PodSecurity: restrictedVolumes: regenerate files

This commit is contained in:
Jordan Liggitt 2021-07-07 22:26:47 -04:00
parent 676240a342
commit edb7cdb02a
483 changed files with 1288 additions and 1265 deletions

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- gcePersistentDisk:
pdName: testing
name: volume-gcepersistentdisk
pdName: test
name: volume1

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- awsElasticBlockStore:
volumeID: testing
name: volume-awselasticblockstore
volumeID: test
name: volume1

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- flocker:
datasetName: testing
name: volume-flocker
datasetName: test
name: volume1

View File

@ -14,5 +14,5 @@ spec:
volumes:
- fc:
wwids:
- testing
name: volume-fc
- test
name: volume1

View File

@ -13,6 +13,6 @@ spec:
runAsNonRoot: true
volumes:
- azureFile:
secretName: testing
shareName: testing
name: volume-azurefile
secretName: test
shareName: test
name: volume1

View File

@ -12,6 +12,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-vsphere
- name: volume1
vsphereVolume:
volumePath: testing
volumePath: test

View File

@ -12,7 +12,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-quobyte
- name: volume1
quobyte:
registry: localhost:1234
volume: testing
volume: test

View File

@ -13,6 +13,6 @@ spec:
runAsNonRoot: true
volumes:
- azureDisk:
diskName: testing
diskName: test
diskURI: https://test.blob.core.windows.net/test/test.vhd
name: volume-azuredisk
name: volume1

View File

@ -12,7 +12,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-portworxvolume
- name: volume1
portworxVolume:
fsType: ext4
volumeID: testing
volumeID: test

View File

@ -12,9 +12,9 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-scaleio
- name: volume1
scaleIO:
gateway: localhost
secretRef: null
system: testing
volumeName: testing
system: test
volumeName: test

View File

@ -12,6 +12,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-storageos
- name: volume1
storageos:
volumeName: test

View File

@ -14,4 +14,4 @@ spec:
volumes:
- hostPath:
path: /dev/null
name: volume-hostpath
name: volume1

View File

@ -14,4 +14,4 @@ spec:
volumes:
- gitRepo:
repository: github.com/kubernetes/kubernetes
name: volume-gitrepo
name: volume1

View File

@ -12,7 +12,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-nfs
- name: volume1
nfs:
path: /testing
server: testing
path: /test
server: test

View File

@ -15,5 +15,5 @@ spec:
- iscsi:
iqn: iqn.2001-04.com.example:storage.kube.sys1.xyz
lun: 0
targetPortal: testing
name: volume-iscsi
targetPortal: test
name: volume1

View File

@ -13,6 +13,6 @@ spec:
runAsNonRoot: true
volumes:
- glusterfs:
endpoints: testing
path: testing
name: volume-glusterfs
endpoints: test
path: test
name: volume1

View File

@ -12,8 +12,8 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-rbd
- name: volume1
rbd:
image: testing
image: test
monitors:
- testing
- test

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- flexVolume:
driver: testing
name: volume-flexvolume
driver: test
name: volume1

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- cinder:
volumeID: testing
name: volume-cinder
volumeID: test
name: volume1

View File

@ -14,5 +14,5 @@ spec:
volumes:
- cephfs:
monitors:
- testing
name: volume-cephfs
- test
name: volume1

View File

@ -12,23 +12,24 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- configMap:
name: volume-configmap-test
name: volume-configmap
- name: volume0
- emptyDir: {}
name: volume1
- name: volume2
secret:
secretName: test
- name: volume3
persistentVolumeClaim:
claimName: test
- downwardAPI:
items:
- fieldRef:
fieldPath: metadata.labels
path: labels
name: volume-downwardapi
- emptyDir: {}
name: volume-emptydir
- name: volume-pvc
persistentVolumeClaim:
claimName: test
- name: volume-projects
name: volume4
- configMap:
name: test
name: volume5
- name: volume6
projected:
sources: []
- name: volume-secret
secret:
secretName: test

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- gcePersistentDisk:
pdName: testing
name: volume-gcepersistentdisk
pdName: test
name: volume1

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- awsElasticBlockStore:
volumeID: testing
name: volume-awselasticblockstore
volumeID: test
name: volume1

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- flocker:
datasetName: testing
name: volume-flocker
datasetName: test
name: volume1

View File

@ -14,5 +14,5 @@ spec:
volumes:
- fc:
wwids:
- testing
name: volume-fc
- test
name: volume1

View File

@ -13,6 +13,6 @@ spec:
runAsNonRoot: true
volumes:
- azureFile:
secretName: testing
shareName: testing
name: volume-azurefile
secretName: test
shareName: test
name: volume1

View File

@ -12,6 +12,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-vsphere
- name: volume1
vsphereVolume:
volumePath: testing
volumePath: test

View File

@ -12,7 +12,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-quobyte
- name: volume1
quobyte:
registry: localhost:1234
volume: testing
volume: test

View File

@ -13,6 +13,6 @@ spec:
runAsNonRoot: true
volumes:
- azureDisk:
diskName: testing
diskName: test
diskURI: https://test.blob.core.windows.net/test/test.vhd
name: volume-azuredisk
name: volume1

View File

@ -12,7 +12,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-portworxvolume
- name: volume1
portworxVolume:
fsType: ext4
volumeID: testing
volumeID: test

View File

@ -12,9 +12,9 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-scaleio
- name: volume1
scaleIO:
gateway: localhost
secretRef: null
system: testing
volumeName: testing
system: test
volumeName: test

View File

@ -12,6 +12,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-storageos
- name: volume1
storageos:
volumeName: test

View File

@ -14,4 +14,4 @@ spec:
volumes:
- hostPath:
path: /dev/null
name: volume-hostpath
name: volume1

View File

@ -14,4 +14,4 @@ spec:
volumes:
- gitRepo:
repository: github.com/kubernetes/kubernetes
name: volume-gitrepo
name: volume1

View File

@ -12,7 +12,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-nfs
- name: volume1
nfs:
path: /testing
server: testing
path: /test
server: test

View File

@ -15,5 +15,5 @@ spec:
- iscsi:
iqn: iqn.2001-04.com.example:storage.kube.sys1.xyz
lun: 0
targetPortal: testing
name: volume-iscsi
targetPortal: test
name: volume1

View File

@ -13,6 +13,6 @@ spec:
runAsNonRoot: true
volumes:
- glusterfs:
endpoints: testing
path: testing
name: volume-glusterfs
endpoints: test
path: test
name: volume1

View File

@ -12,8 +12,8 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-rbd
- name: volume1
rbd:
image: testing
image: test
monitors:
- testing
- test

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- flexVolume:
driver: testing
name: volume-flexvolume
driver: test
name: volume1

View File

@ -13,5 +13,5 @@ spec:
runAsNonRoot: true
volumes:
- cinder:
volumeID: testing
name: volume-cinder
volumeID: test
name: volume1

View File

@ -14,5 +14,5 @@ spec:
volumes:
- cephfs:
monitors:
- testing
name: volume-cephfs
- test
name: volume1

View File

@ -12,23 +12,24 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- configMap:
name: volume-configmap-test
name: volume-configmap
- name: volume0
- emptyDir: {}
name: volume1
- name: volume2
secret:
secretName: test
- name: volume3
persistentVolumeClaim:
claimName: test
- downwardAPI:
items:
- fieldRef:
fieldPath: metadata.labels
path: labels
name: volume-downwardapi
- emptyDir: {}
name: volume-emptydir
- name: volume-pvc
persistentVolumeClaim:
claimName: test
- name: volume-projects
name: volume4
- configMap:
name: test
name: volume5
- name: volume6
projected:
sources: []
- name: volume-secret
secret:
secretName: test

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- gcePersistentDisk:
pdName: testing
name: volume-gcepersistentdisk
pdName: test
name: volume1

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- awsElasticBlockStore:
volumeID: testing
name: volume-awselasticblockstore
volumeID: test
name: volume1

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- flocker:
datasetName: testing
name: volume-flocker
datasetName: test
name: volume1

View File

@ -18,5 +18,5 @@ spec:
volumes:
- fc:
wwids:
- testing
name: volume-fc
- test
name: volume1

View File

@ -17,6 +17,6 @@ spec:
runAsNonRoot: true
volumes:
- azureFile:
secretName: testing
shareName: testing
name: volume-azurefile
secretName: test
shareName: test
name: volume1

View File

@ -16,6 +16,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-vsphere
- name: volume1
vsphereVolume:
volumePath: testing
volumePath: test

View File

@ -16,7 +16,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-quobyte
- name: volume1
quobyte:
registry: localhost:1234
volume: testing
volume: test

View File

@ -17,6 +17,6 @@ spec:
runAsNonRoot: true
volumes:
- azureDisk:
diskName: testing
diskName: test
diskURI: https://test.blob.core.windows.net/test/test.vhd
name: volume-azuredisk
name: volume1

View File

@ -16,7 +16,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-portworxvolume
- name: volume1
portworxVolume:
fsType: ext4
volumeID: testing
volumeID: test

View File

@ -16,9 +16,9 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-scaleio
- name: volume1
scaleIO:
gateway: localhost
secretRef: null
system: testing
volumeName: testing
system: test
volumeName: test

View File

@ -16,6 +16,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-storageos
- name: volume1
storageos:
volumeName: test

View File

@ -18,4 +18,4 @@ spec:
volumes:
- hostPath:
path: /dev/null
name: volume-hostpath
name: volume1

View File

@ -18,4 +18,4 @@ spec:
volumes:
- gitRepo:
repository: github.com/kubernetes/kubernetes
name: volume-gitrepo
name: volume1

View File

@ -16,7 +16,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-nfs
- name: volume1
nfs:
path: /testing
server: testing
path: /test
server: test

View File

@ -19,5 +19,5 @@ spec:
- iscsi:
iqn: iqn.2001-04.com.example:storage.kube.sys1.xyz
lun: 0
targetPortal: testing
name: volume-iscsi
targetPortal: test
name: volume1

View File

@ -17,6 +17,6 @@ spec:
runAsNonRoot: true
volumes:
- glusterfs:
endpoints: testing
path: testing
name: volume-glusterfs
endpoints: test
path: test
name: volume1

View File

@ -16,8 +16,8 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-rbd
- name: volume1
rbd:
image: testing
image: test
monitors:
- testing
- test

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- flexVolume:
driver: testing
name: volume-flexvolume
driver: test
name: volume1

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- cinder:
volumeID: testing
name: volume-cinder
volumeID: test
name: volume1

View File

@ -18,5 +18,5 @@ spec:
volumes:
- cephfs:
monitors:
- testing
name: volume-cephfs
- test
name: volume1

View File

@ -16,23 +16,24 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- configMap:
name: volume-configmap-test
name: volume-configmap
- name: volume0
- emptyDir: {}
name: volume1
- name: volume2
secret:
secretName: test
- name: volume3
persistentVolumeClaim:
claimName: test
- downwardAPI:
items:
- fieldRef:
fieldPath: metadata.labels
path: labels
name: volume-downwardapi
- emptyDir: {}
name: volume-emptydir
- name: volume-pvc
persistentVolumeClaim:
claimName: test
- name: volume-projects
name: volume4
- configMap:
name: test
name: volume5
- name: volume6
projected:
sources: []
- name: volume-secret
secret:
secretName: test

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- gcePersistentDisk:
pdName: testing
name: volume-gcepersistentdisk
pdName: test
name: volume1

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- awsElasticBlockStore:
volumeID: testing
name: volume-awselasticblockstore
volumeID: test
name: volume1

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- flocker:
datasetName: testing
name: volume-flocker
datasetName: test
name: volume1

View File

@ -18,5 +18,5 @@ spec:
volumes:
- fc:
wwids:
- testing
name: volume-fc
- test
name: volume1

View File

@ -17,6 +17,6 @@ spec:
runAsNonRoot: true
volumes:
- azureFile:
secretName: testing
shareName: testing
name: volume-azurefile
secretName: test
shareName: test
name: volume1

View File

@ -16,6 +16,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-vsphere
- name: volume1
vsphereVolume:
volumePath: testing
volumePath: test

View File

@ -16,7 +16,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-quobyte
- name: volume1
quobyte:
registry: localhost:1234
volume: testing
volume: test

View File

@ -17,6 +17,6 @@ spec:
runAsNonRoot: true
volumes:
- azureDisk:
diskName: testing
diskName: test
diskURI: https://test.blob.core.windows.net/test/test.vhd
name: volume-azuredisk
name: volume1

View File

@ -16,7 +16,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-portworxvolume
- name: volume1
portworxVolume:
fsType: ext4
volumeID: testing
volumeID: test

View File

@ -16,9 +16,9 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-scaleio
- name: volume1
scaleIO:
gateway: localhost
secretRef: null
system: testing
volumeName: testing
system: test
volumeName: test

View File

@ -16,6 +16,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-storageos
- name: volume1
storageos:
volumeName: test

View File

@ -18,4 +18,4 @@ spec:
volumes:
- hostPath:
path: /dev/null
name: volume-hostpath
name: volume1

View File

@ -18,4 +18,4 @@ spec:
volumes:
- gitRepo:
repository: github.com/kubernetes/kubernetes
name: volume-gitrepo
name: volume1

View File

@ -16,7 +16,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-nfs
- name: volume1
nfs:
path: /testing
server: testing
path: /test
server: test

View File

@ -19,5 +19,5 @@ spec:
- iscsi:
iqn: iqn.2001-04.com.example:storage.kube.sys1.xyz
lun: 0
targetPortal: testing
name: volume-iscsi
targetPortal: test
name: volume1

View File

@ -17,6 +17,6 @@ spec:
runAsNonRoot: true
volumes:
- glusterfs:
endpoints: testing
path: testing
name: volume-glusterfs
endpoints: test
path: test
name: volume1

View File

@ -16,8 +16,8 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-rbd
- name: volume1
rbd:
image: testing
image: test
monitors:
- testing
- test

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- flexVolume:
driver: testing
name: volume-flexvolume
driver: test
name: volume1

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- cinder:
volumeID: testing
name: volume-cinder
volumeID: test
name: volume1

View File

@ -18,5 +18,5 @@ spec:
volumes:
- cephfs:
monitors:
- testing
name: volume-cephfs
- test
name: volume1

View File

@ -16,23 +16,24 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- configMap:
name: volume-configmap-test
name: volume-configmap
- name: volume0
- emptyDir: {}
name: volume1
- name: volume2
secret:
secretName: test
- name: volume3
persistentVolumeClaim:
claimName: test
- downwardAPI:
items:
- fieldRef:
fieldPath: metadata.labels
path: labels
name: volume-downwardapi
- emptyDir: {}
name: volume-emptydir
- name: volume-pvc
persistentVolumeClaim:
claimName: test
- name: volume-projects
name: volume4
- configMap:
name: test
name: volume5
- name: volume6
projected:
sources: []
- name: volume-secret
secret:
secretName: test

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- gcePersistentDisk:
pdName: testing
name: volume-gcepersistentdisk
pdName: test
name: volume1

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- awsElasticBlockStore:
volumeID: testing
name: volume-awselasticblockstore
volumeID: test
name: volume1

View File

@ -17,5 +17,5 @@ spec:
runAsNonRoot: true
volumes:
- flocker:
datasetName: testing
name: volume-flocker
datasetName: test
name: volume1

View File

@ -18,5 +18,5 @@ spec:
volumes:
- fc:
wwids:
- testing
name: volume-fc
- test
name: volume1

View File

@ -17,6 +17,6 @@ spec:
runAsNonRoot: true
volumes:
- azureFile:
secretName: testing
shareName: testing
name: volume-azurefile
secretName: test
shareName: test
name: volume1

View File

@ -16,6 +16,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-vsphere
- name: volume1
vsphereVolume:
volumePath: testing
volumePath: test

View File

@ -16,7 +16,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-quobyte
- name: volume1
quobyte:
registry: localhost:1234
volume: testing
volume: test

View File

@ -17,6 +17,6 @@ spec:
runAsNonRoot: true
volumes:
- azureDisk:
diskName: testing
diskName: test
diskURI: https://test.blob.core.windows.net/test/test.vhd
name: volume-azuredisk
name: volume1

View File

@ -16,7 +16,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-portworxvolume
- name: volume1
portworxVolume:
fsType: ext4
volumeID: testing
volumeID: test

View File

@ -16,9 +16,9 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-scaleio
- name: volume1
scaleIO:
gateway: localhost
secretRef: null
system: testing
volumeName: testing
system: test
volumeName: test

View File

@ -16,6 +16,6 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-storageos
- name: volume1
storageos:
volumeName: test

View File

@ -18,4 +18,4 @@ spec:
volumes:
- hostPath:
path: /dev/null
name: volume-hostpath
name: volume1

View File

@ -18,4 +18,4 @@ spec:
volumes:
- gitRepo:
repository: github.com/kubernetes/kubernetes
name: volume-gitrepo
name: volume1

View File

@ -16,7 +16,7 @@ spec:
securityContext:
runAsNonRoot: true
volumes:
- name: volume-nfs
- name: volume1
nfs:
path: /testing
server: testing
path: /test
server: test

View File

@ -19,5 +19,5 @@ spec:
- iscsi:
iqn: iqn.2001-04.com.example:storage.kube.sys1.xyz
lun: 0
targetPortal: testing
name: volume-iscsi
targetPortal: test
name: volume1

View File

@ -17,6 +17,6 @@ spec:
runAsNonRoot: true
volumes:
- glusterfs:
endpoints: testing
path: testing
name: volume-glusterfs
endpoints: test
path: test
name: volume1

Some files were not shown because too many files have changed in this diff Show More