test-podsecuritypolicy.yaml 789 B

12345678910111213141516171819202122232425262728293031323334
  1. {{- if and .Values.testFramework.enabled .Values.rbac.pspEnabled }}
  2. {{- if .Capabilities.APIVersions.Has "policy/v1beta1/PodSecurityPolicy" }}
  3. apiVersion: policy/v1beta1
  4. kind: PodSecurityPolicy
  5. metadata:
  6. name: {{ template "grafana.fullname" . }}-test
  7. annotations:
  8. "helm.sh/hook": test-success
  9. "helm.sh/hook-delete-policy": "before-hook-creation,hook-succeeded"
  10. labels:
  11. {{- include "grafana.labels" . | nindent 4 }}
  12. spec:
  13. allowPrivilegeEscalation: true
  14. privileged: false
  15. hostNetwork: false
  16. hostIPC: false
  17. hostPID: false
  18. fsGroup:
  19. rule: RunAsAny
  20. seLinux:
  21. rule: RunAsAny
  22. supplementalGroups:
  23. rule: RunAsAny
  24. runAsUser:
  25. rule: RunAsAny
  26. volumes:
  27. - configMap
  28. - downwardAPI
  29. - emptyDir
  30. - projected
  31. - csi
  32. - secret
  33. {{- end }}
  34. {{- end }}