securitycontextconstraints.yaml 818 B

12345678910111213141516171819202122232425262728293031323334353637383940
  1. {{- if .Values.rbac.sccEnabled }}
  2. apiVersion: security.openshift.io/v1
  3. kind: SecurityContextConstraints
  4. metadata:
  5. name: {{ include "loki.fullname" . }}
  6. labels:
  7. {{- include "loki.labels" . | nindent 4 }}
  8. allowHostDirVolumePlugin: false
  9. allowHostIPC: false
  10. allowHostNetwork: false
  11. allowHostPID: false
  12. allowHostPorts: false
  13. allowPrivilegeEscalation: true
  14. allowPrivilegedContainer: false
  15. allowedCapabilities: []
  16. defaultAddCapabilities: null
  17. fsGroup:
  18. type: RunAsAny
  19. groups: []
  20. priority: null
  21. readOnlyRootFilesystem: false
  22. requiredDropCapabilities:
  23. - ALL
  24. runAsUser:
  25. type: RunAsAny
  26. seLinuxContext:
  27. type: MustRunAs
  28. seccompProfiles:
  29. - '*'
  30. supplementalGroups:
  31. type: RunAsAny
  32. volumes:
  33. - configMap
  34. - downwardAPI
  35. - emptyDir
  36. - hostPath
  37. - persistentVolumeClaim
  38. - projected
  39. - secret
  40. {{- end }}