Skip to content

Commit feee614

Browse files
authored
FE-896 | disable privilege escalation for integration sidecar (#1993)
1 parent b690631 commit feee614

File tree

1 file changed

+5
-4
lines changed

1 file changed

+5
-4
lines changed

pkg/util/k8sutil/pods.go

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -783,10 +783,11 @@ func CreateDefaultContainerTemplate(image *schedulerContainerResourcesApi.Image)
783783
},
784784
Security: &schedulerContainerResourcesApi.Security{
785785
SecurityContext: &core.SecurityContext{
786-
RunAsUser: util.NewType[int64](shared.DefaultRunAsUser),
787-
RunAsGroup: util.NewType[int64](shared.DefaultRunAsGroup),
788-
RunAsNonRoot: util.NewType(true),
789-
ReadOnlyRootFilesystem: util.NewType(true),
786+
RunAsUser: util.NewType[int64](shared.DefaultRunAsUser),
787+
RunAsGroup: util.NewType[int64](shared.DefaultRunAsGroup),
788+
RunAsNonRoot: util.NewType(true),
789+
ReadOnlyRootFilesystem: util.NewType(true),
790+
AllowPrivilegeEscalation: util.NewType(false),
790791
Capabilities: &core.Capabilities{
791792
Drop: []core.Capability{
792793
"ALL",

0 commit comments

Comments
 (0)