File tree Expand file tree Collapse file tree 13 files changed +740
-0
lines changed
examples/pods/security/seccomp Expand file tree Collapse file tree 13 files changed +740
-0
lines changed Load Diff Large diffs are not rendered by default.
Original file line number Diff line number Diff line change
1
+ apiVersion : v1
2
+ kind : Pod
3
+ metadata :
4
+ name : audit-pod
5
+ labels :
6
+ app : audit-pod
7
+ annotations :
8
+ seccomp.security.alpha.kubernetes.io/pod : localhost/profiles/audit.json
9
+ spec :
10
+ containers :
11
+ - name : test-container
12
+ image : hashicorp/http-echo:0.2.3
13
+ args :
14
+ - " -text=just made some syscalls!"
15
+ securityContext :
16
+ allowPrivilegeEscalation : false
Original file line number Diff line number Diff line change
1
+ apiVersion : v1
2
+ kind : Pod
3
+ metadata :
4
+ name : default-pod
5
+ labels :
6
+ app : default-pod
7
+ annotations :
8
+ seccomp.security.alpha.kubernetes.io/pod : runtime/default
9
+ spec :
10
+ containers :
11
+ - name : test-container
12
+ image : hashicorp/http-echo:0.2.3
13
+ args :
14
+ - " -text=just made some syscalls!"
15
+ securityContext :
16
+ allowPrivilegeEscalation : false
Original file line number Diff line number Diff line change
1
+ apiVersion : v1
2
+ kind : Pod
3
+ metadata :
4
+ name : fine-pod
5
+ labels :
6
+ app : fine-pod
7
+ annotations :
8
+ seccomp.security.alpha.kubernetes.io/pod : localhost/profiles/fine-grained.json
9
+ spec :
10
+ containers :
11
+ - name : test-container
12
+ image : hashicorp/http-echo:0.2.3
13
+ args :
14
+ - " -text=just made some syscalls!"
15
+ securityContext :
16
+ allowPrivilegeEscalation : false
Original file line number Diff line number Diff line change
1
+ apiVersion : v1
2
+ kind : Pod
3
+ metadata :
4
+ name : violation-pod
5
+ labels :
6
+ app : violation-pod
7
+ annotations :
8
+ seccomp.security.alpha.kubernetes.io/pod : localhost/profiles/violation.json
9
+ spec :
10
+ containers :
11
+ - name : test-container
12
+ image : hashicorp/http-echo:0.2.3
13
+ args :
14
+ - " -text=just made some syscalls!"
15
+ securityContext :
16
+ allowPrivilegeEscalation : false
Original file line number Diff line number Diff line change
1
+ apiVersion : v1
2
+ kind : Pod
3
+ metadata :
4
+ name : audit-pod
5
+ labels :
6
+ app : audit-pod
7
+ spec :
8
+ securityContext :
9
+ seccompProfile :
10
+ type : Localhost
11
+ localhostProfile : profiles/audit.json
12
+ containers :
13
+ - name : test-container
14
+ image : hashicorp/http-echo:0.2.3
15
+ args :
16
+ - " -text=just made some syscalls!"
17
+ securityContext :
18
+ allowPrivilegeEscalation : false
Original file line number Diff line number Diff line change
1
+ apiVersion : v1
2
+ kind : Pod
3
+ metadata :
4
+ name : audit-pod
5
+ labels :
6
+ app : audit-pod
7
+ spec :
8
+ securityContext :
9
+ seccompProfile :
10
+ type : RuntimeDefault
11
+ containers :
12
+ - name : test-container
13
+ image : hashicorp/http-echo:0.2.3
14
+ args :
15
+ - " -text=just made some syscalls!"
16
+ securityContext :
17
+ allowPrivilegeEscalation : false
Original file line number Diff line number Diff line change
1
+ apiVersion : v1
2
+ kind : Pod
3
+ metadata :
4
+ name : fine-pod
5
+ labels :
6
+ app : fine-pod
7
+ spec :
8
+ securityContext :
9
+ seccompProfile :
10
+ type : Localhost
11
+ localhostProfile : profiles/fine-grained.json
12
+ containers :
13
+ - name : test-container
14
+ image : hashicorp/http-echo:0.2.3
15
+ args :
16
+ - " -text=just made some syscalls!"
17
+ securityContext :
18
+ allowPrivilegeEscalation : false
Original file line number Diff line number Diff line change
1
+ apiVersion : v1
2
+ kind : Pod
3
+ metadata :
4
+ name : violation-pod
5
+ labels :
6
+ app : violation-pod
7
+ spec :
8
+ securityContext :
9
+ seccompProfile :
10
+ type : Localhost
11
+ localhostProfile : profiles/violation.json
12
+ containers :
13
+ - name : test-container
14
+ image : hashicorp/http-echo:0.2.3
15
+ args :
16
+ - " -text=just made some syscalls!"
17
+ securityContext :
18
+ allowPrivilegeEscalation : false
Original file line number Diff line number Diff line change
1
+ apiVersion : kind.x-k8s.io/v1alpha4
2
+ kind : Cluster
3
+ nodes :
4
+ - role : control-plane
5
+ extraMounts :
6
+ - hostPath : " ./profiles"
7
+ containerPath : " /var/lib/kubelet/seccomp/profiles"
You can’t perform that action at this time.
0 commit comments