X-Git-Url: https://osm.etsi.org/gitweb/?a=blobdiff_plain;f=installers%2Fdocker%2Fosm_pods%2Flcm.yaml;h=3e5a271d0613611db3cd9594aa7598cd7e35c298;hb=refs%2Fchanges%2F52%2F14052%2F2;hp=517c069562602b16d4ed561883faa5e0a2e04a4a;hpb=c973b57b1f34ecb64f248f3098ac7b79c1b8a0ae;p=osm%2Fdevops.git diff --git a/installers/docker/osm_pods/lcm.yaml b/installers/docker/osm_pods/lcm.yaml index 517c0695..3e5a271d 100644 --- a/installers/docker/osm_pods/lcm.yaml +++ b/installers/docker/osm_pods/lcm.yaml @@ -31,13 +31,17 @@ spec: labels: app: lcm spec: + securityContext: + runAsUser: 1000 + runAsGroup: 1000 + fsGroup: 1000 initContainers: - name: kafka-ro-mongo-test image: alpine:latest command: ["sh", "-c", "until (nc -zvw1 kafka 9092 && nc -zvw1 ro 9090 && nc -zvw1 mongodb-k8s 27017 ); do sleep 3; done; exit 0"] containers: - name: lcm - image: opensourcemano/lcm:11 + image: opensourcemano/lcm:13 env: - name: OSMLCM_RO_HOST value: ro @@ -55,11 +59,17 @@ spec: value: mongodb://mongodb-k8s:27017/?replicaSet=rs0 envFrom: - secretRef: - name: lcm-secret + name: lcm-secret volumeMounts: - - name: osm-packages - mountPath: /app/storage + - mountPath: /etc/ssl/certs/osm-ca.crt + name: osm-ca + readOnly: true + subPath: osm-ca.crt volumes: - - name: osm-packages - hostPath: - path: /var/lib/osm/osm_osm_packages/_data + - name: osm-ca + secret: + defaultMode: 420 + items: + - key: tls.crt + path: osm-ca.crt + secretName: osm-ca