File tree 1 file changed +4
-9
lines changed 1 file changed +4
-9
lines changed Original file line number Diff line number Diff line change @@ -9,6 +9,8 @@ metadata:
9
9
app.kubernetes.io/created-by : operator-controller
10
10
app.kubernetes.io/part-of : operator-controller
11
11
app.kubernetes.io/managed-by : kustomize
12
+ pod-security.kubernetes.io/enforce : restricted
13
+ pod-security.kubernetes.io/enforce-version : latest
12
14
name : system
13
15
---
14
16
apiVersion : apps/v1
@@ -26,8 +28,6 @@ metadata:
26
28
app.kubernetes.io/created-by : operator-controller
27
29
app.kubernetes.io/part-of : operator-controller
28
30
app.kubernetes.io/managed-by : kustomize
29
- pod-security.kubernetes.io/enforce : restricted
30
- pod-security.kubernetes.io/enforce-version : latest
31
31
spec :
32
32
selector :
33
33
matchLabels :
62
62
# - linux
63
63
securityContext :
64
64
runAsNonRoot : true
65
- # TODO(user): For common cases that do not require escalating privileges
66
- # it is recommended to ensure that all your Pods/Containers are restrictive.
67
- # More info: https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
68
- # Please uncomment the following code if your project does NOT have to work on old Kubernetes
69
- # versions < 1.19 or on vendors versions which do NOT support this field by default (i.e. Openshift < 4.11 ).
70
- # seccompProfile:
71
- # type: RuntimeDefault
65
+ seccompProfile :
66
+ type : RuntimeDefault
72
67
containers :
73
68
- command :
74
69
- /manager
You can’t perform that action at this time.
0 commit comments