Remove PodSecurityPolicies in Calico (#9395)

This commit is contained in:
Kay Yan 2022-10-17 20:51:07 +08:00 committed by GitHub
parent 72b45eec2e
commit 32f3d92d6b
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -285,35 +285,3 @@ subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: calico-apiserver name: calico-apiserver
namespace: calico-apiserver namespace: calico-apiserver
---
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
annotations:
seccomp.security.alpha.kubernetes.io/allowedProfileNames: '*'
name: calico-apiserver
spec:
allowPrivilegeEscalation: false
fsGroup:
ranges:
- max: 65535
min: 1
rule: MustRunAs
hostPorts:
- max: 65535
min: 0
requiredDropCapabilities:
- ALL
runAsUser:
rule: RunAsAny
seLinux:
rule: RunAsAny
supplementalGroups:
ranges:
- max: 65535
min: 1
rule: MustRunAs
volumes:
- secret