Skip to content

Conversation

@bradfordcp
Copy link
Collaborator

Updates the default securityContext and podSecurityContext to more restrictive values including:

  • Read-only root filesystem (requires container support / updates)
  • Specifies non-root user and group
  • Drops all capabilities
  • Disallows privilege escalations
  • Specifies non-privileged containers

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant