apiVersion: extensions/v1beta1 kind: PodSecurityPolicy metadata: name: weave-scope spec: privileged: true hostPID: true hostNetwork: true allowedCapabilities: - 'NET_ADMIN' fsGroup: rule: RunAsAny runAsUser: rule: RunAsAny seLinux: rule: RunAsAny supplementalGroups: rule: RunAsAny volumes: - secret - hostPath