blob: c3a604d572698cd0339691666649643c2e718754 [file] [log] [blame]
Mohammed Naser8a2c8fb2023-02-19 17:23:55 +00001{{- if .Values.rbac.sccEnabled }}
2apiVersion: security.openshift.io/v1
3kind: SecurityContextConstraints
4metadata:
5 name: {{ include "loki.name" . }}
6 labels:
7 {{- include "loki.labels" . | nindent 4 }}
8allowHostDirVolumePlugin: false
9allowHostIPC: false
10allowHostNetwork: false
11allowHostPID: false
12allowHostPorts: false
13allowPrivilegeEscalation: true
14allowPrivilegedContainer: false
15allowedCapabilities: []
16defaultAddCapabilities: null
17fsGroup:
18 type: RunAsAny
19groups: []
20priority: null
21readOnlyRootFilesystem: false
22requiredDropCapabilities:
23 - ALL
24runAsUser:
25 type: RunAsAny
26seLinuxContext:
27 type: MustRunAs
28seccompProfiles:
29 - '*'
30supplementalGroups:
31 type: RunAsAny
32volumes:
33 - configMap
34 - downwardAPI
35 - emptyDir
36 - hostPath
37 - persistentVolumeClaim
38 - projected
39 - secret
40{{- end }}