etcd-scc.yml.j2 861 B

123456789101112131415161718192021222324252627282930313233343536373839404142
  1. allowHostDirVolumePlugin: true
  2. allowHostIPC: false
  3. allowHostNetwork: true
  4. allowHostPID: false
  5. allowHostPorts: false
  6. allowPrivilegedContainer: false
  7. allowedCapabilities: []
  8. allowedFlexVolumes: []
  9. apiVersion: v1
  10. defaultAddCapabilities: []
  11. fsGroup:
  12. ranges:
  13. - max: "{{ contiv_etcd_system_gid }}"
  14. min: "{{ contiv_etcd_system_gid }}"
  15. type: MustRunAs
  16. groups: []
  17. kind: SecurityContextConstraints
  18. metadata:
  19. annotations:
  20. kubernetes.io/description: 'For contiv-etcd only.'
  21. creationTimestamp: null
  22. name: contiv-etcd
  23. priority: null
  24. readOnlyRootFilesystem: true
  25. requiredDropCapabilities:
  26. - KILL
  27. - MKNOD
  28. - SETUID
  29. - SETGID
  30. runAsUser:
  31. type: MustRunAs
  32. uid: "{{ contiv_etcd_system_uid }}"
  33. seLinuxContext:
  34. type: MustRunAs
  35. supplementalGroups:
  36. type: MustRunAs
  37. users:
  38. - system:serviceaccount:kube-system:contiv-etcd
  39. volumes:
  40. - emptyDir
  41. - hostPath
  42. - secret