Skip to content

Commit 2de4669

Browse files
Update bdc-scc.yaml
1 parent ba7e7dc commit 2de4669

1 file changed

Lines changed: 31 additions & 31 deletions

File tree

  • samples/features/sql-big-data-cluster/deployment/openshift
Lines changed: 31 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -1,39 +1,39 @@
1-
apiVersion: security.openshift.io/v1
2-
kind: SecurityContextConstraints
3-
metadata:
4-
  annotations:
5-
    kubernetes.io/description: SQL Server BDC custom scc is based on 'nonroot' scc plus additional capabilities.
6-
  generation: 2
7-
  name: bdc-scc
8-
allowHostDirVolumePlugin: false
9-
allowHostIPC: false
10-
allowHostNetwork: false
11-
allowHostPID: false
12-
allowHostPorts: false
13-
allowPrivilegeEscalation: true
14-
allowPrivilegedContainer: false
1+
allowHostDirVolumePlugin: false
2+
allowHostIPC: false
3+
allowHostNetwork: false
4+
allowHostPID: false
5+
allowHostPorts: false
6+
allowPrivilegeEscalation: true
7+
allowPrivilegedContainer: false
158
allowedCapabilities:
16-
- SETUID
17-
- SETGID
18-
- CHOWN
9+
- SETUID
10+
- SETGID
11+
- CHOWN
1912
- SYS_PTRACE
20-
defaultAddCapabilities: null
13+
apiVersion: security.openshift.io/v1
14+
defaultAddCapabilities: null
2115
fsGroup:
22-
  type: RunAsAny
23-
readOnlyRootFilesystem: false
16+
type: RunAsAny
17+
kind: SecurityContextConstraints
18+
metadata:
19+
annotations:
20+
kubernetes.io/description: SQL Server BDC custom scc is based on 'nonroot' scc plus additional capabilities required by BDC.
21+
generation: 2
22+
name: bdc-scc
23+
readOnlyRootFilesystem: false
2424
requiredDropCapabilities:
25-
- KILL
26-
- MKNOD
25+
- KILL
26+
- MKNOD
2727
runAsUser:
28-
  type: MustRunAsNonRoot
28+
type: MustRunAsNonRoot
2929
seLinuxContext:
30-
  type: MustRunAs
30+
type: MustRunAs
3131
supplementalGroups:
32-
  type: RunAsAny
32+
type: RunAsAny
3333
volumes:
34-
- configMap
35-
- downwardAPI
36-
- emptyDir
37-
- persistentVolumeClaim
38-
- projected
39-
- secret
34+
- configMap
35+
- downwardAPI
36+
- emptyDir
37+
- persistentVolumeClaim
38+
- projected
39+
- secret

0 commit comments

Comments
 (0)