deploy: reduce the PSP permission for rbd deployment

rbd deployment doesnot need extra permission like
privileged,Capabilities and remove unwanted volumes.

Signed-off-by: Madhu Rajanna <madhupr007@gmail.com>
This commit is contained in:
Madhu Rajanna 2021-09-17 13:57:01 +05:30 committed by mergify[bot]
parent e5569f0547
commit 9e88fd1eb7

View File

@ -4,12 +4,8 @@ kind: PodSecurityPolicy
metadata: metadata:
name: rbd-csi-provisioner-psp name: rbd-csi-provisioner-psp
spec: spec:
allowPrivilegeEscalation: true
allowedCapabilities:
- 'SYS_ADMIN'
fsGroup: fsGroup:
rule: RunAsAny rule: RunAsAny
privileged: true
runAsUser: runAsUser:
rule: RunAsAny rule: RunAsAny
seLinux: seLinux:
@ -21,7 +17,6 @@ spec:
- 'emptyDir' - 'emptyDir'
- 'projected' - 'projected'
- 'secret' - 'secret'
- 'downwardAPI'
- 'hostPath' - 'hostPath'
allowedHostPaths: allowedHostPaths:
- pathPrefix: '/dev' - pathPrefix: '/dev'