30 lines
725 B
YAML
30 lines
725 B
YAML
|
{{- if eq .Values.os "openshift4"}}
|
||
|
kind: SecurityContextConstraints
|
||
|
apiVersion: security.openshift.io/v1
|
||
|
metadata:
|
||
|
name: ntnx-csi-scc
|
||
|
allowHostDirVolumePlugin: true
|
||
|
allowHostIPC: false
|
||
|
allowHostNetwork: true
|
||
|
allowHostPID: false
|
||
|
allowHostPorts: true
|
||
|
allowPrivilegeEscalation: true
|
||
|
allowPrivilegedContainer: true
|
||
|
allowedCapabilities: []
|
||
|
defaultAddCapabilities: []
|
||
|
fsGroup:
|
||
|
type: RunAsAny
|
||
|
groups: []
|
||
|
priority:
|
||
|
readOnlyRootFilesystem: false
|
||
|
requiredDropCapabilities: []
|
||
|
runAsUser:
|
||
|
type: RunAsAny
|
||
|
seLinuxContext:
|
||
|
type: RunAsAny
|
||
|
supplementalGroups:
|
||
|
type: RunAsAny
|
||
|
users:
|
||
|
- system:serviceaccount:{{ .Release.Namespace }}:csi-provisioner
|
||
|
- system:serviceaccount:{{ .Release.Namespace }}:csi-node-ntnx-plugin
|
||
|
{{- end}}
|