@@ -88,9 +88,6 @@ indexer:
8888 limits :
8989 cpu : 100m
9090 memory : 256Mi
91- securityContext :
92- runAsUser : 1000 # Match Docker image UID (wazuh-indexer user)
93- runAsGroup : 1000 # Match Docker image GID
9491
9592 config :
9693 sslEnabled : true
@@ -129,15 +126,10 @@ indexer:
129126
130127 podSecurityContext :
131128 fsGroup : 1000 # Match Docker image user group
132- runAsUser : 1000 # Match Docker image UID (wazuh-indexer user)
133- runAsGroup : 1000 # Match Docker image GID
134- runAsNonRoot : true # Docker image runs as non-root user
135129
136130 securityContext :
137131 runAsUser : 1000 # Match Docker image UID (wazuh-indexer user)
138132 runAsGroup : 1000 # Match Docker image GID
139- runAsNonRoot : true # Docker image runs as non-root user
140- allowPrivilegeEscalation : false # Security hardening
141133 capabilities :
142134 add : ["SYS_CHROOT"] # Required for OpenSearch/Elasticsearch
143135 # capabilities:
@@ -251,19 +243,12 @@ manager:
251243 master :
252244 podSecurityContext :
253245 fsGroup : 101 # Wazuh group GID (matches Docker image wazuh group)
254- runAsUser : 0 # Docker image runs as root (no USER directive)
255- runAsGroup : 0 # Root group
256- runAsNonRoot : false # Docker image runs as root
257246
258247 podAnnotations : {}
259248
260249 podLabels : {}
261250
262251 securityContext :
263- runAsUser : 0 # Docker image runs as root (no USER directive)
264- runAsGroup : 0 # Root group
265- runAsNonRoot : false # Docker image runs as root
266- allowPrivilegeEscalation : false # Security hardening
267252 capabilities :
268253 add : ["SYS_CHROOT"] # Required for Wazuh manager
269254 # capabilities:
@@ -328,19 +313,12 @@ manager:
328313
329314 podSecurityContext :
330315 fsGroup : 101 # Wazuh group GID (matches Docker image wazuh group)
331- runAsUser : 0 # Docker image runs as root (no USER directive)
332- runAsGroup : 0 # Root group
333- runAsNonRoot : false # Docker image runs as root
334316
335317 podAnnotations : {}
336318
337319 podLabels : {}
338320
339321 securityContext :
340- runAsUser : 0 # Docker image runs as root (no USER directive)
341- runAsGroup : 0 # Root group
342- runAsNonRoot : false # Docker image runs as root
343- allowPrivilegeEscalation : false # Security hardening
344322 capabilities :
345323 add : ["SYS_CHROOT"] # Required for Wazuh manager
346324 # capabilities:
0 commit comments