apiVersion: v1 kind: Pod metadata: name: bad-pod-2 namespace: staging-ns spec: containers: - name: busybox1 image: busybox args: - sleep - 1d securityContext: seccompProfile: type: RuntimeDefault runAsNonRoot: true allowPrivilegeEscalation: false capabilities: drop: - ALL add: - foo initContainers: - name: busybox2 image: busybox args: - sleep - 1d securityContext: seccompProfile: type: RuntimeDefault runAsNonRoot: true allowPrivilegeEscalation: false capabilities: drop: - ALL add: - baz