Skip to content

Commit

Permalink
add securityContext example for Restricted pod-security policies
Browse files Browse the repository at this point in the history
  • Loading branch information
Greg May committed Feb 13, 2024
1 parent 19978b6 commit e6e9bfb
Show file tree
Hide file tree
Showing 4 changed files with 37 additions and 1 deletion.
5 changes: 4 additions & 1 deletion charts/tsm-node/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,10 @@ securityContext:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
# runAsUser: 2000
# allowPrivilegeEscalation: false
# seccompProfile:
# type: "RuntimeDefault"

# -- The primary service definition for the TSM node
sdkService:
Expand Down
11 changes: 11 additions & 0 deletions examples/tsm-node-multiinstance/tsm0.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -132,3 +132,14 @@ affinity:
resources:
requests:
cpu: 14

securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 2000
allowPrivilegeEscalation: false
seccompProfile:
type: "RuntimeDefault"
11 changes: 11 additions & 0 deletions examples/tsm-node-multiinstance/tsm1.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -132,3 +132,14 @@ affinity:
resources:
requests:
cpu: 14

securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 2000
allowPrivilegeEscalation: false
seccompProfile:
type: "RuntimeDefault"
11 changes: 11 additions & 0 deletions examples/tsm-node-multiinstance/tsm2.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -133,3 +133,14 @@ affinity:
resources:
requests:
cpu: 14

securityContext:
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 2000
allowPrivilegeEscalation: false
seccompProfile:
type: "RuntimeDefault"

0 comments on commit e6e9bfb

Please sign in to comment.