From 65df1fac110c77a004f8af37da64216f6a16c8be Mon Sep 17 00:00:00 2001 From: Andrey Date: Mon, 10 Feb 2025 17:37:43 +0100 Subject: [PATCH 1/2] Add run_as_non_root=True to Kubernetes Starter template --- examples/templates/kubernetes/main.tf | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/examples/templates/kubernetes/main.tf b/examples/templates/kubernetes/main.tf index 9177b338f8109..1d4716177b86b 100644 --- a/examples/templates/kubernetes/main.tf +++ b/examples/templates/kubernetes/main.tf @@ -262,8 +262,9 @@ resource "kubernetes_deployment" "main" { } spec { security_context { - run_as_user = 1000 - fs_group = 1000 + run_as_user = 1000 + fs_group = 1000 + run_as_non_root = True } container { From 7038755fa377e04dd5c59ef260e28f6b316df6d1 Mon Sep 17 00:00:00 2001 From: Andrey Date: Mon, 10 Feb 2025 19:54:18 +0100 Subject: [PATCH 2/2] Fix the typo in parameter name --- examples/templates/kubernetes/main.tf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/examples/templates/kubernetes/main.tf b/examples/templates/kubernetes/main.tf index 1d4716177b86b..d6ed9830484f5 100644 --- a/examples/templates/kubernetes/main.tf +++ b/examples/templates/kubernetes/main.tf @@ -264,7 +264,7 @@ resource "kubernetes_deployment" "main" { security_context { run_as_user = 1000 fs_group = 1000 - run_as_non_root = True + run_as_non_root = true } container {