File tree Expand file tree Collapse file tree 2 files changed +15
-1
lines changed Expand file tree Collapse file tree 2 files changed +15
-1
lines changed Original file line number Diff line number Diff line change @@ -12,6 +12,7 @@ checks:
12
12
- host-ipc
13
13
- host-network
14
14
- host-pid
15
+ - latest-tag
15
16
- mismatching-selector
16
17
- no-anti-affinity
17
18
- no-extensions-v1beta
@@ -22,14 +23,26 @@ checks:
22
23
- privilege-escalation-container
23
24
- privileged-container
24
25
- privileged-ports
26
+ - read-secret-from-env-var
25
27
- run-as-non-root
26
28
- sensitive-host-mounts
27
29
- ssh-port
28
30
- unsafe-proc-mount
29
31
- unsafe-sysctls
32
+ - unset-memory-requirements
33
+ - use-namespace
34
+ - wildcard-in-rules
30
35
- writable-host-mount
31
36
exclude :
37
+ # Coder needs to create pods for workspaces
38
+ - access-to-create-pods
39
+ - access-to-secrets
40
+ # TODO: evaluate high availability by default
41
+ - minimum-three-replicas
42
+ # TODO: add update strategy
43
+ - no-rolling-update-strategy
44
+ # TODO: add network policy for coderd and timescale pods
45
+ - non-isolated-pod
32
46
- required-annotation-email
33
47
- required-label-owner
34
48
- unset-cpu-requirements
35
- - unset-memory-requirements
Original file line number Diff line number Diff line change @@ -24,6 +24,7 @@ mkdir -p "$BUILD"
24
24
for example in " ${EXAMPLES[@]} " ; do
25
25
run_trace false helm template " $example " " $PROJECT_ROOT " \
26
26
--create-namespace \
27
+ --namespace=coder-test \
27
28
--release-name \
28
29
--values=" $PROJECT_ROOT /examples/images.yaml" \
29
30
--values=" $PROJECT_ROOT /examples/$example /$example .values.yaml" \
You can’t perform that action at this time.
0 commit comments