Skip to content

Commit 5d39cfe

Browse files
committed
Rewrite PodSecurityPolicy guide
1 parent a99a42f commit 5d39cfe

File tree

5 files changed

+538
-206
lines changed

5 files changed

+538
-206
lines changed
Lines changed: 3 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
apiVersion: extensions/v1beta1
22
kind: PodSecurityPolicy
33
metadata:
4-
name: permissive
4+
name: example
55
spec:
6+
privileged: false # Don't allow privileged pods!
7+
# The rest fills in some required fields.
68
seLinux:
79
rule: RunAsAny
810
supplementalGroups:
@@ -11,10 +13,5 @@ spec:
1113
rule: RunAsAny
1214
fsGroup:
1315
rule: RunAsAny
14-
hostPorts:
15-
- min: 8000
16-
max: 8080
1716
volumes:
1817
- '*'
19-
allowedCapabilities:
20-
- '*'

0 commit comments

Comments
 (0)