- Sort Score
- Result 10 results
- Languages All
Results 11 - 20 of 313 for AllowPrivilegeEscalation (0.22 sec)
-
pkg/kube/inject/testdata/inject/hello-multi.yaml.injected
resources: limits: cpu: "2" memory: 1Gi requests: cpu: 100m memory: 128Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL privileged: false readOnlyRootFilesystem: true runAsGroup: 1337 runAsNonRoot: true
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue Feb 27 16:55:16 UTC 2024 - 13.2K bytes - Viewed (0) -
plugin/pkg/admission/security/podsecurity/testdata/pod_restricted.yaml
successThreshold: 1 timeoutSeconds: 5 resources: limits: memory: 210Mi requests: cpu: 100m memory: 70Mi securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true runAsGroup: 1001 runAsUser: 1001 runAsNonRoot: true capabilities: add: - NET_BIND_SERVICE drop:
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Oct 04 16:26:30 UTC 2021 - 18.3K bytes - Viewed (0) -
pkg/kube/inject/testdata/inject/list.yaml.injected
limits: cpu: "2" memory: 1Gi requests: cpu: 100m memory: 128Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL privileged: false readOnlyRootFilesystem: true runAsGroup: 1337
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue Feb 27 16:55:16 UTC 2024 - 14.2K bytes - Viewed (0) -
plugin/pkg/admission/security/podsecurity/testdata/pod_baseline.yaml
successThreshold: 1 timeoutSeconds: 5 resources: limits: memory: 210Mi requests: cpu: 100m memory: 70Mi securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true runAsGroup: 1001 capabilities: add: - NET_BIND_SERVICE drop: - ALL
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Oct 04 16:26:30 UTC 2021 - 18.1K bytes - Viewed (0) -
pkg/kube/inject/testdata/inject/explicit-security-context.yaml.injected
resources: limits: cpu: "2" memory: 1Gi requests: cpu: 100m memory: 128Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL privileged: false readOnlyRootFilesystem: true runAsGroup: 1337 runAsNonRoot: true
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue Feb 27 16:55:16 UTC 2024 - 6.4K bytes - Viewed (0) -
pkg/kube/inject/testdata/inject/prometheus-scrape2.yaml.injected
timeoutSeconds: 3 resources: limits: cpu: "2" memory: 1Gi requests: cpu: 100m memory: 128Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL privileged: false readOnlyRootFilesystem: true runAsGroup: 1337 runAsNonRoot: true runAsUser: 1337
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue Feb 27 16:55:16 UTC 2024 - 5.4K bytes - Viewed (0) -
pkg/kube/inject/testdata/inject/replicationcontroller.yaml.injected
resources: limits: cpu: "2" memory: 1Gi requests: cpu: 100m memory: 128Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL privileged: false readOnlyRootFilesystem: true runAsGroup: 1337 runAsNonRoot: true
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue Feb 27 16:55:16 UTC 2024 - 6.4K bytes - Viewed (0) -
helm/minio/templates/securitycontextconstraints.yaml
release: {{ .Release.Name }} heritage: {{ .Release.Service }} allowHostDirVolumePlugin: false allowHostIPC: false allowHostNetwork: false allowHostPID: false allowHostPorts: false allowPrivilegeEscalation: true allowPrivilegedContainer: false allowedCapabilities: [] readOnlyRootFilesystem: false defaultAddCapabilities: [] requiredDropCapabilities: - KILL - MKNOD - SETUID - SETGID fsGroup:
Registered: Sun Jun 16 00:44:34 UTC 2024 - Last Modified: Fri Aug 20 22:30:54 UTC 2021 - 1.1K bytes - Viewed (0) -
cmd/kubeadm/app/util/staticpod/utils_linux.go
err := updatePathOwnerAndPermissions(caKeyFile, *runAsUser, *runAsGroup, 0600) if err != nil { return err } } pod.Spec.Containers[0].SecurityContext = &v1.SecurityContext{ AllowPrivilegeEscalation: ptr.To(false), Capabilities: &v1.Capabilities{ // We drop all capabilities that are added by default. Drop: []v1.Capability{"ALL"}, }, } pod.Spec.SecurityContext.RunAsUser = runAsUser
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Sep 11 14:41:12 UTC 2023 - 8.4K bytes - Viewed (0) -
pkg/kube/inject/testdata/inject/auth.non-default-service-account.yaml.injected
resources: limits: cpu: "2" memory: 1Gi requests: cpu: 100m memory: 128Mi securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL privileged: false readOnlyRootFilesystem: true runAsGroup: 1337 runAsNonRoot: true
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue Feb 27 16:55:16 UTC 2024 - 6.6K bytes - Viewed (0)