rancher-partner-charts/charts/kasten/k10/templates/grafana-scc.yaml

45 lines
910 B
YAML

{{- if .Values.scc.create }}
{{- if .Values.grafana.enabled }}
kind: SecurityContextConstraints
apiVersion: security.openshift.io/v1
metadata:
labels:
{{ include "helm.labels" . | indent 4 }}
name: {{ .Release.Name }}-grafana
allowPrivilegedContainer: false
allowHostNetwork: false
allowHostDirVolumePlugin: true
priority: null
allowedCapabilities: null
allowHostPorts: true
allowHostPID: false
allowHostIPC: false
readOnlyRootFilesystem: false
requiredDropCapabilities:
- KILL
- MKNOD
- SETUID
- SETGID
defaultAddCapabilities: []
allowedCapabilities: []
priority: 0
runAsUser:
type: RunAsAny
seLinuxContext:
type: RunAsAny
fsGroup:
type: RunAsAny
supplementalGroups:
type: RunAsAny
volumes:
- configMap
- downwardAPI
- emptyDir
- persistentVolumeClaim
- projected
- secret
users:
- system:serviceaccount:{{.Release.Namespace}}:{{.Release.Name}}-grafana
{{- end }}
{{- end }}