added comment for root file system flag and updated the key names for tls certificates

Signed-off-by: Rajshekar Reddy <reddymh@gmail.com>
This commit is contained in:
Rajshekar Reddy 2023-02-01 09:57:16 +05:30
parent d8715f1ea0
commit a8bdf3027c
No known key found for this signature in database
GPG key ID: 74CE6BCE90A45F32

View file

@ -109,12 +109,14 @@ controller:
servicePortName: metrics
# -- the controller container's securityContext
securityContext:
readOnlyRootFilesystem: false
readOnlyRootFilesystem: true
runAsNonRoot: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
# # readOnlyRootFilesystem should be false SSL when using postgres
# readOnlyRootFilesystem: false
# -- enable persistence using postgres
persistence: {}
# connectionPool:
@ -141,10 +143,10 @@ controller:
# caCertSecret:
# name: argo-postgres-tls
# key: ca.crt
# serverCertSecret:
# clientCertSecret:
# name: argo-postgres-tls
# key: tls.crt
# serverKeySecret:
# clientKeySecret:
# name: argo-postgres-tls
# key: tls.key
# # default path to store postgres certificates if certPath is not defined: /home/argo/pgcerts