You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何基于OpenShift集群条件创建Helm模板中的SCC资源

如何在Helm Chart中仅在OpenShift集群自动创建SCC资源

你的现有方案需要手动设置isOpenshift参数来控制SCC资源的渲染,不够自动化。下面提供几种无需手动传参、自动识别OpenShift集群的实现方式:

方式一:通过lookup函数检测默认SCC

利用Helm的lookup函数查询OpenShift特有的默认restricted SCC资源,若能查询到则判定为OpenShift集群,自动渲染自定义SCC:

{{- if lookup "security.openshift.io/v1" "SecurityContextConstraints" "" "restricted" }}
apiVersion: security.openshift.io/v1
kind: SecurityContextConstraints
metadata:
  name: {{ .Release.Name }}-custom-scc
# 替换为你的SCC具体配置
allowPrivilegeEscalation: false
allowedCapabilities:
  - NET_BIND_SERVICE
seLinuxContext:
  type: MustRunAs
runAsUser:
  type: MustRunAsRange
# ...其他SCC配置项
{{- end }}

方式二:检测OpenShift专属命名空间

如果查询SCC存在权限问题,可以通过检测OpenShift默认存在的openshift-config命名空间来判断集群类型:

{{- if lookup "" "Namespace" "" "openshift-config" }}
apiVersion: security.openshift.io/v1
kind: SecurityContextConstraints
metadata:
  name: {{ .Release.Name }}-custom-scc
# 你的SCC配置内容
{{- end }}

方式三:检测OpenShift API组

通过检查集群支持的API版本中是否包含security.openshift.io/v1来判定:

{{- $isOpenshift := false }}
{{- range .Capabilities.APIVersions }}
  {{- if eq . "security.openshift.io/v1" }}
    {{- $isOpenshift = true }}
  {{- end }}
{{- end }}
{{- if $isOpenshift }}
apiVersion: security.openshift.io/v1
kind: SecurityContextConstraints
metadata:
  name: {{ .Release.Name }}-custom-scc
# 你的SCC配置内容
{{- end }}

注意事项

  • 以上方案均基于Helm 3.x版本,lookup函数在Helm 3中才被引入
  • 使用lookup函数时,确保执行Helm安装的ServiceAccount具备查询对应资源的权限
  • 无需再手动传入--set isOpenshift=true参数,执行helm install <release-name> <chart> -n <namespace>即可自动完成SCC的创建

内容的提问来源于stack exchange,提问作者lprakashv

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 09:25:19