Skip to content

Commit 61b563f

Browse files
authored
move psa labels from deployment to namespace (#288)
1 parent 0eeeb0a commit 61b563f

File tree

1 file changed

+4
-9
lines changed

1 file changed

+4
-9
lines changed

config/manager/manager.yaml

Lines changed: 4 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,8 @@ metadata:
99
app.kubernetes.io/created-by: operator-controller
1010
app.kubernetes.io/part-of: operator-controller
1111
app.kubernetes.io/managed-by: kustomize
12+
pod-security.kubernetes.io/enforce: restricted
13+
pod-security.kubernetes.io/enforce-version: latest
1214
name: system
1315
---
1416
apiVersion: apps/v1
@@ -26,8 +28,6 @@ metadata:
2628
app.kubernetes.io/created-by: operator-controller
2729
app.kubernetes.io/part-of: operator-controller
2830
app.kubernetes.io/managed-by: kustomize
29-
pod-security.kubernetes.io/enforce: restricted
30-
pod-security.kubernetes.io/enforce-version: latest
3131
spec:
3232
selector:
3333
matchLabels:
@@ -62,13 +62,8 @@ spec:
6262
# - linux
6363
securityContext:
6464
runAsNonRoot: true
65-
# TODO(user): For common cases that do not require escalating privileges
66-
# it is recommended to ensure that all your Pods/Containers are restrictive.
67-
# More info: https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
68-
# Please uncomment the following code if your project does NOT have to work on old Kubernetes
69-
# versions < 1.19 or on vendors versions which do NOT support this field by default (i.e. Openshift < 4.11 ).
70-
# seccompProfile:
71-
# type: RuntimeDefault
65+
seccompProfile:
66+
type: RuntimeDefault
7267
containers:
7368
- command:
7469
- /manager

0 commit comments

Comments
 (0)