Skip to content

Commit f40b01c

Browse files
authored
Enhacement: More thorough security context (#107)
* Disable allowPrivilegeEscalation and attach SecComp Signed-off-by: Pascal Bachor <bachorp@users.noreply.github.com>
1 parent edb6585 commit f40b01c

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

valkey/values.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,12 +46,15 @@ podSecurityContext:
4646
fsGroup: 1000
4747
runAsUser: 1000
4848
runAsGroup: 1000
49+
seccompProfile:
50+
type: RuntimeDefault
4951

5052
# Priority class name for pod scheduling (leave empty to use cluster's default)
5153
priorityClassName: ""
5254

5355
# Security context for the Valkey containers
5456
securityContext:
57+
allowPrivilegeEscalation: false
5558
capabilities:
5659
drop:
5760
- ALL

0 commit comments

Comments
 (0)