This commit is contained in:
2026-02-02 14:17:31 +11:00
parent e731c0ac77
commit a5fed4a656

View File

@@ -37,10 +37,10 @@ spec:
memory: "512Mi" memory: "512Mi"
cpu: "250m" cpu: "250m"
securityContext: securityContext:
allowPrivilegeEscalation: true allowPrivilegeEscalation: false
capabilities: capabilities:
drop: ["ALL"] drop: ["ALL"]
runAsNonRoot: false runAsNonRoot: true
seccompProfile: seccompProfile:
type: RuntimeDefault type: RuntimeDefault
volumes: volumes: