Skip to content

Commit 3e6bc69

Browse files
committed
UPSTREAM: <carry>: (aws) Make workload pod explicity unprivileged
Signed-off-by: chiragkyal <[email protected]>
1 parent ed594b7 commit 3e6bc69

File tree

1 file changed

+16
-0
lines changed

1 file changed

+16
-0
lines changed

test/bats/tests/aws/BasicTestMount.yaml

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,29 @@ metadata:
44
name: basic-test-mount
55
spec:
66
serviceAccountName: basic-test-mount-sa
7+
securityContext:
8+
runAsNonRoot: true
9+
runAsUser: 1000
10+
runAsGroup: 3000
11+
fsGroup: 2000
12+
seccompProfile:
13+
type: RuntimeDefault
714
containers:
815
- image: registry.k8s.io/e2e-test-images/busybox:1.29-4
916
name: busybox
1017
imagePullPolicy: IfNotPresent
1118
command:
1219
- "/bin/sleep"
1320
- "10000"
21+
securityContext:
22+
allowPrivilegeEscalation: false
23+
capabilities:
24+
drop:
25+
- ALL
26+
runAsNonRoot: true
27+
runAsUser: 1000
28+
seccompProfile:
29+
type: RuntimeDefault
1430
volumeMounts:
1531
- name: secrets-store-inline
1632
mountPath: "/mnt/secrets-store"

0 commit comments

Comments
 (0)