Important
Self-managed SingleStore will soon transition from version 9.1 RC to version 10. This new semantic versioning scheme will provide SingleStore with finer control over engine and feature releases that were not possible with the current versioning scheme.
In the interim, SingleStore 9.1 RC can be used to preview, evaluate, and provide feedback on the new and upcoming features in SingleStore 10 prior to its general availability. Ahead of this transition, SingleStore 9.0 is recommended for production workloads, which can later be upgraded to SingleStore 10.
Run SingleStore with Volume Mounts and Restricted Pod Security
To run SingleStore within a restricted security context, the aggregatorSpec, leafSpec, and backupSpec all support a securityContext field for overriding the pod security context to meet Kubernetes requirements.nodeVolumes field allows for mounting arbitrary volumes which, in this example, is required to allow writing to the /tmp directory.
aggregatorSpec:nodeVolumes:volumeMounts:- mountPath: /tmpname: tmpvolumes:- emptyDir: {}name: tmpsecurityContext:allowPrivilegeEscalation: falsecapabilities:drop:- ALLreadOnlyRootFilesystem: truerunAsNonRoot: truerunAsUser: 999seccompProfile:type: RuntimeDefault
backupSpec:securityContext:allowPrivilegeEscalation: falsecapabilities:drop:- ALLreadOnlyRootFilesystem: truerunAsNonRoot: truerunAsUser: 999seccompProfile:type: RuntimeDefault
Add the following to the container in the Operator deployment to allow it to meet the restricted security requirements.
securityContext:allowPrivilegeEscalation: falsecapabilities:drop:- ALLreadOnlyRootFilesystem: truerunAsNonRoot: truerunAsUser: 10001
Refer to Enforce Pod Security Standards with Namespace Labels for more information.
Last modified: