podsecuritypolicy.yaml 849 B

123456789101112131415161718192021222324252627282930313233343536
  1. {{- if .Values.rbac.pspEnabled }}
  2. {{- if .Capabilities.APIVersions.Has "policy/v1beta1/PodSecurityPolicy" }}
  3. apiVersion: policy/v1beta1
  4. kind: PodSecurityPolicy
  5. metadata:
  6. name: {{ template "fluent-bit-loki.fullname" . }}
  7. labels:
  8. app: {{ template "fluent-bit-loki.name" . }}
  9. chart: {{ template "fluent-bit-loki.chart" . }}
  10. heritage: {{ .Release.Service }}
  11. release: {{ .Release.Name }}
  12. spec:
  13. privileged: false
  14. allowPrivilegeEscalation: false
  15. volumes:
  16. - 'secret'
  17. - 'configMap'
  18. - 'hostPath'
  19. - 'projected'
  20. - 'downwardAPI'
  21. hostNetwork: false
  22. hostIPC: false
  23. hostPID: false
  24. runAsUser:
  25. rule: 'RunAsAny'
  26. seLinux:
  27. rule: 'RunAsAny'
  28. supplementalGroups:
  29. rule: 'RunAsAny'
  30. fsGroup:
  31. rule: 'RunAsAny'
  32. readOnlyRootFilesystem: true
  33. requiredDropCapabilities:
  34. - ALL
  35. {{- end }}
  36. {{- end }}