apiVersion: v1 kind: Pod metadata: name: badpod01 namespace: default spec: containers: - name: container01 image: nginx:1.1.9 securityContext: allowPrivilegeEscalation: false runAsNonRoot: true seccompProfile: type: RuntimeDefault capabilities: add: - SYS_ADMIN drop: - ALL