Skip to content

Commit df509eb

Browse files
committed
update security context for CSI Node DS
1 parent aa0023b commit df509eb

File tree

1 file changed

+7
-2
lines changed
  • charts/spdk-csi/latest/spdk-csi/templates

1 file changed

+7
-2
lines changed

charts/spdk-csi/latest/spdk-csi/templates/node.yaml

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -71,10 +71,15 @@ spec:
7171
mountPath: /registration
7272
- name: csi-node
7373
securityContext:
74-
privileged: true
74+
runAsUser: 0
75+
runAsGroup: 0
76+
allowPrivilegeEscalation: false
7577
capabilities:
78+
drop: ["ALL"]
7679
add: ["SYS_ADMIN", "SYS_MODULE"]
77-
allowPrivilegeEscalation: true
80+
readOnlyRootFilesystem: true
81+
seccompProfile:
82+
type: RuntimeDefault
7883
image: "{{ .Values.image.csi.repository }}:{{ .Values.image.csi.tag }}"
7984
imagePullPolicy: {{ .Values.image.csi.pullPolicy }}
8085
args:

0 commit comments

Comments
 (0)