podsecuritypolicy.yaml 758 B

12345678910111213141516171819202122232425262728293031
  1. {{- if .Values.podSecurityPolicy.enabled }}
  2. apiVersion: {{ template "podSecurityPolicy.apiVersion" . }}
  3. kind: PodSecurityPolicy
  4. metadata:
  5. name: {{ template "nfs-client-provisioner.fullname" . }}
  6. labels:
  7. app: {{ template "nfs-client-provisioner.name" . }}
  8. chart: {{ .Chart.Name }}-{{ .Chart.Version }}
  9. heritage: {{ .Release.Service }}
  10. release: {{ .Release.Name }}
  11. spec:
  12. privileged: false
  13. allowPrivilegeEscalation: false
  14. requiredDropCapabilities:
  15. - ALL
  16. volumes:
  17. - 'secret'
  18. - 'nfs'
  19. hostNetwork: false
  20. hostIPC: false
  21. hostPID: false
  22. runAsUser:
  23. rule: 'RunAsAny'
  24. seLinux:
  25. rule: 'RunAsAny'
  26. supplementalGroups:
  27. rule: 'RunAsAny'
  28. fsGroup:
  29. rule: 'RunAsAny'
  30. readOnlyRootFilesystem: false
  31. {{- end }}