Skip to content

Commit 871e81c

Browse files
authored
Merge pull request #2078 from rajatchopra/gfd_in_sandbox_dp
new privileges for sandbox-device-plugin
2 parents f463225 + c725eef commit 871e81c

File tree

2 files changed

+30
-0
lines changed

2 files changed

+30
-0
lines changed

assets/state-sandbox-device-plugin/0200_role.yaml

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,3 +12,22 @@ rules:
1212
- use
1313
resourceNames:
1414
- privileged
15+
- apiGroups:
16+
- ""
17+
resources:
18+
- pods
19+
verbs:
20+
- create
21+
- get
22+
- list
23+
- watch
24+
- delete
25+
- apiGroups:
26+
- nfd.k8s-sigs.io
27+
resources:
28+
- nodefeatures
29+
verbs:
30+
- create
31+
- get
32+
- list
33+
- watch

assets/state-sandbox-device-plugin/0500_daemonset.yaml

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,17 @@ spec:
6161
- image: "FILLED BY THE OPERATOR"
6262
imagePullPolicy: IfNotPresent
6363
name: nvidia-sandbox-device-plugin-ctr
64+
env:
65+
- name: NODE_NAME
66+
valueFrom:
67+
fieldRef:
68+
apiVersion: v1
69+
fieldPath: spec.nodeName
70+
- name: POD_NAMESPACE
71+
valueFrom:
72+
fieldRef:
73+
apiVersion: v1
74+
fieldPath: metadata.namespace
6475
securityContext:
6576
privileged: true
6677
volumeMounts:

0 commit comments

Comments
 (0)