set allowPrivilegeEscalation for deployment templates (#1328)

* set allowPrivilegeEscalation for deployment templates

* securityContext of container, not pod

* aligning

* default service account for pooler
This commit is contained in:
Felix Kunde
2021-01-25 18:23:29 +01:00
committed by GitHub
parent 5ecb7b42e0
commit ac2a00c45e
6 changed files with 27 additions and 10 deletions
+1 -1
View File
@@ -45,7 +45,7 @@ spec:
size: 1Gi
# storageClass: my-sc
# iops: 1000 # for EBS gp3
# throughput: 250 # in MB/s for EBS gp3
# throughput: 250 # in MB/s for EBS gp3
additionalVolumes:
- name: empty
mountPath: /opt/empty
+1
View File
@@ -32,6 +32,7 @@ spec:
runAsUser: 1000
runAsNonRoot: true
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
env:
# provided additional ENV vars can overwrite individual config map entries
- name: CONFIG_MAP_NAME