mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-06 07:57:07 +00:00
38 lines
665 B
YAML
38 lines
665 B
YAML
apiVersion: v1
|
|
kind: Pod
|
|
metadata:
|
|
name: bad-pod-1
|
|
namespace: staging-ns
|
|
spec:
|
|
containers:
|
|
- name: nginx1
|
|
image: nginx
|
|
args:
|
|
- sleep
|
|
- 1d
|
|
securityContext:
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
runAsNonRoot: true
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
add:
|
|
- baz
|
|
initContainers:
|
|
- name: nginx2
|
|
image: nginx
|
|
args:
|
|
- sleep
|
|
- 1d
|
|
securityContext:
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
runAsNonRoot: true
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
add:
|
|
- foo
|