It would probably be good to set `readOnlyRootFilesystem` wherever possible to further secure the running containers. Found with https://github.com/stackrox/kube-linter