From 6ba1a667e3117200e801652c28ec15a9193e2bb1 Mon Sep 17 00:00:00 2001 From: Derek Roberts Date: Fri, 1 Sep 2023 16:33:24 -0700 Subject: [PATCH] fix: Caddy upgrade for security warnings (#456) --- public/Dockerfile | 3 +-- public/openshift.deploy.yml | 3 +++ 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/public/Dockerfile b/public/Dockerfile index 1afc25230..2b907ec6e 100644 --- a/public/Dockerfile +++ b/public/Dockerfile @@ -2,7 +2,6 @@ ARG build_dir=public ARG port=4300 - # Build container FROM node:18.16.1-alpine3.17 AS build @@ -17,7 +16,7 @@ RUN cd libs && npm ci && cd .. && \ # Deploy container -FROM caddy:2.4.6-alpine +FROM caddy:2.6.4-alpine # Copy over Caddyfile and static content ARG build_dir diff --git a/public/openshift.deploy.yml b/public/openshift.deploy.yml index d14fef9af..fbdf95799 100644 --- a/public/openshift.deploy.yml +++ b/public/openshift.deploy.yml @@ -109,6 +109,9 @@ objects: spec: containers: - image: ${NAME}-${ZONE}-${COMPONENT}:${ZONE}-${COMPONENT} + securityContext: + capabilities: + add: ["NET_BIND_SERVICE"] imagePullPolicy: Always name: ${NAME} env: