diff --git a/roles/download/defaults/main.yml b/roles/download/defaults/main.yml index 4085b0421e6c5a0405ccef3a38ff5f01e7db04f0..0139a3ab947288ca9b7cc8088cae65741f154cf7 100644 --- a/roles/download/defaults/main.yml +++ b/roles/download/defaults/main.yml @@ -1072,7 +1072,7 @@ nodelocaldns_version: "1.22.18" nodelocaldns_image_repo: "{{ kube_image_repo }}/dns/k8s-dns-node-cache" nodelocaldns_image_tag: "{{ nodelocaldns_version }}" -dnsautoscaler_version: 1.8.5 +dnsautoscaler_version: v1.8.8 dnsautoscaler_image_repo: "{{ kube_image_repo }}/cpa/cluster-proportional-autoscaler" dnsautoscaler_image_tag: "{{ dnsautoscaler_version }}" diff --git a/roles/kubernetes-apps/ansible/templates/dns-autoscaler.yml.j2 b/roles/kubernetes-apps/ansible/templates/dns-autoscaler.yml.j2 index 6ea165183cb1f18c7fbebc27ad97846266da2c3e..9704155bb2dd73ec73f4c665e9f414bc156f60f1 100644 --- a/roles/kubernetes-apps/ansible/templates/dns-autoscaler.yml.j2 +++ b/roles/kubernetes-apps/ansible/templates/dns-autoscaler.yml.j2 @@ -30,12 +30,13 @@ spec: labels: k8s-app: dns-autoscaler{{ coredns_ordinal_suffix }} annotations: - seccomp.security.alpha.kubernetes.io/pod: 'runtime/default' spec: nodeSelector: {{ dns_autoscaler_deployment_nodeselector}} priorityClassName: system-cluster-critical securityContext: + seccompProfile: + type: RuntimeDefault supplementalGroups: [ 65534 ] fsGroup: 65534 nodeSelector: