zilliztech/milvus-helm

Support setting the security context and pod topology spread constraints for MinIO

Aperta

#107 aperta il 12 lug 2024

 (0 commenti) (0 reazioni) (0 assegnatari)Go Template (77 fork)auto 404
enhancementgood first issue

Metriche repository

Star
 (119 stelle)
Metriche merge PR
 (Metriche PR in attesa)

Descrizione

For security reasons, we use Kyverno's admission controller on our cluster to ensure that certain Linux capabilities are dropped and that containers run as non-root, along with other policies. While we can change the security contexts of the components using the Bitnami Helm charts (etcd, Kafka, etc.) we are unable to do this for MinIO.

In addition, in order to improve resiliency, we would like to be able to set Pod Topology Spread Constraints for the same components.

This is a feature request to expose these in the MinIO Helm chart.

Related to https://github.com/zilliztech/milvus-operator/issues/144

Guida contributor