diff --git a/infrastructure/dashboard/kubernetes-dashboard.yaml b/infrastructure/dashboard/kubernetes-dashboard.yaml index 15bee85ab1c1e3e9bd9b371af3296ee8f2524397..d5c1a77b8d0c00926a2aae5b94aeb90217404292 100644 --- a/infrastructure/dashboard/kubernetes-dashboard.yaml +++ b/infrastructure/dashboard/kubernetes-dashboard.yaml @@ -262,6 +262,7 @@ spec: app.kubernetes.io/version: "v1.0.0" spec: securityContext: + runAsNonRoot: true seccompProfile: type: RuntimeDefault containers: @@ -284,6 +285,9 @@ spec: readOnlyRootFilesystem: true runAsUser: 1001 runAsGroup: 2001 + capabilities: + drop: + - ALL volumes: - name: tmp-volume emptyDir: {} @@ -316,6 +320,7 @@ spec: app.kubernetes.io/version: "v1.0.0" spec: securityContext: + runAsNonRoot: true seccompProfile: type: RuntimeDefault containers: @@ -335,6 +340,9 @@ spec: readOnlyRootFilesystem: true runAsUser: 1001 runAsGroup: 2001 + capabilities: + drop: + - ALL volumes: - name: tmp-volume emptyDir: {} @@ -367,6 +375,7 @@ spec: app.kubernetes.io/version: "v1.0.9" spec: securityContext: + runAsNonRoot: true seccompProfile: type: RuntimeDefault containers: @@ -391,6 +400,9 @@ spec: readOnlyRootFilesystem: true runAsUser: 1001 runAsGroup: 2001 + capabilities: + drop: + - ALL volumes: - name: tmp-volume emptyDir: {}