[bitnami/fluent-bit] feat: Add support for PSA restricted policy (#20438)

Signed-off-by: Javier Salmeron Garcia <jsalmeron@vmware.com>
This commit is contained in:
Javier J. Salmerón-García
2023-10-31 16:13:07 +01:00
committed by GitHub
parent c91aebb2d0
commit 477f4ae3db
3 changed files with 103 additions and 86 deletions

View File

@@ -324,13 +324,25 @@ podSecurityContext:
## Configure Container Security Context (only main container)
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
## @param containerSecurityContext.enabled Enabled Fluent Bit containers' Security Context
## @param containerSecurityContext.runAsUser Set Fluent Bit container's Security Context runAsUser
## @param containerSecurityContext.runAsNonRoot Force the container to be run as non root
## @param containerSecurityContext.runAsUser Set Fluent Bit containers' Security Context runAsUser
## @param containerSecurityContext.runAsNonRoot Set Fluent Bit container's Security Context runAsNonRoot
## @param containerSecurityContext.readOnlyRootFilesystem Set Fluent Bit container's Security Context runAsNonRoot
## @param containerSecurityContext.privileged Set primary container's Security Context privileged
## @param containerSecurityContext.allowPrivilegeEscalation Set primary container's Security Context allowPrivilegeEscalation
## @param containerSecurityContext.capabilities.drop List of capabilities to be dropped
## @param containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
##
containerSecurityContext:
enabled: true
runAsUser: 1001
runAsNonRoot: true
privileged: false
allowPrivilegeEscalation: false
readOnlyRootFilesystem: false
capabilities:
drop: ["ALL"]
seccompProfile:
type: "RuntimeDefault"
## @param podAnnotations Additional pod annotations
## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/
##