-
Notifications
You must be signed in to change notification settings - Fork 8.5k
Description
hello all,
to mitigate an azure defender fix for setting readOnlyRootFilesystem: true for the controller , can you please guide me or direct me to understand what are the volume mounts needed to make the deployment work?
tried adding these but i cant get the pod up and running in AKS as below
│ Autoscroll:On FullScreen:Off Timestamps:Off Wrap:Off │
│ ------------------------------------------------------------------------------- │
│ NGINX Ingress controller │
│ Release: v1.11.5 │
│ Build: 97ffeee │
│ Repository: https://github.com/kubernetes/ingress-nginx │
│ nginx version: nginx/1.25.5 │
│ │
│ ------------------------------------------------------------------------------- │
│ │
│ W1013 10:55:24.984095 7 client_config.go:667] Neither --kubeconfig nor --master was specified. Using the inClusterConfig. This might not work. │
│ I1013 10:55:24.984217 7 main.go:205] "Creating API client" host="https://172.16.0.1:443" │
│ I1013 10:55:24.999834 7 main.go:248] "Running in Kubernetes cluster" major="1" minor="32" git="v1.32.7" state="clean" commit="d5f83cad5f5356b280b95 │
│ I1013 10:55:25.009080 7 main.go:83] "Valid default backend" service="nginx-ingress/nginx-ingress-ingress-nginx-defaultbackend" │
│ I1013 10:55:25.186941 7 main.go:101] "SSL fake certificate created" file="/etc/ingress-controller/ssl/default-fake-certificate.pem" │
│ I1013 10:55:25.227394 7 ssl.go:535] "loading tls certificate" path="/usr/local/certificates/cert" key="/usr/local/certificates/key" │
│ F1013 10:55:25.239879 7 nginx.go:175] Invalid NGINX configuration template: unexpected error reading template /etc/nginx/template/nginx.tmpl: open │
│ stream closed: EOF for nginx-ingress/nginx-ingress-ingress-nginx-controller-twk5x (controller)
│ F1013 10:46:38.099641 7 nginx.go:175] Invalid NGINX configuration template: unexpected error reading template /etc/nginx/template/nginx.tmpl: open │
│ stream closed: EOF for nginx-ingress/nginx-ingress-ingress-nginx-controller-xkzcw (controller)
extraVolumeMounts:
- name: nginx-conf
mountPath: /etc/nginx
- name: tmp-nginx
mountPath: /tmp/nginx
- name: tmp-nginx-cache
mountPath: /tmp/nginx_cache
- name: var-run
mountPath: /var/run
- name: ssl-dir
mountPath: /etc/ingress-controller/ssl
- name: telemetry
mountPath: /etc/ingress-controller/telemetry
- name: var-lib-nginx
mountPath: /var/lib/nginx
- name: nginx-cache
mountPath: /var/cache/nginx
- name: nginx-tmp
mountPath: /tmp
- name: var-log-nginx
mountPath: /var/log/nginx
- name: copy-portal-skins
mountPath: /var/lib/lemonldap-ng/portal/skins
-- Additional volumes to the controller pod.
extraVolumes:
- name: nginx-conf
emptyDir: {}
- name: tmp-nginx
emptyDir: {}
- name: tmp-nginx-cache
emptyDir: {}
- name: var-run
emptyDir: {}
- name: ssl-dir
emptyDir: {}
- name: telemetry
emptyDir: {}
- name: var-lib-nginx
emptyDir: {}
- name: nginx-cache
emptyDir: {}
- name: nginx-tmp
emptyDir: {}
- name: var-log-nginx
emptyDir: {}
Metadata
Metadata
Assignees
Labels
Type
Projects
Status