mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-06 16:06:56 +00:00
37 lines
651 B
YAML
37 lines
651 B
YAML
|
apiVersion: v1
|
||
|
kind: Pod
|
||
|
metadata:
|
||
|
name: good-pod-2
|
||
|
namespace: staging-ns
|
||
|
spec:
|
||
|
containers:
|
||
|
- name: nginx1
|
||
|
image: nginx
|
||
|
args:
|
||
|
- sleep
|
||
|
- 1d
|
||
|
securityContext:
|
||
|
seccompProfile:
|
||
|
type: RuntimeDefault
|
||
|
runAsNonRoot: true
|
||
|
runAsUser: 0
|
||
|
allowPrivilegeEscalation: false
|
||
|
capabilities:
|
||
|
drop:
|
||
|
- ALL
|
||
|
initContainers:
|
||
|
- name: nginx2
|
||
|
image: nginx
|
||
|
args:
|
||
|
- sleep
|
||
|
- 1d
|
||
|
securityContext:
|
||
|
seccompProfile:
|
||
|
type: RuntimeDefault
|
||
|
runAsNonRoot: true
|
||
|
runAsUser: 10
|
||
|
allowPrivilegeEscalation: false
|
||
|
capabilities:
|
||
|
drop:
|
||
|
- ALL
|