test-podsecuritypolicy.yaml 625 B

1234567891011121314151617181920212223242526272829
  1. {{- if and .Values.testFramework.enabled .Values.rbac.pspEnabled }}
  2. apiVersion: policy/v1beta1
  3. kind: PodSecurityPolicy
  4. metadata:
  5. name: {{ template "grafana.fullname" . }}-test
  6. namespace: {{ template "grafana.namespace" . }}
  7. labels:
  8. {{- include "grafana.labels" . | nindent 4 }}
  9. spec:
  10. allowPrivilegeEscalation: true
  11. privileged: false
  12. hostNetwork: false
  13. hostIPC: false
  14. hostPID: false
  15. fsGroup:
  16. rule: RunAsAny
  17. seLinux:
  18. rule: RunAsAny
  19. supplementalGroups:
  20. rule: RunAsAny
  21. runAsUser:
  22. rule: RunAsAny
  23. volumes:
  24. - configMap
  25. - downwardAPI
  26. - emptyDir
  27. - projected
  28. - secret
  29. {{- end }}