blob: 05470d9ff6c7a78b231a7b4bf37a755d3faed7d3 [file] [log] [blame]
Mohammed Naser8a2c8fb2023-02-19 17:23:55 +00001{{- if .Values.rbac.pspEnabled }}
2apiVersion: policy/v1beta1
3kind: PodSecurityPolicy
4metadata:
5 name: {{ include "loki.name" . }}
6 labels:
7 {{- include "loki.labels" . | nindent 4 }}
Giovanni Tirloni59219b62024-04-09 14:50:25 -03008{{- if .Values.rbac.pspAnnotations }}
9 annotations:
10{{ toYaml .Values.rbac.pspAnnotations | indent 4 }}
11{{- end }}
Mohammed Naser8a2c8fb2023-02-19 17:23:55 +000012spec:
13 privileged: false
14 allowPrivilegeEscalation: false
15 volumes:
16 - 'configMap'
17 - 'emptyDir'
18 - 'persistentVolumeClaim'
19 - 'secret'
Giovanni Tirloni59219b62024-04-09 14:50:25 -030020 - 'projected'
Mohammed Naser8a2c8fb2023-02-19 17:23:55 +000021 hostNetwork: false
22 hostIPC: false
23 hostPID: false
24 runAsUser:
25 rule: 'MustRunAsNonRoot'
26 seLinux:
27 rule: 'RunAsAny'
28 supplementalGroups:
29 rule: 'MustRunAs'
30 ranges:
31 - min: 1
32 max: 65535
33 fsGroup:
34 rule: 'MustRunAs'
35 ranges:
36 - min: 1
37 max: 65535
38 readOnlyRootFilesystem: true
39 requiredDropCapabilities:
40 - ALL
41{{- end }}