| {{- if .Values.global.podSecurityPolicy.enabled }} |
| apiVersion: policy/v1beta1 |
| name: {{ template "cert-manager.fullname" . }} |
| app: {{ include "cert-manager.name" . }} |
| app.kubernetes.io/name: {{ include "cert-manager.name" . }} |
| app.kubernetes.io/instance: {{ .Release.Name }} |
| app.kubernetes.io/component: "controller" |
| {{- include "labels" . | nindent 4 }} |
| seccomp.security.alpha.kubernetes.io/allowedProfileNames: 'docker/default' |
| seccomp.security.alpha.kubernetes.io/defaultProfileName: 'docker/default' |
| {{- if .Values.global.podSecurityPolicy.useAppArmor }} |
| apparmor.security.beta.kubernetes.io/allowedProfileNames: 'runtime/default' |
| apparmor.security.beta.kubernetes.io/defaultProfileName: 'runtime/default' |
| allowPrivilegeEscalation: false |
| allowedCapabilities: [] # default set of capabilities are implicitly allowed |