blob: 716dbf16fe5b452513d67015527d677803aabe3d [file] [log] [blame]
Giorgi Lekveishvili725bb392023-05-05 18:24:27 +04001{{- if and .Values.podSecurityPolicy.enabled .Values.defaultBackend.enabled (empty .Values.defaultBackend.existingPsp) -}}
2apiVersion: policy/v1beta1
3kind: PodSecurityPolicy
4metadata:
5 name: {{ include "ingress-nginx.fullname" . }}-backend
6 labels:
7 {{- include "ingress-nginx.labels" . | nindent 4 }}
8 app.kubernetes.io/component: default-backend
9spec:
10 allowPrivilegeEscalation: false
11 fsGroup:
12 ranges:
13 - max: 65535
14 min: 1
15 rule: MustRunAs
16 requiredDropCapabilities:
17 - ALL
18 runAsUser:
19 rule: MustRunAsNonRoot
20 seLinux:
21 rule: RunAsAny
22 supplementalGroups:
23 ranges:
24 - max: 65535
25 min: 1
26 rule: MustRunAs
27 volumes:
28 - configMap
29 - emptyDir
30 - projected
31 - secret
32 - downwardAPI
33{{- end }}