diff --git a/controller/controllers/component_controller.go b/controller/controllers/component_controller.go index 734a35a23..e32b0300c 100644 --- a/controller/controllers/component_controller.go +++ b/controller/controllers/component_controller.go @@ -286,13 +286,13 @@ func GetPodSecurityContextFromAnnotation(annotations map[string]string) *coreV1. annotationFound := false for k, v := range annotations { - if !strings.HasPrefix(k, "core.kalm.dev/podExt/securityContext") { + if !strings.HasPrefix(k, "core.kalm.dev/podExt-securityContext-") { continue } annotationFound = true - rest := strings.TrimPrefix(k, "core.kalm.dev/podExt/securityContext") + rest := strings.TrimPrefix(k, "core.kalm.dev/podExt-securityContext-") switch rest { case "runAsGroup": diff --git a/controller/controllers/logsystem_controller.go b/controller/controllers/logsystem_controller.go index c6a9185df..28b7c2e89 100644 --- a/controller/controllers/logsystem_controller.go +++ b/controller/controllers/logsystem_controller.go @@ -186,8 +186,8 @@ func (r *LogSystemReconcilerTask) ReconcilePLGMonolithicLoki() error { Spec: corev1alpha1.ComponentSpec{ Annotations: map[string]string{ "sidecar.istio.io/inject": "false", - "core.kalm.dev/podExt/securityContext/runAsGroup": "0", - "core.kalm.dev/podExt/securityContext/runAsUser": "0", + "core.kalm.dev/podExt-securityContext-runAsGroup": "0", + "core.kalm.dev/podExt-securityContext-runAsUser": "0", }, Image: lokiImage, WorkloadType: corev1alpha1.WorkloadTypeStatefulSet,