@ -70,7 +70,7 @@ spec:
allowPrivilegeEscalation: false
capabilities:
drop: ["all"]
add: ["CAP_NET_BIND_SERVICE"]
add: ["NET_BIND_SERVICE"]
readOnlyRootFilesystem: true
runAsGroup: 10001
runAsNonRoot: true