We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
2 parents 34837c2 + 285500f commit d3b5968Copy full SHA for d3b5968
config/manager/manager.yaml
@@ -3,6 +3,8 @@ kind: Namespace
3
metadata:
4
labels:
5
control-plane: controller-manager
6
+ pod-security.kubernetes.io/enforce: restricted
7
+ pod-security.kubernetes.io/enforce-version: v1.23
8
name: system
9
---
10
apiVersion: apps/v1
@@ -57,6 +59,14 @@ spec:
57
59
- containerPort: 8080
58
60
name: metrics
61
protocol: TCP
62
+ securityContext:
63
+ allowPrivilegeEscalation: false
64
+ readOnlyRootFilesystem: true
65
+ runAsNonRoot: true
66
+ seccompProfile:
67
+ type: RuntimeDefault
68
+ capabilities:
69
+ drop: ["ALL"]
70
volumeMounts:
71
- mountPath: /tmp/k8s-webhook-server/serving-certs
72
name: cert
0 commit comments