Skip to content

helm: default to pss-baseline #489

@jcpunk

Description

@jcpunk

As I understand it the container needs to run as root, so restricted isn't possible.

Having the helm chart default to https://kubernetes.io/docs/concepts/security/pod-security-standards/#baseline would provide some level of assurance that default hardening is occurring.

I'd love to see things that are workable from restricted (such as readOnlyRootFilesystem) set by default as well.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions