Skip to content

Commit 8b27caf

Browse files
author
Rohit Patil
committed
add mustrunasrange
1 parent 521c397 commit 8b27caf

2 files changed

Lines changed: 4 additions & 1 deletion

File tree

  • openshift-kube-apiserver/admission/customresourcevalidation/securitycontextconstraints/validation
  • vendor/github.com/openshift/api/security/v1

openshift-kube-apiserver/admission/customresourcevalidation/securitycontextconstraints/validation/validation.go

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,9 +73,10 @@ func ValidateSecurityContextConstraints(scc *securityv1.SecurityContextConstrain
7373
// ensure the runAsGroup strategy has a valid type
7474
if len(scc.RunAsGroup.Type) > 0 {
7575
if scc.RunAsGroup.Type != securityv1.RunAsGroupStrategyMustRunAs &&
76+
scc.RunAsGroup.Type != securityv1.RunAsGroupStrategyMustRunAsRange &&
7677
scc.RunAsGroup.Type != securityv1.RunAsGroupStrategyRunAsAny {
7778
allErrs = append(allErrs, field.NotSupported(field.NewPath("runAsGroup", "type"), scc.RunAsGroup.Type,
78-
[]string{string(securityv1.RunAsGroupStrategyMustRunAs), string(securityv1.RunAsGroupStrategyRunAsAny)}))
79+
[]string{string(securityv1.RunAsGroupStrategyMustRunAs), string(securityv1.RunAsGroupStrategyMustRunAsRange), string(securityv1.RunAsGroupStrategyRunAsAny)}))
7980
}
8081
allErrs = append(allErrs, validateIDRanges(scc.RunAsGroup.Ranges, field.NewPath("runAsGroup"))...)
8182

vendor/github.com/openshift/api/security/v1/types.go

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)