fix(openvscode-server): allow rootfs access, make token required (#1611)
* fix(openvscode-server): allow rootfs access, make token required * doesn't work like that
This commit is contained in:
@@ -1,7 +1,7 @@
|
|||||||
apiVersion: v2
|
apiVersion: v2
|
||||||
kubeVersion: ">=1.16.0-0"
|
kubeVersion: ">=1.16.0-0"
|
||||||
name: openvscode-server
|
name: openvscode-server
|
||||||
version: 0.0.11
|
version: 0.0.12
|
||||||
appVersion: "1.63.2"
|
appVersion: "1.63.2"
|
||||||
description: Openvscode-server provides a version of VS Code that runs a server on a remote machine.
|
description: Openvscode-server provides a version of VS Code that runs a server on a remote machine.
|
||||||
type: application
|
type: application
|
||||||
|
|||||||
@@ -85,6 +85,7 @@ questions:
|
|||||||
schema:
|
schema:
|
||||||
type: string
|
type: string
|
||||||
private: true
|
private: true
|
||||||
|
required: true
|
||||||
default: ""
|
default: ""
|
||||||
- variable: SUDO_PASSWORD
|
- variable: SUDO_PASSWORD
|
||||||
label: "SUDO_PASSWORD"
|
label: "SUDO_PASSWORD"
|
||||||
@@ -99,7 +100,13 @@ questions:
|
|||||||
type: dict
|
type: dict
|
||||||
attrs:
|
attrs:
|
||||||
# Include{fixedEnv}
|
# Include{fixedEnv}
|
||||||
|
- variable: PUID
|
||||||
|
label: "PUID"
|
||||||
|
description: "Sets the PUID env var"
|
||||||
|
schema:
|
||||||
|
type: int
|
||||||
|
required: true
|
||||||
|
default: 568
|
||||||
# Include{containerConfig}
|
# Include{containerConfig}
|
||||||
|
|
||||||
- variable: service
|
- variable: service
|
||||||
@@ -280,7 +287,7 @@ questions:
|
|||||||
label: "ReadOnly Root Filesystem"
|
label: "ReadOnly Root Filesystem"
|
||||||
schema:
|
schema:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: true
|
default: false
|
||||||
- variable: allowPrivilegeEscalation
|
- variable: allowPrivilegeEscalation
|
||||||
label: "Allow Privilege Escalation"
|
label: "Allow Privilege Escalation"
|
||||||
schema:
|
schema:
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ image:
|
|||||||
|
|
||||||
securityContext:
|
securityContext:
|
||||||
runAsNonRoot: false
|
runAsNonRoot: false
|
||||||
|
readOnlyRootFilesystem: false
|
||||||
|
|
||||||
podSecurityContext:
|
podSecurityContext:
|
||||||
runAsUser: 0
|
runAsUser: 0
|
||||||
|
|||||||
Reference in New Issue
Block a user