File tree Expand file tree Collapse file tree 10 files changed +165
-0
lines changed
bundle/tests/scorecard/kuttl/security-context Expand file tree Collapse file tree 10 files changed +165
-0
lines changed Original file line number Diff line number Diff line change
1
+ apiVersion : kuttl.dev/v1beta1
2
+ kind : TestAssert
3
+ timeout : 60
4
+ ---
5
+ # Check the default security context
6
+ apiVersion : apps/v1
7
+ kind : Deployment
8
+ metadata :
9
+ name : security-context-rc
10
+ spec :
11
+ template :
12
+ spec :
13
+ containers :
14
+ - name : app
15
+ securityContext :
16
+ allowPrivilegeEscalation : false
17
+ capabilities :
18
+ drop :
19
+ - ALL
20
+ privileged : false
21
+ readOnlyRootFilesystem : false
22
+ runAsNonRoot : true
23
+ status :
24
+ replicas : 1
25
+ readyReplicas : 1
26
+ updatedReplicas : 1
Original file line number Diff line number Diff line change
1
+ apiVersion : rc.app.stacks/v1beta2
2
+ kind : RuntimeComponent
3
+ metadata :
4
+ name : security-context-rc
5
+ spec :
6
+ applicationImage : k8s.gcr.io/pause:2.0
7
+ replicas : 1
Original file line number Diff line number Diff line change
1
+ apiVersion : kuttl.dev/v1beta1
2
+ kind : TestAssert
3
+ timeout : 60
4
+ ---
5
+ apiVersion : apps/v1
6
+ kind : Deployment
7
+ metadata :
8
+ name : security-context-rc
9
+ spec :
10
+ template :
11
+ spec :
12
+ containers :
13
+ - name : app
14
+ securityContext :
15
+ allowPrivilegeEscalation : true
16
+ readOnlyRootFilesystem : true
17
+ runAsNonRoot : false
18
+ status :
19
+ replicas : 1
20
+ readyReplicas : 1
21
+ availableReplicas : 1
Original file line number Diff line number Diff line change
1
+ apiVersion : rc.app.stacks/v1beta2
2
+ kind : RuntimeComponent
3
+ metadata :
4
+ name : security-context-rc
5
+ spec :
6
+ applicationImage : k8s.gcr.io/pause:2.0
7
+ replicas : 1
8
+ securityContext :
9
+ allowPrivilegeEscalation : true
10
+ readOnlyRootFilesystem : true
11
+ runAsNonRoot : false
Original file line number Diff line number Diff line change
1
+ apiVersion : kuttl.dev/v1beta1
2
+ kind : TestAssert
3
+ timeout : 60
4
+ ---
5
+ apiVersion : apps/v1
6
+ kind : Deployment
7
+ metadata :
8
+ name : security-context-rc
9
+ spec :
10
+ template :
11
+ spec :
12
+ containers :
13
+ - name : app
14
+ securityContext :
15
+ privileged : true
16
+ status :
17
+ replicas : 1
18
+ readyReplicas : 1
19
+ availableReplicas : 1
Original file line number Diff line number Diff line change
1
+ apiVersion : rc.app.stacks/v1beta2
2
+ kind : RuntimeComponent
3
+ metadata :
4
+ name : security-context-rc
5
+ spec :
6
+ applicationImage : k8s.gcr.io/pause:2.0
7
+ replicas : 1
8
+ securityContext :
9
+ privileged : true
Original file line number Diff line number Diff line change
1
+ apiVersion : kuttl.dev/v1beta1
2
+ kind : TestAssert
3
+ timeout : 60
4
+ ---
5
+ apiVersion : apps/v1
6
+ kind : Deployment
7
+ metadata :
8
+ name : security-context-rc
9
+ spec :
10
+ template :
11
+ spec :
12
+ containers :
13
+ - name : app
14
+ securityContext :
15
+ capabilities :
16
+ add :
17
+ - NET_ADMIN
18
+ - SYS_TIME
19
+ status :
20
+ replicas : 1
21
+ readyReplicas : 1
22
+ availableReplicas : 1
Original file line number Diff line number Diff line change
1
+ apiVersion : rc.app.stacks/v1beta2
2
+ kind : RuntimeComponent
3
+ metadata :
4
+ name : security-context-rc
5
+ spec :
6
+ applicationImage : k8s.gcr.io/pause:2.0
7
+ replicas : 1
8
+ securityContext :
9
+ capabilities :
10
+ add :
11
+ - NET_ADMIN
12
+ - SYS_TIME
Original file line number Diff line number Diff line change
1
+ apiVersion : kuttl.dev/v1beta1
2
+ kind : TestAssert
3
+ timeout : 60
4
+ ---
5
+ apiVersion : apps/v1
6
+ kind : Deployment
7
+ metadata :
8
+ name : security-context-rc
9
+ spec :
10
+ template :
11
+ spec :
12
+ containers :
13
+ - name : app
14
+ securityContext :
15
+ allowPrivilegeEscalation : false
16
+ capabilities :
17
+ drop :
18
+ - ALL
19
+ privileged : false
20
+ readOnlyRootFilesystem : false
21
+ runAsNonRoot : true
22
+ status :
23
+ replicas : 1
24
+ readyReplicas : 1
25
+ updatedReplicas : 1
Original file line number Diff line number Diff line change
1
+ apiVersion : rc.app.stacks/v1beta2
2
+ kind : RuntimeComponent
3
+ metadata :
4
+ name : security-context-rc
5
+ spec :
6
+ applicationImage : k8s.gcr.io/pause:2.0
7
+ replicas : 1
8
+ securityContext :
9
+ allowPrivilegeEscalation : null
10
+ capabilities : null
11
+ privileged : null
12
+ readOnlyRootFilesystem : null
13
+ runAsNonRoot : null
You can’t perform that action at this time.
0 commit comments