diff --git a/config/300-gateway.yaml b/config/300-gateway.yaml index 4a71d3eb7..6c9df8f9f 100644 --- a/config/300-gateway.yaml +++ b/config/300-gateway.yaml @@ -72,8 +72,6 @@ spec: allowPrivilegeEscalation: false readOnlyRootFilesystem: false runAsNonRoot: true - runAsUser: 65534 - runAsGroup: 65534 capabilities: drop: - ALL diff --git a/openshift/patches/003-dropuid.patch b/openshift/patches/003-dropuid.patch new file mode 100644 index 000000000..5b7d331f6 --- /dev/null +++ b/openshift/patches/003-dropuid.patch @@ -0,0 +1,13 @@ +diff --git a/config/300-gateway.yaml b/config/300-gateway.yaml +index 4a71d3eb..6c9df8f9 100644 +--- a/config/300-gateway.yaml ++++ b/config/300-gateway.yaml +@@ -72,8 +72,6 @@ spec: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: false + runAsNonRoot: true +- runAsUser: 65534 +- runAsGroup: 65534 + capabilities: + drop: + - ALL diff --git a/openshift/release/artifacts/net-kourier.yaml b/openshift/release/artifacts/net-kourier.yaml index 75fb69cfd..319131466 100644 --- a/openshift/release/artifacts/net-kourier.yaml +++ b/openshift/release/artifacts/net-kourier.yaml @@ -486,8 +486,6 @@ spec: allowPrivilegeEscalation: false readOnlyRootFilesystem: false runAsNonRoot: true - runAsUser: 65534 - runAsGroup: 65534 capabilities: drop: - ALL