{{- if and .Values.k8s_sensor.deployment.enabled .Values.podSecurityPolicy.enable -}} --- kind: PodSecurityPolicy apiVersion: policy/v1beta1 metadata: name: k8sensor namespace: {{ .Release.Namespace }} labels: {{- include "instana-agent.commonLabels" . | nindent 4 }} spec: volumes: - configMap - downwardAPI - emptyDir - persistentVolumeClaim - secret - projected - hostPath runAsUser: rule: "RunAsAny" seLinux: rule: "RunAsAny" supplementalGroups: rule: "RunAsAny" fsGroup: rule: "RunAsAny" {{- end }}