zilliztech / milvus-helm

Apache License 2.0
54 stars 41 forks source link

Support setting the security context and pod topology spread constraints for MinIO #107

Open bcbrockway opened 2 months ago

bcbrockway commented 2 months ago

For security reasons, we use Kyverno's admission controller on our cluster to ensure that certain Linux capabilities are dropped and that containers run as non-root, along with other policies. While we can change the security contexts of the components using the Bitnami Helm charts (etcd, Kafka, etc.) we are unable to do this for MinIO.

In addition, in order to improve resiliency, we would like to be able to set Pod Topology Spread Constraints for the same components.

This is a feature request to expose these in the MinIO Helm chart.

Related to https://github.com/zilliztech/milvus-operator/issues/144