2.4.5.3. Pod 安全策略示例
您的 Pod 安全策略可能类似以下 YAML 文件:
apiVersion: policy.open-cluster-management.io/v1 kind: Policy metadata: name: policy-podsecuritypolicy namespace: open-cluster-management spec: complianceType: musthave remediationAction: inform namespaces: exclude: ["kube-*"] include: ["default"] object-templates: - complianceType: musthave objectDefinition: apiVersion: policy/v1beta1 kind: PodSecurityPolicy # no privileged pods metadata: name: restricted-open-cluster-management annotations: seccomp.security.alpha.kubernetes.io/allowedProfileNames: '*' spec: privileged: false # no priviliedged pods allowPrivilegeEscalation: false allowedCapabilities: - '*' volumes: - '*' hostNetwork: true hostPorts: - min: 1000 # ports < 1000 are reserved max: 65535 hostIPC: false hostPID: false runAsUser: rule: 'RunAsAny' seLinux: rule: 'RunAsAny' supplementalGroups: rule: 'RunAsAny' fsGroup: rule: 'RunAsAny' ...
如需更多信息,请参阅管理 Pod 安全策略。查看由控制器监控的其他配置策略,请参阅 Kubernetes 配置策略控制器页面。