fix(umami): don't mount root FS read-only
All checks were successful
Renovate / renovate (push) Successful in 21s

This commit is contained in:
Peter 2024-04-29 16:58:24 +02:00
parent 493d52ad41
commit 6c7f7d4505
Signed by: prskr
GPG key ID: F56BED6903BC5E37

View file

@ -36,17 +36,12 @@ spec:
- containerPort: 3000 - containerPort: 3000
protocol: TCP protocol: TCP
name: web name: web
volumeMounts:
- name: next-cache
mountPath: /data/.next/cache
- name: node-cache
mountPath: /home/node/.cache
securityContext: securityContext:
allowPrivilegeEscalation: false allowPrivilegeEscalation: false
capabilities: capabilities:
drop: drop:
- ALL - ALL
readOnlyRootFilesystem: true readOnlyRootFilesystem: false
affinity: affinity:
nodeAffinity: nodeAffinity:
preferredDuringSchedulingIgnoredDuringExecution: preferredDuringSchedulingIgnoredDuringExecution:
@ -61,10 +56,3 @@ spec:
runAsUser: 1000 runAsUser: 1000
runAsGroup: 1000 runAsGroup: 1000
runAsNonRoot: true runAsNonRoot: true
volumes:
- name: next-cache
emptyDir:
sizeLimit: 250Mi
- name: node-cache
emptyDir:
sizeLimit: 1500Mi