From ad843b9630762391772e4b7df596809202a395a2 Mon Sep 17 00:00:00 2001 From: Kellen Anker Date: Thu, 9 Oct 2025 10:04:30 -0600 Subject: [PATCH 1/3] add missing Linux CAP when running in VNM mode --- .pre-commit-config.yaml | 2 +- deployments/sdm-client/Chart.yaml | 2 +- deployments/sdm-client/templates/deployment.yaml | 5 +++++ deployments/sdm-client/values.yaml | 3 ++- 4 files changed, 9 insertions(+), 3 deletions(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index a17aed6..ff5a1fe 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -158,7 +158,7 @@ repos: pass_filenames: false - repo: https://github.com/losisin/helm-values-schema-json - rev: v2.2.1 + rev: v2.3.0 hooks: - id: helm-schema name: helm-schema | relay diff --git a/deployments/sdm-client/Chart.yaml b/deployments/sdm-client/Chart.yaml index 481f622..8a24969 100644 --- a/deployments/sdm-client/Chart.yaml +++ b/deployments/sdm-client/Chart.yaml @@ -1,7 +1,7 @@ apiVersion: v2 name: sdm-client kubeVersion: '>= 1.16.0-0' -version: 1.2.0 +version: 1.3.0 description: StrongDM Client Container type: application icon: https://raw.githubusercontent.com/strongdm/charts/main/sdm_icon.png diff --git a/deployments/sdm-client/templates/deployment.yaml b/deployments/sdm-client/templates/deployment.yaml index 6798881..a2d6053 100644 --- a/deployments/sdm-client/templates/deployment.yaml +++ b/deployments/sdm-client/templates/deployment.yaml @@ -48,6 +48,11 @@ spec: image: {{ template "strongdm.imageURI" . }} imagePullPolicy: {{ .Values.strongdm.image.pullPolicy }} {{- include "strongdm.resources" (dict "resources" .Values.strongdm.pod.resources) | nindent 10 }} + {{- if .Values.strongdm.config.vnmEnabled }} + securityContext: + capabilities: + add: ["NET_ADMIN"] + {{- end }} livenessProbe: exec: command: ["sdm", "ready"] diff --git a/deployments/sdm-client/values.yaml b/deployments/sdm-client/values.yaml index add9176..c5b7a2f 100644 --- a/deployments/sdm-client/values.yaml +++ b/deployments/sdm-client/values.yaml @@ -13,7 +13,8 @@ strongdm: digest: "" config: # @schema; description: General application configuration. - appDomain: app.strongdm.com # @schema; description: Control plane to which to connect. Format `uk.strongdm.com`, etc. + appDomain: app.strongdm.com # @schema; description: Control plane to which to connect. Format `app.uk.strongdm.com`, etc. + vnmEnabled: false # @schema; description: Whether Virtual Networking Mode is enabled on this StrongDM organization. Adds required Linux capabilities. disableAutoUpdate: false # @schema; description: Disable automatically checking for and applying updates. Implicitly set to `true` if @strongdm.image.tag or @strongdm.image.digest are supplied. maintenanceWindowStart: 0 # @schema; description: Hour of the day (0-23 UTC) to terminate connections and restart when applying updates. verboseLogs: false # @schema; description: Toggle debug logging. From 33d47460db99f04c8a06e55ab4e952f3b564fdc5 Mon Sep 17 00:00:00 2001 From: Kellen Anker Date: Thu, 9 Oct 2025 10:10:52 -0600 Subject: [PATCH 2/3] devel tag --- deployments/sdm-client/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/deployments/sdm-client/Chart.yaml b/deployments/sdm-client/Chart.yaml index 8a24969..e0531fe 100644 --- a/deployments/sdm-client/Chart.yaml +++ b/deployments/sdm-client/Chart.yaml @@ -1,7 +1,7 @@ apiVersion: v2 name: sdm-client kubeVersion: '>= 1.16.0-0' -version: 1.3.0 +version: 1.3.0-pre1 description: StrongDM Client Container type: application icon: https://raw.githubusercontent.com/strongdm/charts/main/sdm_icon.png From f9995d1086107555519b85eea1b192c3bcec611d Mon Sep 17 00:00:00 2001 From: Kellen Anker Date: Thu, 1 Oct 2026 14:27:28 -0600 Subject: [PATCH 3/3] fix schema --- deployments/sdm-client/values.schema.json | 7 +++++++ deployments/sdm-client/values.yaml | 14 +++++++------- 2 files changed, 14 insertions(+), 7 deletions(-) diff --git a/deployments/sdm-client/values.schema.json b/deployments/sdm-client/values.schema.json index 090e696..5fbff4a 100644 --- a/deployments/sdm-client/values.schema.json +++ b/deployments/sdm-client/values.schema.json @@ -33,24 +33,31 @@ } }, "config": { + "description": "General application configuration.", "type": "object", "properties": { "additionalEnvVars": { + "description": "Additional environment variables to add to the ConfigMap.", "type": "object" }, "appDomain": { + "description": "Control plane to which to connect. Format `app.uk.strongdm.com`, etc.", "type": "string" }, "disableAutoUpdate": { + "description": "Disable automatically checking for and applying updates. Implicitly set to `true` if @strongdm.image.tag or @strongdm.image.digest are supplied.", "type": "boolean" }, "maintenanceWindowStart": { + "description": "Hour of the day (0-23 UTC) to terminate connections and restart when applying updates.", "type": "integer" }, "verboseLogs": { + "description": "Toggle debug logging.", "type": "boolean" }, "vnmEnabled": { + "description": "Whether Virtual Networking Mode is enabled on this StrongDM organization. Adds required Linux capabilities.", "type": "boolean" } } diff --git a/deployments/sdm-client/values.yaml b/deployments/sdm-client/values.yaml index 81d45fd..2db7817 100644 --- a/deployments/sdm-client/values.yaml +++ b/deployments/sdm-client/values.yaml @@ -12,13 +12,13 @@ strongdm: tag: latest digest: "" - config: # @schema; description: General application configuration. - appDomain: app.strongdm.com # @schema; description: Control plane to which to connect. Format `app.uk.strongdm.com`, etc. - vnmEnabled: false # @schema; description: Whether Virtual Networking Mode is enabled on this StrongDM organization. Adds required Linux capabilities. - disableAutoUpdate: false # @schema; description: Disable automatically checking for and applying updates. Implicitly set to `true` if @strongdm.image.tag or @strongdm.image.digest are supplied. - maintenanceWindowStart: 0 # @schema; description: Hour of the day (0-23 UTC) to terminate connections and restart when applying updates. - verboseLogs: false # @schema; description: Toggle debug logging. - additionalEnvVars: {} # @schema; description: Additional environment variables to add to the ConfigMap. + config: # @schema description: General application configuration. + appDomain: app.strongdm.com # @schema description: Control plane to which to connect. Format `app.uk.strongdm.com`, etc. + vnmEnabled: false # @schema description: Whether Virtual Networking Mode is enabled on this StrongDM organization. Adds required Linux capabilities. + disableAutoUpdate: false # @schema description: Disable automatically checking for and applying updates. Implicitly set to `true` if @strongdm.image.tag or @strongdm.image.digest are supplied. + maintenanceWindowStart: 0 # @schema description: Hour of the day (0-23 UTC) to terminate connections and restart when applying updates. + verboseLogs: false # @schema description: Toggle debug logging. + additionalEnvVars: {} # @schema description: Additional environment variables to add to the ConfigMap. auth: # @schema description: StrongDM authentication sources. serviceToken: "" # @schema description: The SDM_SERVICE_TOKEN with which to authenticate this StrongDM client. Specify this directly, or provide an existing secret to @strongdm.auth.secretName.