Add runAsNonRoot: true and allowPrivilegeEscalation: false to the specs

Signed-off-by: Volodymyr Zotov <volodymyr.zotov@gmail.com>
This commit is contained in:
Volodymyr Zotov
2023-02-28 15:59:17 -06:00
parent ea8773bfee
commit 702974f750
3 changed files with 10 additions and 0 deletions

View File

@@ -12,6 +12,8 @@ spec:
app: onepassword-connect
version: "1.0.0"
spec:
securityContext:
runAsNonRoot: true
volumes:
- name: shared-data
emptyDir: {}
@@ -32,6 +34,8 @@ spec:
containers:
- name: connect-api
image: 1password/connect-api:latest
securityContext:
allowPrivilegeEscalation: false
resources:
limits:
memory: "128Mi"
@@ -49,6 +53,8 @@ spec:
name: shared-data
- name: connect-sync
image: 1password/connect-sync:latest
securityContext:
allowPrivilegeEscalation: false
resources:
limits:
memory: "128Mi"

View File

@@ -8,6 +8,8 @@ metadata:
spec:
template:
spec:
securityContext:
runAsNonRoot: true
containers:
- name: kube-rbac-proxy
securityContext:

View File

@@ -6,6 +6,8 @@ metadata:
spec:
template:
spec:
securityContext:
runAsNonRoot: true
containers:
- name: manager
args: