Skip to content

Commit 2bbe58f

Browse files
Merge pull request #136 from razo7/read-only-pod-fs
Limit Access to the pod's Root File System
2 parents 280dbc2 + 58dd50a commit 2bbe58f

File tree

2 files changed

+2
-0
lines changed

2 files changed

+2
-0
lines changed

bundle/manifests/node-maintenance-operator.clusterserviceversion.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -283,6 +283,7 @@ spec:
283283
capabilities:
284284
drop:
285285
- ALL
286+
readOnlyRootFilesystem: true
286287
priorityClassName: system-cluster-critical
287288
securityContext:
288289
runAsNonRoot: true

config/manager/manager.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,7 @@ spec:
6767
name: manager
6868
securityContext:
6969
allowPrivilegeEscalation: false
70+
readOnlyRootFilesystem: true
7071
capabilities:
7172
drop:
7273
- "ALL"

0 commit comments

Comments
 (0)