diff --git a/pkg/operator/ceph/cluster/cleanup.go b/pkg/operator/ceph/cluster/cleanup.go index eb50d1a33..9f7c2e0ef 100644 --- a/pkg/operator/ceph/cluster/cleanup.go +++ b/pkg/operator/ceph/cluster/cleanup.go @@ -162,6 +162,7 @@ func (c *ClusterController) cleanUpJobTemplateSpec(cluster *cephv1.CephCluster, Volumes: volumes, RestartPolicy: v1.RestartPolicyOnFailure, PriorityClassName: cephv1.GetCleanupPriorityClassName(cluster.Spec.PriorityClassNames), + SecurityContext: &v1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, HostNetwork: opcontroller.EnforceHostNetwork(), }, diff --git a/pkg/operator/ceph/cluster/mgr/spec.go b/pkg/operator/ceph/cluster/mgr/spec.go index 1c38893d0..bc8adf10c 100644 --- a/pkg/operator/ceph/cluster/mgr/spec.go +++ b/pkg/operator/ceph/cluster/mgr/spec.go @@ -61,6 +61,7 @@ func (c *Cluster) makeDeployment(mgrConfig *mgrConfig) (*apps.Deployment, error) Containers: []v1.Container{ c.makeMgrDaemonContainer(mgrConfig), }, + SecurityContext: &v1.PodSecurityContext{}, ServiceAccountName: serviceAccountName, RestartPolicy: v1.RestartPolicyAlways, Volumes: volumes, diff --git a/pkg/operator/ceph/cluster/mon/spec.go b/pkg/operator/ceph/cluster/mon/spec.go index 8901f26bd..161d77e20 100644 --- a/pkg/operator/ceph/cluster/mon/spec.go +++ b/pkg/operator/ceph/cluster/mon/spec.go @@ -190,6 +190,7 @@ func (c *Cluster) makeMonPod(monConfig *monConfig, canary bool) (*corev1.Pod, er Volumes: controller.DaemonVolumesBase(monConfig.DataPathMap, keyringStoreName, c.spec.DataDirHostPath), HostNetwork: monConfig.UseHostNetwork, PriorityClassName: cephv1.GetMonPriorityClassName(c.spec.PriorityClassNames), + SecurityContext: &corev1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, } diff --git a/pkg/operator/ceph/cluster/nodedaemon/crash.go b/pkg/operator/ceph/cluster/nodedaemon/crash.go index 87ed94fb7..9f3eb43bc 100644 --- a/pkg/operator/ceph/cluster/nodedaemon/crash.go +++ b/pkg/operator/ceph/cluster/nodedaemon/crash.go @@ -121,6 +121,7 @@ func (r *ReconcileNode) createOrUpdateCephCrash(node corev1.Node, tolerations [] HostNetwork: cephCluster.Spec.Network.IsHost(), Volumes: volumes, PriorityClassName: cephv1.GetCrashCollectorPriorityClassName(cephCluster.Spec.PriorityClassNames), + SecurityContext: &corev1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, }, } diff --git a/pkg/operator/ceph/cluster/nodedaemon/exporter.go b/pkg/operator/ceph/cluster/nodedaemon/exporter.go index ab4debc27..4c30320ce 100644 --- a/pkg/operator/ceph/cluster/nodedaemon/exporter.go +++ b/pkg/operator/ceph/cluster/nodedaemon/exporter.go @@ -144,6 +144,7 @@ func (r *ReconcileNode) createOrUpdateCephExporter(node corev1.Node, tolerations Volumes: volumes, PriorityClassName: cephv1.GetCephExporterPriorityClassName(cephCluster.Spec.PriorityClassNames), TerminationGracePeriodSeconds: &terminationGracePeriodSeconds, + SecurityContext: &corev1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, }, } diff --git a/pkg/operator/ceph/cluster/nodedaemon/pruner.go b/pkg/operator/ceph/cluster/nodedaemon/pruner.go index bb8e3966b..1f6951690 100644 --- a/pkg/operator/ceph/cluster/nodedaemon/pruner.go +++ b/pkg/operator/ceph/cluster/nodedaemon/pruner.go @@ -110,6 +110,7 @@ func (r *ReconcileNode) createOrUpdateCephCron(cephCluster cephv1.CephCluster, c RestartPolicy: corev1.RestartPolicyNever, HostNetwork: cephCluster.Spec.Network.IsHost(), Volumes: volumes, + SecurityContext: &corev1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, }, } diff --git a/pkg/operator/ceph/cluster/osd/key_rotation.go b/pkg/operator/ceph/cluster/osd/key_rotation.go index f9a427100..6401a8eb4 100644 --- a/pkg/operator/ceph/cluster/osd/key_rotation.go +++ b/pkg/operator/ceph/cluster/osd/key_rotation.go @@ -161,6 +161,7 @@ func (c *Cluster) getKeyRotationPodTemplateSpec(osdProps osdProperties, osd OSDI HostNetwork: c.spec.Network.IsHost(), PriorityClassName: cephv1.GetOSDPriorityClassName(c.spec.PriorityClassNames), SchedulerName: osdProps.schedulerName, + SecurityContext: &v1.PodSecurityContext{}, }, } if c.spec.Network.IsHost() { diff --git a/pkg/operator/ceph/cluster/osd/provision_spec.go b/pkg/operator/ceph/cluster/osd/provision_spec.go index 4839ea6a2..48147c486 100644 --- a/pkg/operator/ceph/cluster/osd/provision_spec.go +++ b/pkg/operator/ceph/cluster/osd/provision_spec.go @@ -158,6 +158,7 @@ func (c *Cluster) provisionPodTemplateSpec(osdProps osdProperties, restart v1.Re HostNetwork: opcontroller.EnforceHostNetwork(), PriorityClassName: cephv1.GetOSDPriorityClassName(c.spec.PriorityClassNames), SchedulerName: osdProps.schedulerName, + SecurityContext: &v1.PodSecurityContext{}, } if c.spec.Network.IsHost() { podSpec.DNSPolicy = v1.DNSClusterFirstWithHostNet diff --git a/pkg/operator/ceph/cluster/osd/spec.go b/pkg/operator/ceph/cluster/osd/spec.go index 386bb9a24..f1ab7516b 100644 --- a/pkg/operator/ceph/cluster/osd/spec.go +++ b/pkg/operator/ceph/cluster/osd/spec.go @@ -631,8 +631,9 @@ func (c *Cluster) makeDeployment(osdProps osdProperties, osd *OSDInfo, provision WorkingDir: opconfig.VarLogCephDir, }, }, - Volumes: volumes, - SchedulerName: osdProps.schedulerName, + Volumes: volumes, + SecurityContext: &v1.PodSecurityContext{}, + SchedulerName: osdProps.schedulerName, }, } diff --git a/pkg/operator/ceph/cluster/rbd/spec.go b/pkg/operator/ceph/cluster/rbd/spec.go index dd627232b..e37fe79f5 100644 --- a/pkg/operator/ceph/cluster/rbd/spec.go +++ b/pkg/operator/ceph/cluster/rbd/spec.go @@ -43,6 +43,7 @@ func (r *ReconcileCephRBDMirror) makeDeployment(daemonConfig *daemonConfig, rbdM Volumes: controller.DaemonVolumes(daemonConfig.DataPathMap, daemonConfig.ResourceName, r.cephClusterSpec.DataDirHostPath), HostNetwork: r.cephClusterSpec.Network.IsHost(), PriorityClassName: rbdMirror.Spec.PriorityClassName, + SecurityContext: &v1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, }, } diff --git a/pkg/operator/ceph/controller/cleanup.go b/pkg/operator/ceph/controller/cleanup.go index 99a4a60ef..739cce905 100644 --- a/pkg/operator/ceph/controller/cleanup.go +++ b/pkg/operator/ceph/controller/cleanup.go @@ -129,6 +129,7 @@ func (c *ResourceCleanup) jobTemplateSpec() v1.PodTemplateSpec { Volumes: volumes, RestartPolicy: v1.RestartPolicyOnFailure, PriorityClassName: cephv1.GetCleanupPriorityClassName(c.cluster.Spec.PriorityClassNames), + SecurityContext: &v1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, }, } diff --git a/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin-holder.yaml b/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin-holder.yaml index 911536032..f29659b29 100644 --- a/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin-holder.yaml +++ b/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin-holder.yaml @@ -29,6 +29,7 @@ spec: spec: # HostPID is needed to expose the correct process ID network namespace and not the process namespace hostPID: true + securityContext: {} serviceAccountName: rook-csi-cephfs-plugin-sa {{ if .PluginPriorityClassName }} priorityClassName: {{ .PluginPriorityClassName }} diff --git a/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin-provisioner-dep.yaml b/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin-provisioner-dep.yaml index 54bf92cd1..d78fc1cbe 100644 --- a/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin-provisioner-dep.yaml +++ b/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin-provisioner-dep.yaml @@ -17,6 +17,7 @@ spec: {{ $key }}: "{{ $value }}" {{ end }} spec: + securityContext: {} serviceAccountName: rook-csi-cephfs-provisioner-sa {{ if .ProvisionerPriorityClassName }} priorityClassName: {{ .ProvisionerPriorityClassName }} diff --git a/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin.yaml b/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin.yaml index 5ce364cd7..bd4bac53c 100644 --- a/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin.yaml +++ b/pkg/operator/ceph/csi/template/cephfs/csi-cephfsplugin.yaml @@ -22,6 +22,7 @@ spec: {{ $key }}: "{{ $value }}" {{ end }} spec: + securityContext: {} serviceAccountName: rook-csi-cephfs-plugin-sa hostNetwork: {{ .EnableCSIHostNetwork }} {{ if .PluginPriorityClassName }} diff --git a/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin-holder.yaml b/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin-holder.yaml index 2a4c64cf8..240d4b6b5 100644 --- a/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin-holder.yaml +++ b/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin-holder.yaml @@ -29,6 +29,7 @@ spec: spec: # HostPID is needed to expose the correct process ID network namespace and not the process namespace hostPID: true + securityContext: {} serviceAccountName: rook-csi-nfs-plugin-sa {{ if .PluginPriorityClassName }} priorityClassName: {{ .PluginPriorityClassName }} diff --git a/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin-provisioner-dep.yaml b/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin-provisioner-dep.yaml index 7fad6f7bf..9411546f2 100644 --- a/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin-provisioner-dep.yaml +++ b/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin-provisioner-dep.yaml @@ -16,6 +16,7 @@ spec: {{ $key }}: "{{ $value }}" {{ end }} spec: + securityContext: {} serviceAccountName: rook-csi-nfs-provisioner-sa {{ if .ProvisionerPriorityClassName }} priorityClassName: {{ .ProvisionerPriorityClassName }} diff --git a/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin.yaml b/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin.yaml index 67d2a93ca..a0d16acf6 100644 --- a/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin.yaml +++ b/pkg/operator/ceph/csi/template/nfs/csi-nfsplugin.yaml @@ -17,6 +17,7 @@ spec: {{ $key }}: "{{ $value }}" {{ end }} spec: + securityContext: {} serviceAccountName: rook-csi-nfs-plugin-sa hostNetwork: {{ .EnableCSIHostNetwork }} {{ if .PluginPriorityClassName }} diff --git a/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin-holder.yaml b/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin-holder.yaml index 6191b9729..c8f11c5cc 100644 --- a/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin-holder.yaml +++ b/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin-holder.yaml @@ -29,6 +29,7 @@ spec: spec: # HostPID is needed to expose the correct process ID network namespace and not the process namespace hostPID: true + securityContext: {} serviceAccountName: rook-csi-rbd-plugin-sa {{ if .PluginPriorityClassName }} priorityClassName: {{ .PluginPriorityClassName }} diff --git a/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin-provisioner-dep.yaml b/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin-provisioner-dep.yaml index 5f8b23974..741b362b9 100644 --- a/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin-provisioner-dep.yaml +++ b/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin-provisioner-dep.yaml @@ -17,6 +17,7 @@ spec: {{ $key }}: "{{ $value }}" {{ end }} spec: + securityContext: {} serviceAccountName: rook-csi-rbd-provisioner-sa {{ if .ProvisionerPriorityClassName }} priorityClassName: {{ .ProvisionerPriorityClassName }} diff --git a/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin.yaml b/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin.yaml index 93f93be4b..fb0a3fca5 100644 --- a/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin.yaml +++ b/pkg/operator/ceph/csi/template/rbd/csi-rbdplugin.yaml @@ -22,6 +22,7 @@ spec: {{ $key }}: "{{ $value }}" {{ end }} spec: + securityContext: {} serviceAccountName: rook-csi-rbd-plugin-sa {{ if .PluginPriorityClassName }} priorityClassName: {{ .PluginPriorityClassName }} diff --git a/pkg/operator/ceph/file/mds/spec.go b/pkg/operator/ceph/file/mds/spec.go index 31065deef..2fe5cceac 100644 --- a/pkg/operator/ceph/file/mds/spec.go +++ b/pkg/operator/ceph/file/mds/spec.go @@ -65,6 +65,7 @@ func (c *Cluster) makeDeployment(mdsConfig *mdsConfig, fsNamespacedname types.Na Volumes: controller.DaemonVolumes(mdsConfig.DataPathMap, mdsConfig.ResourceName, c.clusterSpec.DataDirHostPath), HostNetwork: c.clusterSpec.Network.IsHost(), PriorityClassName: c.fs.Spec.MetadataServer.PriorityClassName, + SecurityContext: &v1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, }, } diff --git a/pkg/operator/ceph/file/mirror/spec.go b/pkg/operator/ceph/file/mirror/spec.go index d13d1848b..383214115 100644 --- a/pkg/operator/ceph/file/mirror/spec.go +++ b/pkg/operator/ceph/file/mirror/spec.go @@ -46,6 +46,7 @@ func (r *ReconcileFilesystemMirror) makeDeployment(daemonConfig *daemonConfig, f Volumes: controller.DaemonVolumes(daemonConfig.DataPathMap, daemonConfig.ResourceName, r.cephClusterSpec.DataDirHostPath), HostNetwork: r.cephClusterSpec.Network.IsHost(), PriorityClassName: fsMirror.Spec.PriorityClassName, + SecurityContext: &v1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, }, } diff --git a/pkg/operator/ceph/nfs/spec.go b/pkg/operator/ceph/nfs/spec.go index 5834acf5c..e5d9fb1a0 100644 --- a/pkg/operator/ceph/nfs/spec.go +++ b/pkg/operator/ceph/nfs/spec.go @@ -149,6 +149,7 @@ func (r *ReconcileCephNFS) makeDeployment(nfs *cephv1.CephNFS, cfg daemonConfig) // connecting to the krb server. give all ganesha servers the same hostname so they can all // use the same krb credentials to auth Hostname: fmt.Sprintf("%s-%s", nfs.Namespace, nfs.Name), + SecurityContext: &v1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, } // Replace default unreachable node toleration diff --git a/pkg/operator/ceph/object/cosi/spec.go b/pkg/operator/ceph/object/cosi/spec.go index f0cc0a5a9..141db46e4 100644 --- a/pkg/operator/ceph/object/cosi/spec.go +++ b/pkg/operator/ceph/object/cosi/spec.go @@ -88,6 +88,7 @@ func createCOSIPodSpec(cephCOSIDriver *cephv1.CephCOSIDriver) (corev1.PodTemplat cosiDriverContainer, cosiSideCarContainer, }, + SecurityContext: &corev1.PodSecurityContext{}, ServiceAccountName: DefaultServiceAccountName, Volumes: []corev1.Volume{ {Name: cosiSocketVolumeName, VolumeSource: corev1.VolumeSource{EmptyDir: &corev1.EmptyDirVolumeSource{}}}, diff --git a/pkg/operator/ceph/object/spec.go b/pkg/operator/ceph/object/spec.go index 83d338f5a..1b6e5b056 100644 --- a/pkg/operator/ceph/object/spec.go +++ b/pkg/operator/ceph/object/spec.go @@ -150,6 +150,7 @@ func (c *clusterConfig) makeRGWPodSpec(rgwConfig *rgwConfig) (v1.PodTemplateSpec ), HostNetwork: hostNetwork, PriorityClassName: c.store.Spec.Gateway.PriorityClassName, + SecurityContext: &v1.PodSecurityContext{}, ServiceAccountName: serviceAccountName, } diff --git a/pkg/operator/discover/discover.go b/pkg/operator/discover/discover.go index b895badd7..5b73b8cc0 100644 --- a/pkg/operator/discover/discover.go +++ b/pkg/operator/discover/discover.go @@ -177,6 +177,7 @@ func (d *Discover) createDiscoverDaemonSet(ctx context.Context, namespace, disco }, HostNetwork: opcontroller.EnforceHostNetwork(), PriorityClassName: k8sutil.GetValue(data, discoverDaemonsetPriorityClassNameEnv, ""), + SecurityContext: &v1.PodSecurityContext{}, }, }, }, diff --git a/pkg/operator/k8sutil/cmdreporter/cmdreporter.go b/pkg/operator/k8sutil/cmdreporter/cmdreporter.go index b651def6d..3de895d3a 100644 --- a/pkg/operator/k8sutil/cmdreporter/cmdreporter.go +++ b/pkg/operator/k8sutil/cmdreporter/cmdreporter.go @@ -302,6 +302,7 @@ func (cr *cmdReporterCfg) initJobSpec() (*batch.Job, error) { *cmdReporterContainer, }, RestartPolicy: v1.RestartPolicyOnFailure, + SecurityContext: &v1.PodSecurityContext{}, ServiceAccountName: k8sutil.DefaultServiceAccount, HostNetwork: cephv1.EnforceHostNetwork(), }