ansible-role-k8s-weave/templates/psp.yaml.j2
2019-10-01 13:47:02 +02:00

21 lines
No EOL
352 B
Django/Jinja

apiVersion: extensions/v1beta1
kind: PodSecurityPolicy
metadata:
name: weave-scope
spec:
privileged: true
hostPID: true
hostNetwork: true
allowedCapabilities:
- 'NET_ADMIN'
fsGroup:
rule: RunAsAny
runAsUser:
rule: RunAsAny
seLinux:
rule: RunAsAny
supplementalGroups:
rule: RunAsAny
volumes:
- secret
- hostPath