mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-07-20 10:20:51 +00:00
PodSecurity test: update registry from k8s.gcr.io to registry.k8s.io
This commit is contained in:
parent
b2f8c8f00d
commit
51089767a6
@ -60,8 +60,8 @@ func init() {
|
|||||||
// Define minimal valid baseline pod.
|
// Define minimal valid baseline pod.
|
||||||
// This must remain valid for all versions.
|
// This must remain valid for all versions.
|
||||||
baseline_1_0 := &corev1.Pod{Spec: corev1.PodSpec{
|
baseline_1_0 := &corev1.Pod{Spec: corev1.PodSpec{
|
||||||
InitContainers: []corev1.Container{{Name: "initcontainer1", Image: "k8s.gcr.io/pause"}},
|
InitContainers: []corev1.Container{{Name: "initcontainer1", Image: "registry.k8s.io/pause"}},
|
||||||
Containers: []corev1.Container{{Name: "container1", Image: "k8s.gcr.io/pause"}}}}
|
Containers: []corev1.Container{{Name: "container1", Image: "registry.k8s.io/pause"}}}}
|
||||||
minimalValidPods[api.LevelBaseline][api.MajorMinorVersion(1, 0)] = baseline_1_0
|
minimalValidPods[api.LevelBaseline][api.MajorMinorVersion(1, 0)] = baseline_1_0
|
||||||
|
|
||||||
//
|
//
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: apparmorprofile0
|
name: apparmorprofile0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: apparmorprofile1
|
name: apparmorprofile1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: capabilities_baseline0
|
name: capabilities_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
add:
|
add:
|
||||||
- NET_RAW
|
- NET_RAW
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: capabilities_baseline1
|
name: capabilities_baseline1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: capabilities_baseline2
|
name: capabilities_baseline2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
add:
|
add:
|
||||||
- chown
|
- chown
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: capabilities_baseline3
|
name: capabilities_baseline3
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
add:
|
add:
|
||||||
- CAP_CHOWN
|
- CAP_CHOWN
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: hostnamespaces0
|
name: hostnamespaces0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
hostIPC: true
|
hostIPC: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: hostnamespaces1
|
name: hostnamespaces1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
hostNetwork: true
|
hostNetwork: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: hostnamespaces2
|
name: hostnamespaces2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
hostPID: true
|
hostPID: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: hostpathvolumes0
|
name: hostpathvolumes0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
volumes:
|
volumes:
|
||||||
- emptyDir: {}
|
- emptyDir: {}
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: hostpathvolumes1
|
name: hostpathvolumes1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
volumes:
|
volumes:
|
||||||
- hostPath:
|
- hostPath:
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: hostports0
|
name: hostports0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12345
|
- containerPort: 12345
|
||||||
hostPort: 12345
|
hostPort: 12345
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: hostports1
|
name: hostports1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12346
|
- containerPort: 12346
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: hostports2
|
name: hostports2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12345
|
- containerPort: 12345
|
||||||
hostPort: 12345
|
hostPort: 12345
|
||||||
- containerPort: 12347
|
- containerPort: 12347
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12346
|
- containerPort: 12346
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: privileged0
|
name: privileged0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: privileged1
|
name: privileged1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: procmount0
|
name: procmount0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Unmasked
|
procMount: Unmasked
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: procmount1
|
name: procmount1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Unmasked
|
procMount: Unmasked
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: seccompprofile_baseline0
|
name: seccompprofile_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: seccompprofile_baseline1
|
name: seccompprofile_baseline1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: seccompprofile_baseline2
|
name: seccompprofile_baseline2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: selinuxoptions0
|
name: selinuxoptions0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,13 +4,13 @@ metadata:
|
|||||||
name: selinuxoptions1
|
name: selinuxoptions1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions:
|
seLinuxOptions:
|
||||||
type: somevalue
|
type: somevalue
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: selinuxoptions2
|
name: selinuxoptions2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions:
|
seLinuxOptions:
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: selinuxoptions3
|
name: selinuxoptions3
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: selinuxoptions4
|
name: selinuxoptions4
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: sysctls0
|
name: sysctls0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
sysctls:
|
sysctls:
|
||||||
|
@ -4,13 +4,13 @@ metadata:
|
|||||||
name: windowshostprocess0
|
name: windowshostprocess0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
windowsOptions: {}
|
windowsOptions: {}
|
||||||
hostNetwork: true
|
hostNetwork: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
windowsOptions: {}
|
windowsOptions: {}
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: windowshostprocess1
|
name: windowshostprocess1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
windowsOptions:
|
windowsOptions:
|
||||||
hostProcess: true
|
hostProcess: true
|
||||||
hostNetwork: true
|
hostNetwork: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
windowsOptions:
|
windowsOptions:
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: apparmorprofile0
|
name: apparmorprofile0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,8 +4,8 @@ metadata:
|
|||||||
name: base
|
name: base
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,7 +4,7 @@ metadata:
|
|||||||
name: capabilities_baseline0
|
name: capabilities_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
@ -23,7 +23,7 @@ spec:
|
|||||||
- SETUID
|
- SETUID
|
||||||
- SYS_CHROOT
|
- SYS_CHROOT
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: hostports0
|
name: hostports0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12345
|
- containerPort: 12345
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12346
|
- containerPort: 12346
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: privileged0
|
name: privileged0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: false
|
privileged: false
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: false
|
privileged: false
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: procmount0
|
name: procmount0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Default
|
procMount: Default
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Default
|
procMount: Default
|
||||||
|
@ -7,8 +7,8 @@ metadata:
|
|||||||
name: seccompprofile_baseline0
|
name: seccompprofile_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: selinuxoptions0
|
name: selinuxoptions0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: selinuxoptions1
|
name: selinuxoptions1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions:
|
seLinuxOptions:
|
||||||
level: somevalue
|
level: somevalue
|
||||||
type: container_init_t
|
type: container_init_t
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions:
|
seLinuxOptions:
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: sysctls0
|
name: sysctls0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: sysctls1
|
name: sysctls1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
sysctls:
|
sysctls:
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: apparmorprofile0
|
name: apparmorprofile0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: apparmorprofile1
|
name: apparmorprofile1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: capabilities_baseline0
|
name: capabilities_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
add:
|
add:
|
||||||
- NET_RAW
|
- NET_RAW
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: capabilities_baseline1
|
name: capabilities_baseline1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: capabilities_baseline2
|
name: capabilities_baseline2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
add:
|
add:
|
||||||
- chown
|
- chown
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: capabilities_baseline3
|
name: capabilities_baseline3
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
add:
|
add:
|
||||||
- CAP_CHOWN
|
- CAP_CHOWN
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: hostnamespaces0
|
name: hostnamespaces0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
hostIPC: true
|
hostIPC: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: hostnamespaces1
|
name: hostnamespaces1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
hostNetwork: true
|
hostNetwork: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: hostnamespaces2
|
name: hostnamespaces2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
hostPID: true
|
hostPID: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: hostpathvolumes0
|
name: hostpathvolumes0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
volumes:
|
volumes:
|
||||||
- emptyDir: {}
|
- emptyDir: {}
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: hostpathvolumes1
|
name: hostpathvolumes1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
volumes:
|
volumes:
|
||||||
- hostPath:
|
- hostPath:
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: hostports0
|
name: hostports0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12345
|
- containerPort: 12345
|
||||||
hostPort: 12345
|
hostPort: 12345
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: hostports1
|
name: hostports1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12346
|
- containerPort: 12346
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: hostports2
|
name: hostports2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12345
|
- containerPort: 12345
|
||||||
hostPort: 12345
|
hostPort: 12345
|
||||||
- containerPort: 12347
|
- containerPort: 12347
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12346
|
- containerPort: 12346
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: privileged0
|
name: privileged0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: privileged1
|
name: privileged1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: procmount0
|
name: procmount0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Unmasked
|
procMount: Unmasked
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: procmount1
|
name: procmount1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Unmasked
|
procMount: Unmasked
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: seccompprofile_baseline0
|
name: seccompprofile_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: seccompprofile_baseline1
|
name: seccompprofile_baseline1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: seccompprofile_baseline2
|
name: seccompprofile_baseline2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: selinuxoptions0
|
name: selinuxoptions0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,13 +4,13 @@ metadata:
|
|||||||
name: selinuxoptions1
|
name: selinuxoptions1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions:
|
seLinuxOptions:
|
||||||
type: somevalue
|
type: somevalue
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: selinuxoptions2
|
name: selinuxoptions2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions:
|
seLinuxOptions:
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: selinuxoptions3
|
name: selinuxoptions3
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: selinuxoptions4
|
name: selinuxoptions4
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: sysctls0
|
name: sysctls0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
sysctls:
|
sysctls:
|
||||||
|
@ -4,13 +4,13 @@ metadata:
|
|||||||
name: windowshostprocess0
|
name: windowshostprocess0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
windowsOptions: {}
|
windowsOptions: {}
|
||||||
hostNetwork: true
|
hostNetwork: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
windowsOptions: {}
|
windowsOptions: {}
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: windowshostprocess1
|
name: windowshostprocess1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
windowsOptions:
|
windowsOptions:
|
||||||
hostProcess: true
|
hostProcess: true
|
||||||
hostNetwork: true
|
hostNetwork: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
windowsOptions:
|
windowsOptions:
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: apparmorprofile0
|
name: apparmorprofile0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,8 +4,8 @@ metadata:
|
|||||||
name: base
|
name: base
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,7 +4,7 @@ metadata:
|
|||||||
name: capabilities_baseline0
|
name: capabilities_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
@ -23,7 +23,7 @@ spec:
|
|||||||
- SETUID
|
- SETUID
|
||||||
- SYS_CHROOT
|
- SYS_CHROOT
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: hostports0
|
name: hostports0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12345
|
- containerPort: 12345
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12346
|
- containerPort: 12346
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: privileged0
|
name: privileged0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: false
|
privileged: false
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: false
|
privileged: false
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: procmount0
|
name: procmount0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Default
|
procMount: Default
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Default
|
procMount: Default
|
||||||
|
@ -7,8 +7,8 @@ metadata:
|
|||||||
name: seccompprofile_baseline0
|
name: seccompprofile_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: selinuxoptions0
|
name: selinuxoptions0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions: {}
|
seLinuxOptions: {}
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: selinuxoptions1
|
name: selinuxoptions1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions:
|
seLinuxOptions:
|
||||||
level: somevalue
|
level: somevalue
|
||||||
type: container_init_t
|
type: container_init_t
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
seLinuxOptions:
|
seLinuxOptions:
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: sysctls0
|
name: sysctls0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: sysctls1
|
name: sysctls1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
sysctls:
|
sysctls:
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: apparmorprofile0
|
name: apparmorprofile0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: apparmorprofile1
|
name: apparmorprofile1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: capabilities_baseline0
|
name: capabilities_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
add:
|
add:
|
||||||
- NET_RAW
|
- NET_RAW
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: capabilities_baseline1
|
name: capabilities_baseline1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: capabilities_baseline2
|
name: capabilities_baseline2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
add:
|
add:
|
||||||
- chown
|
- chown
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: capabilities_baseline3
|
name: capabilities_baseline3
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities:
|
capabilities:
|
||||||
add:
|
add:
|
||||||
- CAP_CHOWN
|
- CAP_CHOWN
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
capabilities: {}
|
capabilities: {}
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: hostnamespaces0
|
name: hostnamespaces0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
hostIPC: true
|
hostIPC: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: hostnamespaces1
|
name: hostnamespaces1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
hostNetwork: true
|
hostNetwork: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,9 +4,9 @@ metadata:
|
|||||||
name: hostnamespaces2
|
name: hostnamespaces2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
hostPID: true
|
hostPID: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: hostpathvolumes0
|
name: hostpathvolumes0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
volumes:
|
volumes:
|
||||||
- emptyDir: {}
|
- emptyDir: {}
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: hostpathvolumes1
|
name: hostpathvolumes1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
volumes:
|
volumes:
|
||||||
- hostPath:
|
- hostPath:
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: hostports0
|
name: hostports0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12345
|
- containerPort: 12345
|
||||||
hostPort: 12345
|
hostPort: 12345
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
@ -4,10 +4,10 @@ metadata:
|
|||||||
name: hostports1
|
name: hostports1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12346
|
- containerPort: 12346
|
||||||
|
@ -4,14 +4,14 @@ metadata:
|
|||||||
name: hostports2
|
name: hostports2
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12345
|
- containerPort: 12345
|
||||||
hostPort: 12345
|
hostPort: 12345
|
||||||
- containerPort: 12347
|
- containerPort: 12347
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 12346
|
- containerPort: 12346
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: privileged0
|
name: privileged0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: privileged1
|
name: privileged1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
|
@ -4,12 +4,12 @@ metadata:
|
|||||||
name: procmount0
|
name: procmount0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Unmasked
|
procMount: Unmasked
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
|
@ -4,11 +4,11 @@ metadata:
|
|||||||
name: procmount1
|
name: procmount1
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
securityContext:
|
securityContext:
|
||||||
procMount: Unmasked
|
procMount: Unmasked
|
||||||
|
@ -6,8 +6,8 @@ metadata:
|
|||||||
name: seccompprofile_baseline0
|
name: seccompprofile_baseline0
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: container1
|
name: container1
|
||||||
initContainers:
|
initContainers:
|
||||||
- image: k8s.gcr.io/pause
|
- image: registry.k8s.io/pause
|
||||||
name: initcontainer1
|
name: initcontainer1
|
||||||
|
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user