diff --git a/resources/scc.yaml b/resources/scc.yaml index b95b83a3..717846cc 100644 --- a/resources/scc.yaml +++ b/resources/scc.yaml @@ -3,7 +3,7 @@ kind: SecurityContextConstraints apiVersion: security.openshift.io/v1 metadata: name: nginx-ingress-admin -allowPrivilegedContainer: true +allowPrivilegedContainer: false runAsUser: type: MustRunAs uid: 101 @@ -19,10 +19,10 @@ allowHostPorts: false allowHostDirVolumePlugin: false allowHostIPC: false readOnlyRootFilesystem: false +seccompProfiles: +- runtime/default volumes: - secret -defaultAddCapabilities: - - "NET_BIND_SERVICE" requiredDropCapabilities: - ALL users: