rancher-partner-charts/charts/instana/instana-agent/templates/k8s-sensor-podsecuritypolic...

28 lines
568 B
YAML

{{- if and .Values.k8s_sensor.deployment.enabled .Values.podSecurityPolicy.enable -}}
---
kind: PodSecurityPolicy
apiVersion: policy/v1beta1
metadata:
name: k8sensor
namespace: {{ .Release.Namespace }}
labels:
{{- include "instana-agent.commonLabels" . | nindent 4 }}
spec:
volumes:
- configMap
- downwardAPI
- emptyDir
- persistentVolumeClaim
- secret
- projected
- hostPath
runAsUser:
rule: "RunAsAny"
seLinux:
rule: "RunAsAny"
supplementalGroups:
rule: "RunAsAny"
fsGroup:
rule: "RunAsAny"
{{- end }}