diff --git a/deployments/sdm-client/Chart.yaml b/deployments/sdm-client/Chart.yaml index bf287fb..8a24969 100644 --- a/deployments/sdm-client/Chart.yaml +++ b/deployments/sdm-client/Chart.yaml @@ -1,7 +1,7 @@ apiVersion: v2 name: sdm-client kubeVersion: '>= 1.16.0-0' -version: 1.2.1 +version: 1.3.0 description: StrongDM Client Container type: application icon: https://raw.githubusercontent.com/strongdm/charts/main/sdm_icon.png diff --git a/deployments/sdm-client/templates/deployment.yaml b/deployments/sdm-client/templates/deployment.yaml index 0a4093d..f9083ec 100644 --- a/deployments/sdm-client/templates/deployment.yaml +++ b/deployments/sdm-client/templates/deployment.yaml @@ -48,6 +48,11 @@ spec: image: {{ template "strongdm.imageURI" . }} imagePullPolicy: {{ .Values.strongdm.image.pullPolicy }} {{- include "strongdm.resources" (dict "resources" .Values.strongdm.pod.resources) | nindent 10 }} + {{- if .Values.strongdm.config.vnmEnabled }} + securityContext: + capabilities: + add: ["NET_ADMIN"] + {{- end }} livenessProbe: exec: command: ["sdm", "ready"] diff --git a/deployments/sdm-client/values.schema.json b/deployments/sdm-client/values.schema.json index b982997..5fbff4a 100644 --- a/deployments/sdm-client/values.schema.json +++ b/deployments/sdm-client/values.schema.json @@ -41,7 +41,7 @@ "type": "object" }, "appDomain": { - "description": "Control plane to which to connect. Format `uk.strongdm.com`, etc.", + "description": "Control plane to which to connect. Format `app.uk.strongdm.com`, etc.", "type": "string" }, "disableAutoUpdate": { @@ -55,6 +55,10 @@ "verboseLogs": { "description": "Toggle debug logging.", "type": "boolean" + }, + "vnmEnabled": { + "description": "Whether Virtual Networking Mode is enabled on this StrongDM organization. Adds required Linux capabilities.", + "type": "boolean" } } }, diff --git a/deployments/sdm-client/values.yaml b/deployments/sdm-client/values.yaml index 45e88af..2db7817 100644 --- a/deployments/sdm-client/values.yaml +++ b/deployments/sdm-client/values.yaml @@ -13,7 +13,8 @@ strongdm: digest: "" config: # @schema description: General application configuration. - appDomain: app.strongdm.com # @schema description: Control plane to which to connect. Format `uk.strongdm.com`, etc. + appDomain: app.strongdm.com # @schema description: Control plane to which to connect. Format `app.uk.strongdm.com`, etc. + vnmEnabled: false # @schema description: Whether Virtual Networking Mode is enabled on this StrongDM organization. Adds required Linux capabilities. disableAutoUpdate: false # @schema description: Disable automatically checking for and applying updates. Implicitly set to `true` if @strongdm.image.tag or @strongdm.image.digest are supplied. maintenanceWindowStart: 0 # @schema description: Hour of the day (0-23 UTC) to terminate connections and restart when applying updates. verboseLogs: false # @schema description: Toggle debug logging.