cadvisor/deploy/kubernetes/base/podsecuritypolicy.yaml
George Angel 18566a56f8 add manifests for rbac and psps
Allow cadvisor to run in clusters with PSPs enabled
2019-05-01 21:36:39 +01:00

22 lines
388 B
YAML

apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: cadvisor
spec:
seLinux:
rule: RunAsAny
supplementalGroups:
rule: RunAsAny
runAsUser:
rule: RunAsAny
fsGroup:
rule: RunAsAny
volumes:
- '*'
allowedHostPaths:
- pathPrefix: "/"
- pathPrefix: "/var/run"
- pathPrefix: "/sys"
- pathPrefix: "/var/lib/docker"
- pathPrefix: "/dev/disk"