如何基于OpenShift集群条件创建Helm模板中的SCC资源
如何在Helm Chart中仅在OpenShift集群自动创建SCC资源
你的现有方案需要手动设置isOpenshift参数来控制SCC资源的渲染,不够自动化。下面提供几种无需手动传参、自动识别OpenShift集群的实现方式:
方式一:通过lookup函数检测默认SCC
利用Helm的lookup函数查询OpenShift特有的默认restricted SCC资源,若能查询到则判定为OpenShift集群,自动渲染自定义SCC:
{{- if lookup "security.openshift.io/v1" "SecurityContextConstraints" "" "restricted" }} apiVersion: security.openshift.io/v1 kind: SecurityContextConstraints metadata: name: {{ .Release.Name }}-custom-scc # 替换为你的SCC具体配置 allowPrivilegeEscalation: false allowedCapabilities: - NET_BIND_SERVICE seLinuxContext: type: MustRunAs runAsUser: type: MustRunAsRange # ...其他SCC配置项 {{- end }}
方式二:检测OpenShift专属命名空间
如果查询SCC存在权限问题,可以通过检测OpenShift默认存在的openshift-config命名空间来判断集群类型:
{{- if lookup "" "Namespace" "" "openshift-config" }} apiVersion: security.openshift.io/v1 kind: SecurityContextConstraints metadata: name: {{ .Release.Name }}-custom-scc # 你的SCC配置内容 {{- end }}
方式三:检测OpenShift API组
通过检查集群支持的API版本中是否包含security.openshift.io/v1来判定:
{{- $isOpenshift := false }} {{- range .Capabilities.APIVersions }} {{- if eq . "security.openshift.io/v1" }} {{- $isOpenshift = true }} {{- end }} {{- end }} {{- if $isOpenshift }} apiVersion: security.openshift.io/v1 kind: SecurityContextConstraints metadata: name: {{ .Release.Name }}-custom-scc # 你的SCC配置内容 {{- end }}
注意事项
- 以上方案均基于Helm 3.x版本,
lookup函数在Helm 3中才被引入 - 使用
lookup函数时,确保执行Helm安装的ServiceAccount具备查询对应资源的权限 - 无需再手动传入
--set isOpenshift=true参数,执行helm install <release-name> <chart> -n <namespace>即可自动完成SCC的创建
内容的提问来源于stack exchange,提问作者lprakashv
相关产品推荐
相关产品推荐

