RunAsGroup / Pod Spec Overlay for Container steps (Custom stage)
R
Rubber Scallop
Summary
EKS clusters with OPA Gatekeeper enforce runAsGroup. Harness supports Pod Spec Overlay for CI stage Kubernetes infrastructure, but Container steps in Custom stages don’t expose Pod Spec Overlay or a runAsGroup field, causing admission failures unless users manually edit YAML per pipeline/step.
Current Behavior
Custom-stage Container step UI exposes Run as User / Run as Non Root / Privileged / Capabilities, but not runAsGroup or Pod Spec Overlay.
Adding podSpecOverlay directly in YAML works, but must be repeated everywhere.
Request
- Allow a default/inherited Pod Spec Overlay at Kubernetes infrastructure/connector/account/org/project level applied to all K8s step executions (CI + non-CI).