fix(kodi-headless) set rofs to false + default credentials (#4902)

* fix(kodi-headless) set perms rootless

* rofs false | docs

* rar
This commit is contained in:
Xstar97
2022-11-27 23:40:19 +02:00
committed by GitHub
parent d086f90ce5
commit b0c13f2ee7
4 changed files with 48 additions and 44 deletions
+14 -15
View File
@@ -1,29 +1,28 @@
apiVersion: v2 apiVersion: v2
kubeVersion: ">=1.16.0-0"
name: kodi-headless
version: 4.0.1
appVersion: "190" appVersion: "190"
description: A headless install of kodi in a docker container.
type: application
deprecated: false
home: https://truecharts.org/docs/charts/stable/kodi-headless
icon: https://truecharts.org/img/hotlink-ok/chart-icons/kodi-headless.png
keywords:
- kodi-headless
sources:
- https://github.com/truecharts/charts/tree/master/charts/stable/kodi-headless
- https://hub.docker.com/r/linuxserver/kodi-headless
dependencies: dependencies:
- name: common - name: common
repository: https://library-charts.truecharts.org repository: https://library-charts.truecharts.org
version: 11.0.3 version: 11.0.3
# condition: deprecated: false
description: A headless install of kodi in a docker container.
home: https://truecharts.org/docs/charts/stable/kodi-headless
icon: https://truecharts.org/img/hotlink-ok/chart-icons/kodi-headless.png
keywords:
- kodi-headless
kubeVersion: ">=1.16.0-0"
maintainers: maintainers:
- email: info@truecharts.org - email: info@truecharts.org
name: TrueCharts name: TrueCharts
url: https://truecharts.org url: https://truecharts.org
name: kodi-headless
sources:
- https://github.com/truecharts/charts/tree/master/charts/stable/kodi-headless
- https://hub.docker.com/r/linuxserver/kodi-headless
type: application
version: 4.0.2
annotations: annotations:
truecharts.org/catagories: | truecharts.org/catagories: |
- incubator - media
truecharts.org/SCALE-support: "true" truecharts.org/SCALE-support: "true"
truecharts.org/grade: U truecharts.org/grade: U
@@ -0,0 +1,4 @@
# Default credentials
- Username: `kodi`
- Password: `kodi`
+29 -29
View File
@@ -11,8 +11,8 @@ questions:
# Include{containerConfig} # Include{containerConfig}
# Include{serviceRoot} # Include{serviceRoot}
- variable: main - variable: main
label: "Main Service" label: Main Service
description: "The Primary service on which the healthcheck runs, often the webUI" description: The Primary service on which the healthcheck runs, often the webUI
schema: schema:
additional_attrs: true additional_attrs: true
type: dict type: dict
@@ -20,21 +20,21 @@ questions:
# Include{serviceSelectorLoadBalancer} # Include{serviceSelectorLoadBalancer}
# Include{serviceSelectorExtras} # Include{serviceSelectorExtras}
- variable: main - variable: main
label: "Main Service Port Configuration" label: Main Service Port Configuration
schema: schema:
additional_attrs: true additional_attrs: true
type: dict type: dict
attrs: attrs:
- variable: port - variable: port
label: "Port" label: Port
description: "This port exposes the container port on the service" description: This port exposes the container port on the service
schema: schema:
type: int type: int
default: 10148 default: 10148
required: true required: true
- variable: websocket - variable: websocket
label: "websocket Service" label: websocket Service
description: "The websocket service." description: The websocket service.
schema: schema:
additional_attrs: true additional_attrs: true
type: dict type: dict
@@ -42,21 +42,21 @@ questions:
# Include{serviceSelectorLoadBalancer} # Include{serviceSelectorLoadBalancer}
# Include{serviceSelectorExtras} # Include{serviceSelectorExtras}
- variable: websocket - variable: websocket
label: "websocket Service Port Configuration" label: websocket Service Port Configuration
schema: schema:
additional_attrs: true additional_attrs: true
type: dict type: dict
attrs: attrs:
- variable: port - variable: port
label: "Port" label: Port
description: "This port exposes the container port on the service" description: This port exposes the container port on the service
schema: schema:
type: int type: int
default: 10152 default: 10152
required: true required: true
- variable: esall - variable: esall
label: "esall Service" label: esall Service
description: "The esall service." description: The esall service.
schema: schema:
additional_attrs: true additional_attrs: true
type: dict type: dict
@@ -64,14 +64,14 @@ questions:
# Include{serviceSelectorLoadBalancer} # Include{serviceSelectorLoadBalancer}
# Include{serviceSelectorExtras} # Include{serviceSelectorExtras}
- variable: esall - variable: esall
label: "esall Service Port Configuration" label: esall Service Port Configuration
schema: schema:
additional_attrs: true additional_attrs: true
type: dict type: dict
attrs: attrs:
- variable: port - variable: port
label: "Port" label: Port
description: "This port exposes the container port on the service" description: This port exposes the container port on the service
schema: schema:
type: int type: int
default: 9777 default: 9777
@@ -82,8 +82,8 @@ questions:
# Include{serviceList} # Include{serviceList}
# Include{persistenceRoot} # Include{persistenceRoot}
- variable: config - variable: config
label: "App Config Storage" label: App Config Storage
description: "Stores the Application Configuration." description: Stores the Application Configuration.
schema: schema:
additional_attrs: true additional_attrs: true
type: dict type: dict
@@ -92,7 +92,7 @@ questions:
# Include{persistenceList} # Include{persistenceList}
# Include{ingressRoot} # Include{ingressRoot}
- variable: main - variable: main
label: "Main Ingress" label: Main Ingress
schema: schema:
additional_attrs: true additional_attrs: true
type: dict type: dict
@@ -104,41 +104,41 @@ questions:
# Include{security} # Include{security}
# Include{securityContextAdvancedRoot} # Include{securityContextAdvancedRoot}
- variable: privileged - variable: privileged
label: "Privileged mode" label: Privileged mode
schema: schema:
type: boolean type: boolean
default: false default: false
- variable: readOnlyRootFilesystem - variable: readOnlyRootFilesystem
label: "ReadOnly Root Filesystem" label: ReadOnly Root Filesystem
schema: schema:
type: boolean type: boolean
default: true default: false
- variable: allowPrivilegeEscalation - variable: allowPrivilegeEscalation
label: "Allow Privilege Escalation" label: Allow Privilege Escalation
schema: schema:
type: boolean type: boolean
default: false default: false
- variable: runAsNonRoot - variable: runAsNonRoot
label: "runAsNonRoot" label: runAsNonRoot
schema: schema:
type: boolean type: boolean
default: false default: false
# Include{podSecurityContextRoot} # Include{podSecurityContextRoot}
- variable: runAsUser - variable: runAsUser
label: "runAsUser" label: runAsUser
description: "The UserID of the user running the application" description: The UserID of the user running the application
schema: schema:
type: int type: int
default: 0 default: 0
- variable: runAsGroup - variable: runAsGroup
label: "runAsGroup" label: runAsGroup
description: "The groupID this App of the user running the application" description: The groupID this App of the user running the application
schema: schema:
type: int type: int
default: 0 default: 0
- variable: fsGroup - variable: fsGroup
label: "fsGroup" label: fsGroup
description: "The group that should own ALL storage." description: The group that should own ALL storage.
schema: schema:
type: int type: int
default: 568 default: 568
+1
View File
@@ -4,6 +4,7 @@ image:
tag: v190 tag: v190
securityContext: securityContext:
readOnlyRootFilesystem: false
runAsNonRoot: false runAsNonRoot: false
podSecurityContext: podSecurityContext: