podsecuritypolicy.yaml 807 B

1234567891011121314151617181920212223242526272829303132333435363738
  1. {{- if .Values.rbac.pspEnabled }}
  2. {{- if .Capabilities.APIVersions.Has "policy/v1beta1/PodSecurityPolicy" }}
  3. apiVersion: policy/v1beta1
  4. kind: PodSecurityPolicy
  5. metadata:
  6. name: {{ include "loki.fullname" . }}
  7. labels:
  8. {{- include "loki.labels" . | nindent 4 }}
  9. spec:
  10. privileged: false
  11. allowPrivilegeEscalation: false
  12. volumes:
  13. - 'configMap'
  14. - 'emptyDir'
  15. - 'persistentVolumeClaim'
  16. - 'secret'
  17. hostNetwork: false
  18. hostIPC: false
  19. hostPID: false
  20. runAsUser:
  21. rule: 'MustRunAsNonRoot'
  22. seLinux:
  23. rule: 'RunAsAny'
  24. supplementalGroups:
  25. rule: 'MustRunAs'
  26. ranges:
  27. - min: 1
  28. max: 65535
  29. fsGroup:
  30. rule: 'MustRunAs'
  31. ranges:
  32. - min: 1
  33. max: 65535
  34. readOnlyRootFilesystem: true
  35. requiredDropCapabilities:
  36. - ALL
  37. {{- end }}
  38. {{- end }}