daemonset.yaml | 1 + bindata/network/openshift-sdn/sdn.yaml | 1 + bindata/network/ovn-kubernetes/managed/ovnkube-node.yaml | 1 + bindata/network/ovn-kubernetes/self-hosted/ovnkube-node.yaml | 1 + 4 files changed, 4 insertions(+) diff --git a/bindata/network/iptables-alerter/003-daemonset.yaml b/bindata/network/iptables-alerter/003-daemonset.yaml index 40feba3332..44f0ec3203 100644 --- a/bindata/network/iptables-alerter/003-daemonset.yaml +++ b/bindata/network/iptables-alerter/003-daemonset.yaml @@ -46,6 +46,7 @@ spec: memory: 65Mi securityContext: privileged: true + terminationMessagePolicy: FallbackToLogsOnError volumeMounts: - mountPath: /iptables-alerter name: iptables-alerter-script diff --git a/bindata/network/openshift-sdn/sdn.yaml b/bindata/network/openshift-sdn/sdn.yaml index 2f28f41112..6ee59bd491 100644 --- a/bindata/network/openshift-sdn/sdn.yaml +++ b/bindata/network/openshift-sdn/sdn.yaml @@ -426,6 +426,7 @@ spec: requests: cpu: 5m memory: 20Mi + terminationMessagePolicy: FallbackToLogsOnError env: - name: K8S_NODE valueFrom: diff --git a/bindata/network/ovn-kubernetes/managed/ovnkube-node.yaml b/bindata/network/ovn-kubernetes/managed/ovnkube-node.yaml index 881cb83570..7d7c058069 100644 --- a/bindata/network/ovn-kubernetes/managed/ovnkube-node.yaml +++ b/bindata/network/ovn-kubernetes/managed/ovnkube-node.yaml @@ -589,6 +589,7 @@ spec: command: ["/bin/bash", "-c", "echo drop-icmp done"] securityContext: privileged: true + terminationMessagePolicy: FallbackToLogsOnError volumeMounts: {{ if .NETWORK_NODE_IDENTITY_ENABLE }} - mountPath: /etc/ovn/ diff --git a/bindata/network/ovn-kubernetes/self-hosted/ovnkube-node.yaml b/bindata/network/ovn-kubernetes/self-hosted/ovnkube-node.yaml index 29877f7308..953bcc24d4 100644 --- a/bindata/network/ovn-kubernetes/self-hosted/ovnkube-node.yaml +++ b/bindata/network/ovn-kubernetes/self-hosted/ovnkube-node.yaml @@ -704,6 +704,7 @@ spec: command: ["/bin/bash", "-c", "echo drop-icmp done"] securityContext: privileged: true + terminationMessagePolicy: FallbackToLogsOnError volumeMounts: {{ if .NETWORK_NODE_IDENTITY_ENABLE }} - mountPath: /etc/ovn/