chore(postgres): set pod security standards

This commit is contained in:
Masaki Yatsu
2025-11-23 15:02:24 +09:00
parent 44ba48ee2f
commit d036c479d3
3 changed files with 33 additions and 7 deletions

View File

@@ -1,7 +1,26 @@
# Pod Security Context for restricted Pod Security Standards
podSecurityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
fsGroup: 10001
# Container Security Context for restricted Pod Security Standards
containerSecurityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsUser: 10001
runAsGroup: 10001
seccompProfile:
type: RuntimeDefault
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 128Mi
limits:
cpu: 100m
memory: 256Mi
requests:
cpu: 50m
memory: 128Mi
limits:
cpu: 100m
memory: 256Mi