···33# To re-generate a bundle for another specific version without changing the standard setup, you can:
44# - use the VERSION as arg of the bundle target (e.g make bundle VERSION=0.0.2)
55# - use environment variables to overwrite this value (e.g export VERSION=0.0.2)
66-VERSION ?= 0.6.23
66+VERSION ?= 0.6.24
7788# CHANNELS define the bundle channels used in the bundle.
99# Add a new line here if you would like to change its default config. (E.g CHANNELS = "candidate,fast,stable")
+2-2
helm/hsm-secrets-operator/Chart.yaml
···22name: hsm-secrets-operator
33description: A Kubernetes operator that bridges Pico HSM binary data storage with Kubernetes Secrets
44type: application
55-version: 0.6.23
66-appVersion: v0.6.23
55+version: 0.6.24
66+appVersion: v0.6.24
77icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/kubernetes/icon/color/kubernetes-icon-color.svg
88home: https://github.com/evanjarrett/hsm-secrets-operator
99sources:
+2-6
internal/controller/hsmpool_agent_controller.go
···664664 },
665665 },
666666 SecurityContext: &corev1.SecurityContext{
667667- Privileged: falsePtr, // Still no privileged containers
667667+ Privileged: truePtr, // Still no privileged containers
668668 AllowPrivilegeEscalation: falsePtr, // Still no privilege escalation
669669- ReadOnlyRootFilesystem: truePtr, // Possible with distroless
669669+ ReadOnlyRootFilesystem: falsePtr, // Possible with distroless
670670 RunAsNonRoot: falsePtr, // Root required for USB
671671 RunAsUser: &rootUserId,
672672- Capabilities: &corev1.Capabilities{
673673- Drop: []corev1.Capability{"ALL"}, // Drop all capabilities
674674- // No additional capabilities needed with root
675675- },
676672 SeccompProfile: &corev1.SeccompProfile{
677673 Type: corev1.SeccompProfileTypeRuntimeDefault,
678674 },