Skip to content
Snippets Groups Projects
Commit 546a2e6a authored by Frederic Branczyk's avatar Frederic Branczyk
Browse files

*: Use non-root

parent 6afb6bce
No related branches found
No related tags found
No related merge requests found
FROM debian:9.3-slim
RUN apt-get update && apt-get install -qq -y wget tar sqlite && \
wget -O /tmp/grafana.tar.gz https://s3-us-west-2.amazonaws.com/grafana-releases/release/grafana-4.6.3.linux-x64.tar.gz && \
tar -zxvf /tmp/grafana.tar.gz -C /tmp && mv /tmp/grafana-4.6.3 /grafana && \
rm -rf /tmp/grafana.tar.gz
ADD config.toml /grafana/conf/config.toml
USER nobody
EXPOSE 3000
VOLUME [ "/data" ]
WORKDIR /grafana
ENTRYPOINT [ "/grafana/bin/grafana-server" ]
CMD [ "-config=/grafana/conf/config.toml" ]
container:
docker build . -t quay.io/coreos/monitoring-grafana:4.6.3-non-root
[database]
path = /data/grafana.db
......@@ -9,9 +9,12 @@ spec:
labels:
app: grafana
spec:
securityContext:
runAsNonRoot: true
runAsUser: 65534
containers:
- name: grafana
image: grafana/grafana:4.6.3
image: quay.io/coreos/monitoring-grafana:4.6.3-non-root
env:
- name: GF_AUTH_BASIC_ENABLED
value: "true"
......@@ -29,7 +32,7 @@ spec:
key: password
volumeMounts:
- name: grafana-storage
mountPath: /var/grafana-storage
mountPath: /data
ports:
- name: web
containerPort: 3000
......
......@@ -9,9 +9,12 @@ spec:
labels:
app: grafana
spec:
securityContext:
runAsNonRoot: true
runAsUser: 65534
containers:
- name: grafana
image: grafana/grafana:4.6.3
image: quay.io/coreos/monitoring-grafana:4.6.3-non-root
env:
- name: GF_AUTH_BASIC_ENABLED
value: "true"
......@@ -29,7 +32,7 @@ spec:
key: password
volumeMounts:
- name: grafana-storage
mountPath: /var/grafana-storage
mountPath: /data
ports:
- name: web
containerPort: 3000
......
......@@ -14,6 +14,9 @@ spec:
name: node-exporter
spec:
serviceAccountName: node-exporter
securityContext:
runAsNonRoot: true
runAsUser: 65534
hostNetwork: true
hostPID: true
containers:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment