Skip to content
Snippets Groups Projects
Unverified Commit fa9f85c7 authored by Cristian Calin's avatar Cristian Calin Committed by GitHub
Browse files

[sysctl] set fs.may_detach_mounts=1 even when CRIs don't set it themselves (#8635)

parent ffa285c2
No related branches found
No related tags found
No related merge requests found
...@@ -87,6 +87,24 @@ ...@@ -87,6 +87,24 @@
reload: yes reload: yes
when: enable_dual_stack_networks | bool when: enable_dual_stack_networks | bool
- name: Check if we need to set fs.may_detach_mounts
stat:
path: /proc/sys/fs/may_detach_mounts
get_attributes: no
get_checksum: no
get_mime: no
register: fs_may_detach_mounts
ignore_errors: true # noqa ignore-errors
- name: Set fs.may_detach_mounts if needed
sysctl:
sysctl_file: "{{ sysctl_file_path }}"
name: fs.may_detach_mounts
value: 1
state: present
reload: yes
when: fs_may_detach_mounts.stat.exists | d(false)
- name: Ensure kube-bench parameters are set - name: Ensure kube-bench parameters are set
sysctl: sysctl:
sysctl_file: "{{ sysctl_file_path }}" sysctl_file: "{{ sysctl_file_path }}"
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment