ansible-role-k8s-weave/templates/psp.yaml.j2
2020-03-19 15:09:54 +01:00

21 lines
No EOL
348 B
Django/Jinja

apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: weave-scope
spec:
privileged: true
hostPID: true
hostNetwork: true
allowedCapabilities:
- 'NET_ADMIN'
fsGroup:
rule: RunAsAny
runAsUser:
rule: RunAsAny
seLinux:
rule: RunAsAny
supplementalGroups:
rule: RunAsAny
volumes:
- secret
- hostPath