diff --git a/pkg/util/k8sutil/pods.go b/pkg/util/k8sutil/pods.go index 8a26af860..33c2c22f3 100644 --- a/pkg/util/k8sutil/pods.go +++ b/pkg/util/k8sutil/pods.go @@ -783,10 +783,11 @@ func CreateDefaultContainerTemplate(image *schedulerContainerResourcesApi.Image) }, Security: &schedulerContainerResourcesApi.Security{ SecurityContext: &core.SecurityContext{ - RunAsUser: util.NewType[int64](shared.DefaultRunAsUser), - RunAsGroup: util.NewType[int64](shared.DefaultRunAsGroup), - RunAsNonRoot: util.NewType(true), - ReadOnlyRootFilesystem: util.NewType(true), + RunAsUser: util.NewType[int64](shared.DefaultRunAsUser), + RunAsGroup: util.NewType[int64](shared.DefaultRunAsGroup), + RunAsNonRoot: util.NewType(true), + ReadOnlyRootFilesystem: util.NewType(true), + AllowPrivilegeEscalation: util.NewType(false), Capabilities: &core.Capabilities{ Drop: []core.Capability{ "ALL",