ansible-role-k8s-weave/templates/scope/psp.yaml.j2
2020-04-21 12:02:56 +02:00

21 lines
No EOL
348 B
Django/Jinja

apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: weave-scope
spec:
privileged: true
hostPID: true
hostNetwork: true
allowedCapabilities:
- 'NET_ADMIN'
fsGroup:
rule: RunAsAny
runAsUser:
rule: RunAsAny
seLinux:
rule: RunAsAny
supplementalGroups:
rule: RunAsAny
volumes:
- secret
- hostPath