Skip to content

Add containerSecurityContext to subcharts

Summary

We have a requirement for dropping ALL capabilities for our pods

Current behavior

We currently get PolicyViolations for our Gitlab pods and jobs for failing to drop-all-capabilities

Expected behavior

we want to be able to add

  containerSecurityContext:
    capabilities:
      drop: 
        - ALL

to our values.yaml to override values

which would require

  securityContext:
    {{- toYaml $.Values.containerSecurityContext | nindent 12 }}

to be added to containers in the various deployment.yamls