@@ -19,13 +19,24 @@ spec:
1919      labels :
2020        app : {{ include "mgmt-agent.resourceNamePrefix" . }}-mgmt-agent 
2121    spec :
22+       securityContext :
23+         runAsUser : {{ default 0 .Values.deployment.security.runAsUser }} 
24+         runAsGroup : {{ default 0 .Values.deployment.security.runAsGroup }} 
25+         fsGroup : {{ default 0 .Values.deployment.security.fsGroup }} 
2226      serviceAccountName : {{ include "mgmt-agent.serviceAccount" . }} 
2327      imagePullSecrets :
2428        - name : {{ include "mgmt-agent.resourceNamePrefix" . }}-mgmt-agent-container-registry-key 
2529      restartPolicy : Always 
2630      containers :
2731        - name : {{ include "mgmt-agent.resourceNamePrefix" . }}-mgmt-agent 
2832          image : {{ .Values.mgmtagent.image.url }} 
33+           resources :
34+             requests :
35+               cpu : {{ .Values.deployment.resource.request.cpuCore }} 
36+               memory : {{ .Values.deployment.resource.request.memory }} 
37+             limits :
38+               cpu : {{ .Values.deployment.resource.limit.cpuCore }} 
39+               memory : {{ .Values.deployment.resource.limit.memory }} 
2940          volumeMounts :
3041            - name : mgmtagent-secret 
3142              mountPath : /opt/oracle/mgmtagent_secret 
@@ -34,19 +45,28 @@ spec:
3445              mountPath : /opt/oracle 
3546            - name : mgmtagent-config 
3647              mountPath : /opt/oracle/mgmtagent_config 
48+             - mountPath : /tmp 
49+               name : tmp 
50+           securityContext :
51+            allowPrivilegeEscalation : false 
52+            readOnlyRootFilesystem : true 
3753      volumes :
3854        - name : mgmtagent-secret 
3955          secret :
4056            secretName : {{ include "mgmt-agent.resourceNamePrefix" . }}-mgmt-agent-rsp 
4157        - name : mgmtagent-config 
4258          configMap :
4359            name : {{ include "mgmt-agent.resourceNamePrefix" . }}-metrics 
60+         - emptyDir : {} 
61+           name : tmp 
4462  volumeClaimTemplates :
4563    - metadata :
4664        name : mgmtagent-pvc 
4765      spec :
4866        accessModes : [ "ReadWriteOnce" ] 
49-         storageClassName : " oci-bv" 
67+         {{- if .Values.deployment.storageClass }} 
68+         storageClassName : {{ .Values.deployment.storageClass }} 
69+         {{- end }} 
5070        resources :
5171          requests :
52-             storage : 2Gi 
72+             storage : {{ .Values.deployment.resource.request.storage }} 
0 commit comments