diff --git a/helm/minio/templates/statefulset.yaml b/helm/minio/templates/statefulset.yaml index f345f4c1c..9c5f815f5 100644 --- a/helm/minio/templates/statefulset.yaml +++ b/helm/minio/templates/statefulset.yaml @@ -191,6 +191,10 @@ spec: value: {{ tpl $val $ | quote }} {{- end }} resources: {{- toYaml .Values.resources | nindent 12 }} + {{- if and .Values.securityContext.enabled .Values.persistence.enabled }} + securityContext: + readOnlyRootFilesystem: {{ .Values.securityContext.readOnlyRootFilesystem | default false }} + {{- end }} {{- with .Values.extraContainers }} {{- if eq (typeOf .) "string" }} {{- tpl . $ | nindent 8 }} diff --git a/helm/minio/values.yaml b/helm/minio/values.yaml index 9d7a4d126..b84d37816 100644 --- a/helm/minio/values.yaml +++ b/helm/minio/values.yaml @@ -249,6 +249,7 @@ securityContext: runAsGroup: 1000 fsGroup: 1000 fsGroupChangePolicy: "OnRootMismatch" + readOnlyRootFilesystem: false # Additational pod annotations podAnnotations: {}