diff --git a/client_reference/kosli_version.md b/client_reference/kosli_version.md index 3283339..7b43215 100644 --- a/client_reference/kosli_version.md +++ b/client_reference/kosli_version.md @@ -12,7 +12,7 @@ kosli version [flags] ``` Print the version of a Kosli CLI. -The output will look something like this: +The output will look something like this: version.BuildInfo\{Version:"v0.0.1", GitCommit:"fe51cd1e31e6a202cba7dead9552a6d418ded79a", GitTreeState:"clean", GoVersion:"go1.16.3"\} - Version is the semantic version of the release. diff --git a/client_reference/overview.md b/client_reference/overview.md index cd1c813..e92a46d 100644 --- a/client_reference/overview.md +++ b/client_reference/overview.md @@ -4,7 +4,7 @@ description: "Reference documentation for the Kosli CLI." --- - This reference was generated from Kosli CLI **v2.16.0**. + This reference was generated from Kosli CLI **v2.17.0**. The Kosli CLI allows you to interact with Kosli from your terminal and CI/CD pipelines. diff --git a/helm/k8s_reporter.md b/helm/k8s_reporter.md index e0ed9a3..4045d19 100644 --- a/helm/k8s_reporter.md +++ b/helm/k8s_reporter.md @@ -176,10 +176,10 @@ If you already run [cert-manager's trust-manager](https://cert-manager.io/docs/t | reporterConfig.environments | list | `[]` | List of Kosli environments to report to. Each entry has required 'name' and optional namespace selectors. Use one entry to report a single environment; use multiple entries to report to multiple environments with different selectors. Per entry: name (required), namespaces, namespacesRegex, excludeNamespaces, excludeNamespacesRegex (optional). Leave namespace fields unset for an entry to report the entire cluster to that environment. | | reporterConfig.httpProxy | string | `""` | the http proxy url | | reporterConfig.kosliOrg | string | `""` | the name of the Kosli org | -| reporterConfig.securityContext | object | `{"allowPrivilegeEscalation":false,"runAsNonRoot":true,"runAsUser":1000}` | the security context for the reporter cronjob Set to null or {} to disable security context entirely (not recommended) For OpenShift, you can omit runAsUser to let OpenShift assign the UID | +| reporterConfig.securityContext | object | `{"allowPrivilegeEscalation":false,"runAsNonRoot":true,"runAsUser":1000}` | the security context for the reporter cronjob. Set to null or {} to disable security context entirely (not recommended). For OpenShift with SCC, explicitly set runAsUser to null to let OpenShift assign the UID from the allowed range. Simply omitting runAsUser from your values override will not work because Helm deep-merges with these defaults. Example OpenShift override: securityContext: allowPrivilegeEscalation: false runAsNonRoot: true runAsUser: null | | reporterConfig.securityContext.allowPrivilegeEscalation | bool | `false` | whether to allow privilege escalation | | reporterConfig.securityContext.runAsNonRoot | bool | `true` | whether to run as non root | -| reporterConfig.securityContext.runAsUser | int | `1000` | the user id to run as Omit this field for OpenShift environments to allow automatic UID assignment | +| reporterConfig.securityContext.runAsUser | int | `1000` | the user id to run as. For OpenShift environments with SCC, set to null (runAsUser: null) to allow automatic UID assignment. Simply omitting this field will not work due to Helm's deep merge with chart defaults. | | resources.limits.cpu | string | `"100m"` | the cpu limit | | resources.limits.memory | string | `"256Mi"` | the memory limit | | resources.requests.memory | string | `"64Mi"` | the memory request |