Skip to content

Commit 8d275dc

Browse files
authored
Fix: nodelocaldns capabilities usage (#12398)
Signed-off-by: ChengHao Yang <[email protected]>
1 parent ff21799 commit 8d275dc

File tree

2 files changed

+6
-2
lines changed

2 files changed

+6
-2
lines changed

roles/kubernetes-apps/ansible/templates/nodelocaldns-daemonset.yml.j2

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,9 @@ spec:
5959
name: metrics
6060
protocol: TCP
6161
securityContext:
62-
privileged: true
62+
capabilities:
63+
add:
64+
- NET_ADMIN
6365
{% if nodelocaldns_bind_metrics_host_ip %}
6466
env:
6567
- name: MY_HOST_IP

roles/kubernetes-apps/ansible/templates/nodelocaldns-second-daemonset.yml.j2

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,9 @@ spec:
4444
name: metrics
4545
protocol: TCP
4646
securityContext:
47-
privileged: true
47+
capabilities:
48+
add:
49+
- NET_ADMIN
4850
{% if nodelocaldns_bind_metrics_host_ip %}
4951
env:
5052
- name: MY_HOST_IP

0 commit comments

Comments
 (0)