zilliztech/milvus-helm

Support setting the security context and pod topology spread constraints for MinIO

Open

#107 opened on Jul 12, 2024

View on GitHub
 (0 comments) (0 reactions) (0 assignees)Go Template (77 forks)auto 404
enhancementgood first issue

Repository metrics

Stars
 (119 stars)
PR merge metrics
 (PR metrics pending)

Description

For security reasons, we use Kyverno's admission controller on our cluster to ensure that certain Linux capabilities are dropped and that containers run as non-root, along with other policies. While we can change the security contexts of the components using the Bitnami Helm charts (etcd, Kafka, etc.) we are unable to do this for MinIO.

In addition, in order to improve resiliency, we would like to be able to set Pod Topology Spread Constraints for the same components.

This is a feature request to expose these in the MinIO Helm chart.

Related to https://github.com/zilliztech/milvus-operator/issues/144

Contributor guide