apiVersion: extensions/v1beta1 kind: PodSecurityPolicy metadata: name: gce.persistent-volume-binder annotations: kubernetes.io/description: 'Policy used by the persistent-volume-binder (a.k.a. persistentvolume-controller) to run recycler pods.' # TODO: This should use the default seccomp profile. seccomp.security.alpha.kubernetes.io/allowedProfileNames: '*' labels: kubernetes.io/cluster-service: 'true' addonmanager.kubernetes.io/mode: Reconcile spec: privileged: false volumes: - 'nfs' - 'secret' # Required for service account credentials. hostNetwork: false hostIPC: false hostPID: false runAsUser: rule: 'RunAsAny' seLinux: rule: 'RunAsAny' supplementalGroups: rule: 'RunAsAny' fsGroup: rule: 'RunAsAny' readOnlyRootFilesystem: false