retain read only root file system in determineEffectiveSecurityContext
This commit is contained in:
parent
e0f7de94f5
commit
04dc71f959
@ -159,6 +159,11 @@ func DetermineEffectiveSecurityContext(pod *api.Pod, container *api.Container) *
|
|||||||
*effectiveSc.RunAsNonRoot = *containerSc.RunAsNonRoot
|
*effectiveSc.RunAsNonRoot = *containerSc.RunAsNonRoot
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if containerSc.ReadOnlyRootFilesystem != nil {
|
||||||
|
effectiveSc.ReadOnlyRootFilesystem = new(bool)
|
||||||
|
*effectiveSc.ReadOnlyRootFilesystem = *containerSc.ReadOnlyRootFilesystem
|
||||||
|
}
|
||||||
|
|
||||||
return effectiveSc
|
return effectiveSc
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user