MOB-148: rollback to enforcing resticted level + fixing PodSec problems

qa
friedrich goerz 4 years ago
parent a2a4fb98bc
commit 7f07bf2c9e

@ -14,10 +14,8 @@ spec:
app: keycloak app: keycloak
spec: spec:
securityContext: securityContext:
allowPrivilegeEscalation: false runAsUser: 2000
runAsNonRoot: true runAsNonRoot: true
capabilities:
drop: ["ALL"]
seccompProfile: seccompProfile:
type: RuntimeDefault type: RuntimeDefault
containers: containers:
@ -25,7 +23,9 @@ spec:
image: staged-harbor-01.smardigo.digital/smardigo/keycloak:14.0.0.1 image: staged-harbor-01.smardigo.digital/smardigo/keycloak:14.0.0.1
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
securityContext: securityContext:
runAsUser: 2000 allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
ports: ports:
- name: app-port - name: app-port
containerPort: 8080 containerPort: 8080

@ -3,9 +3,7 @@ kind: Namespace
metadata: metadata:
labels: labels:
kubernetes.io/metadata.name: sma-ums kubernetes.io/metadata.name: sma-ums
pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/enforce: restricted
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/warn: restricted
name: sma-ums name: sma-ums
spec: spec:
finalizers: finalizers:

Loading…
Cancel
Save