diff --git a/bindata/kube-proxy/000-ns.yaml b/bindata/kube-proxy/000-ns.yaml index b5621ff36e..25594476bd 100644 --- a/bindata/kube-proxy/000-ns.yaml +++ b/bindata/kube-proxy/000-ns.yaml @@ -6,6 +6,9 @@ metadata: name: openshift-kube-proxy openshift.io/run-level: "0" openshift.io/cluster-monitoring: "true" + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/warn: privileged annotations: openshift.io/node-selector: "" #override default node selector openshift.io/description: "kubernetes service proxy" diff --git a/bindata/network/kuryr/000-ns.yaml b/bindata/network/kuryr/000-ns.yaml index 0ffa026f3a..23b21efe6a 100644 --- a/bindata/network/kuryr/000-ns.yaml +++ b/bindata/network/kuryr/000-ns.yaml @@ -6,6 +6,9 @@ metadata: name: openshift-kuryr openshift.io/run-level: "0" openshift.io/cluster-monitoring: "true" + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/warn: privileged annotations: openshift.io/node-selector: "" #override default node selector openshift.io/description: "Kuryr-Kubernetes components" diff --git a/bindata/network/multus/000-ns.yaml b/bindata/network/multus/000-ns.yaml index 477c561829..aefa14c624 100644 --- a/bindata/network/multus/000-ns.yaml +++ b/bindata/network/multus/000-ns.yaml @@ -10,3 +10,6 @@ metadata: openshift.io/node-selector: "" #override default node selector openshift.io/description: "Multus network plugin components" workload.openshift.io/allowed: "management" + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/warn: privileged diff --git a/bindata/network/openshift-sdn/000-ns.yaml b/bindata/network/openshift-sdn/000-ns.yaml index 80f672676a..96fc72982f 100644 --- a/bindata/network/openshift-sdn/000-ns.yaml +++ b/bindata/network/openshift-sdn/000-ns.yaml @@ -10,3 +10,6 @@ metadata: openshift.io/node-selector: "" #override default node selector openshift.io/description: "OpenShift SDN components" workload.openshift.io/allowed: "management" + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/warn: privileged diff --git a/bindata/network/ovn-kubernetes/000-ns.yaml b/bindata/network/ovn-kubernetes/000-ns.yaml index 18b65317e5..a05fc7ae91 100644 --- a/bindata/network/ovn-kubernetes/000-ns.yaml +++ b/bindata/network/ovn-kubernetes/000-ns.yaml @@ -6,6 +6,9 @@ metadata: labels: openshift.io/run-level: "0" openshift.io/cluster-monitoring: "true" + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/warn: privileged annotations: openshift.io/node-selector: "" openshift.io/description: "OVN Kubernetes components" diff --git a/manifests/0000_70_cluster-network-operator_00_namespace.yaml b/manifests/0000_70_cluster-network-operator_00_namespace.yaml index 68aa01cdec..6a046c1dd3 100644 --- a/manifests/0000_70_cluster-network-operator_00_namespace.yaml +++ b/manifests/0000_70_cluster-network-operator_00_namespace.yaml @@ -11,3 +11,6 @@ metadata: labels: name: openshift-network-operator openshift.io/run-level: "0" + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/warn: privileged