diff --git a/openshift/operator-controller/kustomize/overlays/openshift/olmv1-ns/patches/manager_deployment_certs.yaml b/openshift/operator-controller/kustomize/overlays/openshift/olmv1-ns/patches/manager_deployment_certs.yaml index 7f5e9978..a9497231 100644 --- a/openshift/operator-controller/kustomize/overlays/openshift/olmv1-ns/patches/manager_deployment_certs.yaml +++ b/openshift/operator-controller/kustomize/overlays/openshift/olmv1-ns/patches/manager_deployment_certs.yaml @@ -22,3 +22,6 @@ - op: add path: /spec/template/spec/containers/0/env value: [{"name":"SSL_CERT_DIR", "value":"/var/ca-certs"}] +- op: add + path: /spec/template/spec/securityContext/seLinuxOptions + value: {"type":"spc_t"} diff --git a/openshift/operator-controller/manifests/20-deployment-openshift-operator-controller-operator-controller-controller-manager.yml b/openshift/operator-controller/manifests/20-deployment-openshift-operator-controller-operator-controller-controller-manager.yml index 10af5956..6b55f84f 100644 --- a/openshift/operator-controller/manifests/20-deployment-openshift-operator-controller-operator-controller-controller-manager.yml +++ b/openshift/operator-controller/manifests/20-deployment-openshift-operator-controller-operator-controller-controller-manager.yml @@ -97,6 +97,8 @@ spec: node-role.kubernetes.io/master: "" securityContext: runAsNonRoot: true + seLinuxOptions: + type: spc_t seccompProfile: type: RuntimeDefault serviceAccountName: operator-controller-controller-manager