Set securityContext.capabilities for kube-rbac-proxy container (#1354)

This commit is contained in:
Christian Adams
2023-04-12 14:55:57 -04:00
committed by GitHub
parent faf51c8b24
commit 5a3b2179bc
2 changed files with 3 additions and 5 deletions

View File

@@ -12,10 +12,9 @@ spec:
- name: kube-rbac-proxy
securityContext:
allowPrivilegeEscalation: false
# TODO(user): uncomment for common cases that do not require escalating privileges
# capabilities:
# drop:
# - "ALL"
capabilities:
drop:
- "ALL"
image: gcr.io/kubebuilder/kube-rbac-proxy:v0.13.0
args:
- "--secure-listen-address=0.0.0.0:8443"

View File

@@ -51,7 +51,6 @@ spec:
fieldPath: metadata.namespace
securityContext:
allowPrivilegeEscalation: false
# TODO(user): uncomment for common cases that do not require escalating privileges
capabilities:
drop:
- "ALL"