-
Mounting large volumes can be slow (or even fail) because kubelet tries to recursive own all files in the volume. This issue can be mitigated by setting fsGroupChangePolicy to "OnRootMismatch" (requires k8s >= 1.23). This MR introduces `securityContext.fsGroupChangePolicy` to all subcharts. This MR unifies the `securityContext` rendering of all subcharts by introducing a central helper template `gitlab.podSecurityContext` that exposes [fsGroupChangePolicy](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#configure-volume-permission-and-ownership-change-policy-for-pods). By default, no `fsGroupChangePolicy` (which equals `Always`) is applied. Closes #3819 Changelog: added
20283351