rancher-partner-charts/charts/kasten/k10/6.0.601/templates/k10-scc.yaml

45 lines
904 B
YAML

{{- if .Values.scc.create }}
kind: SecurityContextConstraints
apiVersion: security.openshift.io/v1
metadata:
name: {{ .Release.Name }}-scc
labels:
{{ include "helm.labels" . | indent 4 }}
allowHostDirVolumePlugin: false
allowHostIPC: false
allowHostNetwork: false
allowHostPID: false
allowHostPorts: false
allowPrivilegeEscalation: false
allowPrivilegedContainer: false
allowedCapabilities:
- CHOWN
- FOWNER
- DAC_OVERRIDE
defaultAddCapabilities: null
fsGroup:
type: RunAsAny
priority: 0
readOnlyRootFilesystem: false
requiredDropCapabilities:
- KILL
- MKNOD
- SETUID
- SETGID
runAsUser:
type: RunAsAny
seLinuxContext:
type: RunAsAny
supplementalGroups:
type: RunAsAny
users:
- system:serviceaccount:{{.Release.Namespace}}:{{ template "serviceAccountName" . }}
volumes:
- configMap
- downwardAPI
- emptyDir
- persistentVolumeClaim
- projected
- secret
{{- end }}