added runAsNonRoot, dropped caps and disallow priv escalation
All checks were successful
continuous-integration/publish-helm Helm publish succeeded
All checks were successful
continuous-integration/publish-helm Helm publish succeeded
This commit is contained in:
50
values.yaml
50
values.yaml
@@ -252,20 +252,28 @@ injector:
|
||||
certName: tls.crt
|
||||
keyName: tls.key
|
||||
|
||||
# Security context for the pod template and the injector container
|
||||
# The default pod securityContext is:
|
||||
# runAsNonRoot: true
|
||||
# runAsGroup: {{ .Values.injector.gid | default 1000 }}
|
||||
# runAsUser: {{ .Values.injector.uid | default 100 }}
|
||||
# fsGroup: {{ .Values.injector.gid | default 1000 }}
|
||||
# and for container is
|
||||
# allowPrivilegeEscalation: false
|
||||
# capabilities:
|
||||
# drop:
|
||||
# - ALL
|
||||
securityContext:
|
||||
pod: {}
|
||||
container: {}
|
||||
# Security context for the pod template and the injector container
|
||||
# The default pod securityContext is:
|
||||
# runAsNonRoot: true
|
||||
# runAsGroup: {{ .Values.injector.gid | default 1000 }}
|
||||
# runAsUser: {{ .Values.injector.uid | default 100 }}
|
||||
# fsGroup: {{ .Values.injector.gid | default 1000 }}
|
||||
# and for container is
|
||||
# allowPrivilegeEscalation: false
|
||||
# capabilities:
|
||||
# drop:
|
||||
# - ALL
|
||||
#securityContext:
|
||||
# pod: {}
|
||||
# container: {}
|
||||
securityContext:
|
||||
pod:
|
||||
runAsNonRoot: true
|
||||
container:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
|
||||
resources: {}
|
||||
# resources:
|
||||
@@ -1031,9 +1039,17 @@ server:
|
||||
# If not set, these will default to, and for OpenShift:
|
||||
# pod: {}
|
||||
# container: {}
|
||||
securityContext:
|
||||
pod: {}
|
||||
container: {}
|
||||
#securityContext:
|
||||
# pod: {}
|
||||
# container: {}
|
||||
securityContext:
|
||||
pod:
|
||||
runAsNonRoot: true
|
||||
container:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
|
||||
# Should the server pods run on the host network
|
||||
hostNetwork: false
|
||||
|
||||
Reference in New Issue
Block a user