Important
The SingleStore 9.1 release candidate (RC) is available now. It will be promoted to general availability (GA) soon and at that time it will be renamed to SingleStore 10.
In the interim, SingleStore 9.1 RC can be used to preview, evaluate, and provide feedback on the new and upcoming features in SingleStore 10, while SingleStore 9.0 is recommended for production workloads.
Run SingleStore with Volume Mounts and Restricted Pod Security
To run SingleStore within a restricted security context, the aggregatorSpec, leafSpec, and backupSpec all support a securityContext field for overriding the pod security context to meet Kubernetes requirements.nodeVolumes field allows for mounting arbitrary volumes which, in this example, is required to allow writing to the /tmp directory.
aggregatorSpec:nodeVolumes:volumeMounts:- mountPath: /tmpname: tmpvolumes:- emptyDir: {}name: tmpsecurityContext:allowPrivilegeEscalation: falsecapabilities:drop:- ALLreadOnlyRootFilesystem: truerunAsNonRoot: truerunAsUser: 999seccompProfile:type: RuntimeDefault
backupSpec:securityContext:allowPrivilegeEscalation: falsecapabilities:drop:- ALLreadOnlyRootFilesystem: truerunAsNonRoot: truerunAsUser: 999seccompProfile:type: RuntimeDefault
Add the following to the container in the Operator deployment to allow it to meet the restricted security requirements.
securityContext:allowPrivilegeEscalation: falsecapabilities:drop:- ALLreadOnlyRootFilesystem: truerunAsNonRoot: truerunAsUser: 10001
Refer to Enforce Pod Security Standards with Namespace Labels for more information.
Last modified: