@@ -94,11 +94,19 @@ controller:
9494 # -- Affinity rules for controller pods
9595 affinity : {}
9696
97- # -- Security context for controller pods
97+ # -- Security context for controller pods
9898 podSecurityContext : {}
99-
99+
100100 # -- Security context for controller containers
101- securityContext : {}
101+ securityContext :
102+ runAsNonRoot : true
103+ allowPrivilegeEscalation : false
104+ runAsUser : 1000
105+ seccompProfile :
106+ type : RuntimeDefault
107+ capabilities :
108+ drop :
109+ - ALL
102110
103111 # -- Extra labels for controller pods
104112 labels : {}
@@ -222,9 +230,20 @@ database:
222230 failureThreshold : 60
223231
224232 # Security context
225- podSecurityContext : {}
233+ podSecurityContext :
234+ fsGroup : 999
235+ fsGroupChangePolicy : OnRootMismatch
226236
227- securityContext : {}
237+ securityContext :
238+ allowPrivilegeEscalation : false
239+ seccompProfile :
240+ type : RuntimeDefault
241+ runAsNonRoot : true
242+ runAsUser : 999
243+ runAsGroup : 999
244+ capabilities :
245+ drop :
246+ - ALL
228247
229248 # Volume configuration
230249 volumes :
@@ -453,11 +472,19 @@ dbManager:
453472 # -- Affinity rules for DB Manager pods
454473 affinity : {}
455474
456- # -- Security context for DB Manager pods
475+ # -- Security context for DB Manager pods
457476 podSecurityContext : {}
458-
477+
459478 # -- Security context for DB Manager containers
460- securityContext : {}
479+ securityContext :
480+ runAsNonRoot : true
481+ allowPrivilegeEscalation : false
482+ runAsUser : 1000
483+ seccompProfile :
484+ type : RuntimeDefault
485+ capabilities :
486+ drop :
487+ - ALL
461488
462489 # -- Extra labels for DB Manager pods
463490 labels : {}
@@ -509,11 +536,19 @@ ui:
509536 # -- Affinity rules for UI pods
510537 affinity : {}
511538
512- # -- Security context for UI pods
513- podSecurityContext : {}
514-
539+ # -- Security context for UI pods
540+ podSecurityContext :
541+ seccompProfile :
542+ type : RuntimeDefault
543+
515544 # -- Security context for UI containers
516- securityContext : {}
545+ securityContext :
546+ runAsNonRoot : true
547+ allowPrivilegeEscalation : false
548+ runAsUser : 1000
549+ capabilities :
550+ drop :
551+ - ALL
517552
518553 # -- Extra labels for UI pods
519554 labels : {}
0 commit comments