Skip to content

Latest commit

 

History

History
22 lines (21 loc) · 405 Bytes

File metadata and controls

22 lines (21 loc) · 405 Bytes

security context

  • capabilities are limited to container level

definition

apiVersion: v1
kind: Pod
metadata:
	name: "hello"
spec:
	securityContext: # pod level
		runAsUser: 1000
    containers:
        - name: nginx-server
	      image: nginx:latest
	      command: ["nginx"]
		  args: [""]
		  securityContext: # container level
			runAsUser: 1000
			capabilities:
				add: ["MAC_ADMIN"]