diff --git a/cmd/build/helmify/static/values.yaml b/cmd/build/helmify/static/values.yaml index 216bf4274ea..52981ac782b 100644 --- a/cmd/build/helmify/static/values.yaml +++ b/cmd/build/helmify/static/values.yaml @@ -56,7 +56,7 @@ postUpgrade: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -94,7 +94,7 @@ postInstall: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -116,7 +116,7 @@ preUninstall: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -170,7 +170,7 @@ controllerManager: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -203,7 +203,7 @@ audit: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -223,7 +223,7 @@ crds: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 65532 runAsNonRoot: true diff --git a/manifest_staging/charts/gatekeeper/values.yaml b/manifest_staging/charts/gatekeeper/values.yaml index 216bf4274ea..52981ac782b 100644 --- a/manifest_staging/charts/gatekeeper/values.yaml +++ b/manifest_staging/charts/gatekeeper/values.yaml @@ -56,7 +56,7 @@ postUpgrade: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -94,7 +94,7 @@ postInstall: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -116,7 +116,7 @@ preUninstall: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -170,7 +170,7 @@ controllerManager: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -203,7 +203,7 @@ audit: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 999 runAsNonRoot: true @@ -223,7 +223,7 @@ crds: allowPrivilegeEscalation: false capabilities: drop: - - all + - ALL readOnlyRootFilesystem: true runAsGroup: 65532 runAsNonRoot: true