podsecuritypolicy.yaml 868 B

1234567891011121314151617181920212223242526272829303132333435363738394041
  1. {{- if .Values.rbac.pspEnabled }}
  2. {{- if .Capabilities.APIVersions.Has "policy/v1/PodSecurityPolicy" }}
  3. apiVersion: policy/v1
  4. kind: PodSecurityPolicy
  5. metadata:
  6. name: {{ include "tempo.fullname" . }}
  7. namespace: {{ .Release.Namespace }}
  8. labels:
  9. {{- include "tempo.labels" . | nindent 4 }}
  10. spec:
  11. privileged: false
  12. allowPrivilegeEscalation: false
  13. volumes:
  14. - 'configMap'
  15. - 'emptyDir'
  16. - 'persistentVolumeClaim'
  17. - 'secret'
  18. - 'projected'
  19. - 'downwardAPI'
  20. hostNetwork: false
  21. hostIPC: false
  22. hostPID: false
  23. runAsUser:
  24. rule: 'MustRunAsNonRoot'
  25. seLinux:
  26. rule: 'RunAsAny'
  27. supplementalGroups:
  28. rule: 'MustRunAs'
  29. ranges:
  30. - min: 1
  31. max: 65535
  32. fsGroup:
  33. rule: 'MustRunAs'
  34. ranges:
  35. - min: 1
  36. max: 65535
  37. readOnlyRootFilesystem: true
  38. requiredDropCapabilities:
  39. - ALL
  40. {{- end }}
  41. {{- end -}}