Explicitly declare allowPrivilegeEscalation to false
Although containers that do not run as privileged already have this set to false by kubernetes Kubespace [asks us](https://hub.armo.cloud/docs/c-0016) to explicitly declare it to false where not needed. Signed-off-by: Arthur Silva Sens <arthursens2005@gmail.com>
This commit is contained in:
committed by
GitHub
parent
f7d3019a8f
commit
b60b302499
@@ -181,6 +181,9 @@ function(params) {
|
||||
{ name: 'root', mountPath: '/host/root', mountPropagation: 'HostToContainer', readOnly: true },
|
||||
],
|
||||
resources: ne._config.resources,
|
||||
securityContext: {
|
||||
allowPrivilegeEscalation: false,
|
||||
},
|
||||
};
|
||||
|
||||
local kubeRbacProxy = krp({
|
||||
|
||||
Reference in New Issue
Block a user