persistent-volume-binder.yaml 878 B

12345678910111213141516171819202122232425262728293031
  1. apiVersion: policy/v1beta1
  2. kind: PodSecurityPolicy
  3. metadata:
  4. name: gce.persistent-volume-binder
  5. annotations:
  6. kubernetes.io/description: 'Policy used by the persistent-volume-binder
  7. (a.k.a. persistentvolume-controller) to run recycler pods.'
  8. seccomp.security.alpha.kubernetes.io/defaultProfileName: 'docker/default'
  9. seccomp.security.alpha.kubernetes.io/allowedProfileNames: 'runtime/default,docker/default'
  10. labels:
  11. kubernetes.io/cluster-service: 'true'
  12. addonmanager.kubernetes.io/mode: Reconcile
  13. spec:
  14. privileged: false
  15. volumes:
  16. - 'nfs'
  17. - 'secret' # Required for service account credentials.
  18. - 'projected'
  19. hostNetwork: false
  20. hostIPC: false
  21. hostPID: false
  22. runAsUser:
  23. rule: 'RunAsAny'
  24. seLinux:
  25. rule: 'RunAsAny'
  26. supplementalGroups:
  27. rule: 'RunAsAny'
  28. fsGroup:
  29. rule: 'RunAsAny'
  30. readOnlyRootFilesystem: false