diff --git a/jsonnet/kube-prometheus/addons/podsecuritypolicies.libsonnet b/jsonnet/kube-prometheus/addons/podsecuritypolicies.libsonnet index 32ef6176ed01542c1928dcf019a203aae7bfe21d..38dc736c12353e50789aa803f910ce3668610a57 100644 --- a/jsonnet/kube-prometheus/addons/podsecuritypolicies.libsonnet +++ b/jsonnet/kube-prometheus/addons/podsecuritypolicies.libsonnet @@ -160,9 +160,20 @@ local restrictedPodSecurityPolicy = { apiGroups: ['policy'], resources: ['podsecuritypolicies'], verbs: ['use'], - resourceNames: [restrictedPodSecurityPolicy.metadata.name], + resourceNames: ['kube-state-metrics-psp'], }], }, + + podSecurityPolicy: restrictedPodSecurityPolicy { + metadata+: { + name: 'kube-state-metrics-psp', + }, + spec+: { + runAsUser: { + rule: 'RunAsAny', + }, + }, + }, }, nodeExporter+: {