@@ -393,14 +393,27 @@ provisioning:
393
393
fsGroup : 1001
394
394
# # MinIO® container Security Context
395
395
# # ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
396
- # # @param provisioning.containerSecurityContext.enabled Enable container Security Context
397
- # # @param provisioning.containerSecurityContext.runAsUser User ID for the container
398
- # # @param provisioning.containerSecurityContext.runAsNonRoot Avoid running as root User
396
+ # # @param provisioning.containerSecurityContext.enabled Enabled containers' Security Context
397
+ # # @param provisioning.containerSecurityContext.runAsUser Set containers' Security Context runAsUser
398
+ # # @param provisioning.containerSecurityContext.runAsNonRoot Set container's Security Context runAsNonRoot
399
+ # # @param provisioning.containerSecurityContext.privileged Set container's Security Context privileged
400
+ # # @param provisioning.containerSecurityContext.readOnlyRootFilesystem Set container's Security Context readOnlyRootFilesystem
401
+ # # @param provisioning.containerSecurityContext.allowPrivilegeEscalation Set container's Security Context allowPrivilegeEscalation
402
+ # # @param provisioning.containerSecurityContext.capabilities.drop List of capabilities to be dropped
403
+ # # @param provisioning.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
399
404
# #
400
405
containerSecurityContext :
401
406
enabled : true
402
407
runAsUser : 1001
403
408
runAsNonRoot : true
409
+ privileged : false
410
+ readOnlyRootFilesystem : false
411
+ allowPrivilegeEscalation : false
412
+ capabilities :
413
+ drop : ["ALL"]
414
+ seccompProfile :
415
+ type : " RuntimeDefault"
416
+
404
417
# # Automatic Cleanup for Finished Jobs
405
418
# # @param provisioning.cleanupAfterFinished.enabled Enables Cleanup for Finished Jobs
406
419
# # @param provisioning.cleanupAfterFinished.seconds Sets the value of ttlSecondsAfterFinished
@@ -429,14 +442,26 @@ podSecurityContext:
429
442
fsGroup : 1001
430
443
# # MinIO® container Security Context
431
444
# # ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
432
- # # @param containerSecurityContext.enabled Enable container Security Context
433
- # # @param containerSecurityContext.runAsUser User ID for the container
434
- # # @param containerSecurityContext.runAsNonRoot Avoid running as root User
445
+ # # @param containerSecurityContext.enabled Enabled containers' Security Context
446
+ # # @param containerSecurityContext.runAsUser Set containers' Security Context runAsUser
447
+ # # @param containerSecurityContext.runAsNonRoot Set container's Security Context runAsNonRoot
448
+ # # @param containerSecurityContext.privileged Set container's Security Context privileged
449
+ # # @param containerSecurityContext.readOnlyRootFilesystem Set container's Security Context readOnlyRootFilesystem
450
+ # # @param containerSecurityContext.allowPrivilegeEscalation Set container's Security Context allowPrivilegeEscalation
451
+ # # @param containerSecurityContext.capabilities.drop List of capabilities to be dropped
452
+ # # @param containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
435
453
# #
436
454
containerSecurityContext :
437
455
enabled : true
438
456
runAsUser : 1001
439
457
runAsNonRoot : true
458
+ privileged : false
459
+ readOnlyRootFilesystem : false
460
+ allowPrivilegeEscalation : false
461
+ capabilities :
462
+ drop : ["ALL"]
463
+ seccompProfile :
464
+ type : " RuntimeDefault"
440
465
# # @param podLabels Extra labels for MinIO® pods
441
466
# # Ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
442
467
# #
0 commit comments