{{- if .Values.scc.create }} kind: SecurityContextConstraints apiVersion: security.openshift.io/v1 metadata: name: {{ .Release.Name }}-scc labels: {{ include "helm.labels" . | indent 4 }} allowHostDirVolumePlugin: false allowHostIPC: false allowHostNetwork: false allowHostPID: false allowHostPorts: false allowPrivilegeEscalation: false allowPrivilegedContainer: false allowedCapabilities: - CHOWN - FOWNER - DAC_OVERRIDE defaultAddCapabilities: null fsGroup: type: RunAsAny priority: 0 readOnlyRootFilesystem: false requiredDropCapabilities: - KILL - MKNOD - SETUID - SETGID runAsUser: type: RunAsAny seLinuxContext: type: RunAsAny supplementalGroups: type: RunAsAny users: - system:serviceaccount:{{.Release.Namespace}}:{{ template "serviceAccountName" . }} volumes: - configMap - downwardAPI - emptyDir - persistentVolumeClaim - projected - secret {{- end }}