podsecuritypolicy.yaml 1.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354
  1. ---
  2. # Source: loki-stack/charts/grafana/templates/podsecuritypolicy.yaml
  3. apiVersion: policy/v1beta1
  4. kind: PodSecurityPolicy
  5. metadata:
  6. name: loki-grafana
  7. namespace: loki
  8. labels:
  9. app: grafana
  10. chart: grafana-3.8.19
  11. heritage: Tiller
  12. release: loki
  13. annotations:
  14. seccomp.security.alpha.kubernetes.io/allowedProfileNames: 'docker/default'
  15. seccomp.security.alpha.kubernetes.io/defaultProfileName: 'docker/default'
  16. apparmor.security.beta.kubernetes.io/allowedProfileNames: 'runtime/default'
  17. apparmor.security.beta.kubernetes.io/defaultProfileName: 'runtime/default'
  18. spec:
  19. privileged: false
  20. allowPrivilegeEscalation: false
  21. requiredDropCapabilities:
  22. # Default set from Docker, without DAC_OVERRIDE or CHOWN
  23. - FOWNER
  24. - FSETID
  25. - KILL
  26. - SETGID
  27. - SETUID
  28. - SETPCAP
  29. - NET_BIND_SERVICE
  30. - NET_RAW
  31. - SYS_CHROOT
  32. - MKNOD
  33. - AUDIT_WRITE
  34. - SETFCAP
  35. volumes:
  36. - 'configMap'
  37. - 'emptyDir'
  38. - 'projected'
  39. - 'secret'
  40. - 'downwardAPI'
  41. - 'persistentVolumeClaim'
  42. hostNetwork: false
  43. hostIPC: false
  44. hostPID: false
  45. runAsUser:
  46. rule: 'RunAsAny'
  47. seLinux:
  48. rule: 'RunAsAny'
  49. supplementalGroups:
  50. rule: 'RunAsAny'
  51. fsGroup:
  52. rule: 'RunAsAny'
  53. readOnlyRootFilesystem: false