Disable container privilege escalation.
Per Azure best practice, disable a container's ability to escalate its privileges. https://docs.microsoft.com/en-us/azure/aks/developer-best-practices-pod-security#secure-pod-access-to-resources
This commit is contained in:
@@ -16,6 +16,8 @@ spec:
|
||||
containers:
|
||||
- name: migration
|
||||
image: $CONTAINER_IMAGE
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
command: [
|
||||
"/bin/sh", "-c"
|
||||
]
|
||||
|
Reference in New Issue
Block a user