miq-scc-httpd.yaml 867 B

1234567891011121314151617181920212223242526272829303132333435363738
  1. allowHostDirVolumePlugin: false
  2. allowHostIPC: false
  3. allowHostNetwork: false
  4. allowHostPID: false
  5. allowHostPorts: false
  6. allowPrivilegedContainer: false
  7. allowedCapabilities:
  8. apiVersion: v1
  9. defaultAddCapabilities:
  10. - SYS_ADMIN
  11. fsGroup:
  12. type: RunAsAny
  13. groups:
  14. - system:cluster-admins
  15. kind: SecurityContextConstraints
  16. metadata:
  17. annotations:
  18. kubernetes.io/description: miq-httpd provides all features of the anyuid SCC but allows users to have SYS_ADMIN capabilities. This is the required scc for Pods requiring to run with systemd and the message bus.
  19. creationTimestamp:
  20. name: miq-httpd
  21. priority: 10
  22. readOnlyRootFilesystem: false
  23. requiredDropCapabilities:
  24. - MKNOD
  25. - SYS_CHROOT
  26. runAsUser:
  27. type: RunAsAny
  28. seLinuxContext:
  29. type: MustRunAs
  30. supplementalGroups:
  31. type: RunAsAny
  32. users:
  33. volumes:
  34. - configMap
  35. - downwardAPI
  36. - emptyDir
  37. - persistentVolumeClaim
  38. - secret