Major Enhancement
Allow configuring default container/pod SecurityContext in CheCluster CR
New CheCluster CR fields have been introduced spec.devEnvironments.security
, spec.devEnvironments.security.containerSecurityContext
, and spec.devEnvironments.security.podSecurityContext
.
The latter two fields allow configuring the pod and security contexts used by workspaces by setting the corresponding DWOC fields.
When the devEnvironments.security.containerSecurityContext
field is used and devEnvironments.disableContainerBuildCapabilities
is set to false
, the container security context required for the container-builds
SCC will be used, overriding the security context set in devEnvironments.security.containerSecurityContext
.