feat(rabbitmq): enable pod and container security context with updated user and group IDs
Signed-off-by: zhenyus <zhenyus@mathmast.com>
This commit is contained in:
parent
8967828a20
commit
4f5c7307fd
@ -182,18 +182,18 @@ replicaCount: 3
|
|||||||
updateStrategy:
|
updateStrategy:
|
||||||
type: RollingUpdate
|
type: RollingUpdate
|
||||||
podSecurityContext:
|
podSecurityContext:
|
||||||
enabled: false
|
enabled: true
|
||||||
fsGroupChangePolicy: Always
|
fsGroupChangePolicy: Always
|
||||||
sysctls: []
|
sysctls: []
|
||||||
supplementalGroups: []
|
supplementalGroups: []
|
||||||
fsGroup: 1001
|
fsGroup: 1000
|
||||||
containerSecurityContext:
|
containerSecurityContext:
|
||||||
enabled: false
|
enabled: true
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
runAsUser: 1001
|
runAsUser: 1000
|
||||||
runAsGroup: 1001
|
runAsGroup: 1000
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
allowPrivilegeEscalation: true
|
allowPrivilegeEscalation: false
|
||||||
readOnlyRootFilesystem: true
|
readOnlyRootFilesystem: true
|
||||||
capabilities:
|
capabilities:
|
||||||
drop: ["ALL"]
|
drop: ["ALL"]
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user