Update pod security docs for dockershim removal
This commit is contained in:
@@ -658,8 +658,7 @@ added. Capabilities listed in `RequiredDropCapabilities` must not be included in
|
|||||||
|
|
||||||
**DefaultAddCapabilities** - The capabilities which are added to containers by
|
**DefaultAddCapabilities** - The capabilities which are added to containers by
|
||||||
default, in addition to the runtime defaults. See the
|
default, in addition to the runtime defaults. See the
|
||||||
[Docker documentation](https://docs.docker.com/engine/reference/run/#runtime-privilege-and-linux-capabilities)
|
the documentation for your container runtime for information on working with Linux capabilities.
|
||||||
for the default list of capabilities when using the Docker runtime.
|
|
||||||
|
|
||||||
### SELinux
|
### SELinux
|
||||||
|
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ kind: PodSecurityPolicy
|
|||||||
metadata:
|
metadata:
|
||||||
name: restricted
|
name: restricted
|
||||||
annotations:
|
annotations:
|
||||||
|
# docker/default identifies an seccomp profile, but it is not particularly tied to the Docker runtime
|
||||||
seccomp.security.alpha.kubernetes.io/allowedProfileNames: 'docker/default,runtime/default'
|
seccomp.security.alpha.kubernetes.io/allowedProfileNames: 'docker/default,runtime/default'
|
||||||
apparmor.security.beta.kubernetes.io/allowedProfileNames: 'runtime/default'
|
apparmor.security.beta.kubernetes.io/allowedProfileNames: 'runtime/default'
|
||||||
apparmor.security.beta.kubernetes.io/defaultProfileName: 'runtime/default'
|
apparmor.security.beta.kubernetes.io/defaultProfileName: 'runtime/default'
|
||||||
|
|||||||
Reference in New Issue
Block a user