Browse Source

Remove PodSecurityPolicies in Calico (#9395)

pull/9430/head
Kay Yan 2 years ago
committed by GitHub
parent
commit
32f3d92d6b
No known key found for this signature in database GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 0 additions and 32 deletions
  1. 32
      roles/network_plugin/calico/templates/calico-apiserver.yml.j2

32
roles/network_plugin/calico/templates/calico-apiserver.yml.j2

@ -285,35 +285,3 @@ subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: calico-apiserver name: calico-apiserver
namespace: calico-apiserver namespace: calico-apiserver
---
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
annotations:
seccomp.security.alpha.kubernetes.io/allowedProfileNames: '*'
name: calico-apiserver
spec:
allowPrivilegeEscalation: false
fsGroup:
ranges:
- max: 65535
min: 1
rule: MustRunAs
hostPorts:
- max: 65535
min: 0
requiredDropCapabilities:
- ALL
runAsUser:
rule: RunAsAny
seLinux:
rule: RunAsAny
supplementalGroups:
ranges:
- max: 65535
min: 1
rule: MustRunAs
volumes:
- secret
Loading…
Cancel
Save