Do not use privileged containers for worker init

This commit is contained in:
Volodymyr Stoiko 2024-12-26 09:27:28 +02:00
parent 639f1deb51
commit 014036ffcf

View File

@ -38,7 +38,9 @@ spec:
imagePullPolicy: {{ .Values.tap.docker.imagePullPolicy }}
name: check-bpf
securityContext:
privileged: true
capabilities:
add:
- CAP_SYS_ADMIN
volumeMounts:
- mountPath: /sys
name: sys
@ -54,7 +56,9 @@ spec:
imagePullPolicy: {{ .Values.tap.docker.imagePullPolicy }}
name: init-bpf
securityContext:
privileged: true
capabilities:
add:
- CAP_SYS_ADMIN
volumeMounts:
- mountPath: /sys
name: sys