diff --git a/roles/kubernetes-apps/registry/templates/registry-proxy-psp.yml.j2 b/roles/kubernetes-apps/registry/templates/registry-proxy-psp.yml.j2 index e73711a95..c7375336a 100644 --- a/roles/kubernetes-apps/registry/templates/registry-proxy-psp.yml.j2 +++ b/roles/kubernetes-apps/registry/templates/registry-proxy-psp.yml.j2 @@ -17,7 +17,16 @@ spec: privileged: false allowPrivilegeEscalation: false requiredDropCapabilities: - - ALL + - SETPCAP + - MKNOD + - AUDIT_WRITE + - NET_RAW + - DAC_OVERRIDE + - FOWNER + - FSETID + - KILL + - SYS_CHROOT + - SETFCAP volumes: - 'configMap' - 'emptyDir'