podsecuritypolicy.yaml 656 B

12345678910111213141516171819202122232425262728293031323334
  1. ---
  2. # Source: loki-stack/charts/promtail/templates/podsecuritypolicy.yaml
  3. apiVersion: policy/v1beta1
  4. kind: PodSecurityPolicy
  5. metadata:
  6. name: loki-promtail
  7. namespace: loki
  8. labels:
  9. app: promtail
  10. chart: promtail-0.13.1
  11. heritage: Tiller
  12. release: loki
  13. spec:
  14. privileged: false
  15. allowPrivilegeEscalation: false
  16. volumes:
  17. - 'secret'
  18. - 'configMap'
  19. - 'hostPath'
  20. hostNetwork: false
  21. hostIPC: false
  22. hostPID: false
  23. runAsUser:
  24. rule: 'RunAsAny'
  25. seLinux:
  26. rule: 'RunAsAny'
  27. supplementalGroups:
  28. rule: 'RunAsAny'
  29. fsGroup:
  30. rule: 'RunAsAny'
  31. readOnlyRootFilesystem: true
  32. requiredDropCapabilities:
  33. - ALL