Skip to content

Commit

Permalink
kustomize: use separate ServiceAccount for Quay app pods (PROJQUAY-1909)
Browse files Browse the repository at this point in the history
The Quay app pods will use their own ServiceAccount, rather than
the default one in the namespace. This allows modifying permissions
using SecurityContextConstraints without affecting other pods in
the namespace.

Signed-off-by: Alec Merdler <[email protected]>
  • Loading branch information
alecmerdler committed Apr 20, 2021
1 parent 007de38 commit 8f3df20
Show file tree
Hide file tree
Showing 3 changed files with 6 additions and 0 deletions.
1 change: 1 addition & 0 deletions kustomize/base/quay.deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ spec:
labels:
quay-component: quay-app
spec:
serviceAccountName: quay-app
volumes:
- name: configvolume
secret:
Expand Down
4 changes: 4 additions & 0 deletions kustomize/base/quay.serviceaccount.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: quay-app
1 change: 1 addition & 0 deletions pkg/kustomize/kustomize_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -216,6 +216,7 @@ var quayComponents = map[string][]client.Object{
&corev1.ConfigMap{ObjectMeta: metav1.ObjectMeta{Name: "cluster-service-ca"}},
&corev1.Secret{ObjectMeta: metav1.ObjectMeta{Name: "quay-config-editor-credentials"}},
&corev1.Secret{ObjectMeta: metav1.ObjectMeta{Name: "quay-registry-managed-secret-keys"}},
&corev1.ServiceAccount{ObjectMeta: metav1.ObjectMeta{Name: "quay-app"}},
},
"clair": {
&corev1.Secret{ObjectMeta: metav1.ObjectMeta{Name: "clair-config-secret"}},
Expand Down

0 comments on commit 8f3df20

Please sign in to comment.