-
Notifications
You must be signed in to change notification settings - Fork 0
/
scc-node-app.yaml
109 lines (109 loc) · 2.41 KB
/
scc-node-app.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
allowHostPorts: false
priority: null
requiredDropCapabilities: null
allowPrivilegedContainer: false
runAsUser:
type: MustRunAs
uid: 1000720001
users: []
allowHostDirVolumePlugin: false
seccompProfiles:
- runtime/default
allowHostIPC: false
seLinuxContext:
type: MustRunAs
readOnlyRootFilesystem: false
metadata:
annotations:
kubernetes.io/description: scc-node-app is the minimal SCC needed to run nodejs nodes on Kubernetes.
creationTimestamp: '2024-01-30T05:52:27Z'
generation: 6
managedFields:
- apiVersion: security.openshift.io/v1
fieldsType: FieldsV1
fieldsV1:
'f:seLinuxContext':
.: {}
'f:type': {}
'f:readOnlyRootFilesystem': {}
'f:metadata':
'f:annotations':
.: {}
'f:kubernetes.io/description': {}
'f:volumes': {}
'f:groups': {}
'f:defaultAddCapabilities': {}
'f:allowedCapabilities': {}
'f:supplementalGroups':
.: {}
'f:type': {}
'f:allowHostPID': {}
'f:allowHostNetwork': {}
'f:allowPrivilegeEscalation': {}
'f:users': {}
'f:runAsUser':
.: {}
'f:type': {}
'f:uid': {}
'f:allowHostPorts': {}
'f:seccompProfiles': {}
'f:priority': {}
'f:requiredDropCapabilities': {}
'f:allowPrivilegedContainer': {}
'f:allowHostDirVolumePlugin': {}
'f:fsGroup':
.: {}
'f:ranges': {}
'f:type': {}
'f:allowHostIPC': {}
manager: Mozilla
operation: Update
time: '2024-01-30T10:32:10Z'
name: scc-node-app
resourceVersion: '710500'
uid: cb200cda-8fca-469c-b8db-723cd48ab03e
fsGroup:
ranges:
- max: 1000720001
min: 1000720001
type: MustRunAs
groups: []
kind: SecurityContextConstraints
defaultAddCapabilities: null
supplementalGroups:
type: RunAsAny
volumes:
- awsElasticBlockStore
- azureDisk
- azureFile
- cephFS
- cinder
- configMap
- csi
- downwardAPI
- emptyDir
- ephemeral
- fc
- flexVolume
- flocker
- gcePersistentDisk
- gitRepo
- glusterfs
- iscsi
- nfs
- persistentVolumeClaim
- photonPersistentDisk
- portworxVolume
- projected
- quobyte
- rbd
- scaleIO
- secret
- storageOS
- vsphere
allowHostPID: false
allowHostNetwork: false
allowPrivilegeEscalation: false
apiVersion: security.openshift.io/v1
allowedCapabilities:
- SYS_RESOURCE