fix(oxconnector): Update to strict securityContext from upstream defaults

This commit is contained in:
Thorsten Roßner
2025-02-07 08:24:30 +01:00
parent 8dcac46d98
commit 32df1657d2

View File

@@ -73,29 +73,21 @@ podAnnotations: {}
replicaCount: {{ .Values.replicas.oxConnector }} replicaCount: {{ .Values.replicas.oxConnector }}
podSecurityContext:
fsGroup: 1000
securityContext: securityContext:
privileged: false
allowPrivilegeEscalation: false allowPrivilegeEscalation: false
capabilities: capabilities:
drop: drop:
- "ALL" - "ALL"
add: readOnlyRootFilesystem: true
- "CHOWN" runAsNonRoot: true
- "DAC_OVERRIDE" runAsUser: 1000
- "FOWNER" runAsGroup: 1000
- "FSETID"
- "KILL"
- "SETGID"
- "SETUID"
- "SETPCAP"
- "NET_BIND_SERVICE"
- "SYS_CHROOT"
privileged: false
seccompProfile: seccompProfile:
type: "RuntimeDefault" type: "RuntimeDefault"
runAsUser: 0
runAsGroup: 0
runAsNonRoot: false
readOnlyRootFilesystem: false
seLinuxOptions: seLinuxOptions:
{{ .Values.seLinuxOptions.oxConnector | toYaml | nindent 4 }} {{ .Values.seLinuxOptions.oxConnector | toYaml | nindent 4 }}