mirror of
				https://github.com/optim-enterprises-bv/kubernetes.git
				synced 2025-10-30 17:58:14 +00:00 
			
		
		
		
	kubelet: use idmapped mounts for all volumes
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
This commit is contained in:
		| @@ -54,6 +54,15 @@ func (m *kubeGenericRuntimeManager) applyPlatformSpecificContainerConfig(config | ||||
| 		return err | ||||
| 	} | ||||
| 	config.Linux = cl | ||||
|  | ||||
| 	if utilfeature.DefaultFeatureGate.Enabled(kubefeatures.UserNamespacesStatelessPodsSupport) { | ||||
| 		if cl.SecurityContext.NamespaceOptions.UsernsOptions != nil { | ||||
| 			for _, mount := range config.Mounts { | ||||
| 				mount.UidMappings = cl.SecurityContext.NamespaceOptions.UsernsOptions.Uids | ||||
| 				mount.GidMappings = cl.SecurityContext.NamespaceOptions.UsernsOptions.Gids | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
|   | ||||
		Reference in New Issue
	
	Block a user
	 Giuseppe Scrivano
					Giuseppe Scrivano