mirror of
https://github.com/kyverno/kyverno.git
synced 2024-12-15 17:51:20 +00:00
37 lines
649 B
YAML
37 lines
649 B
YAML
|
apiVersion: v1
|
||
|
kind: Pod
|
||
|
metadata:
|
||
|
name: good-pod-1
|
||
|
namespace: default
|
||
|
spec:
|
||
|
containers:
|
||
|
- name: nginx1
|
||
|
image: nginx
|
||
|
args:
|
||
|
- sleep
|
||
|
- 1d
|
||
|
securityContext:
|
||
|
seccompProfile:
|
||
|
type: RuntimeDefault
|
||
|
runAsNonRoot: true
|
||
|
allowPrivilegeEscalation: false
|
||
|
capabilities:
|
||
|
drop:
|
||
|
- ALL
|
||
|
add:
|
||
|
- NET_BIND_SERVICE
|
||
|
initContainers:
|
||
|
- name: nginx2
|
||
|
image: nginx
|
||
|
args:
|
||
|
- sleep
|
||
|
- 1d
|
||
|
securityContext:
|
||
|
seccompProfile:
|
||
|
type: RuntimeDefault
|
||
|
runAsNonRoot: true
|
||
|
allowPrivilegeEscalation: false
|
||
|
capabilities:
|
||
|
drop:
|
||
|
- ALL
|