add capabilities
Signed-off-by: Martyn Ranyard <m@rtyn.berlin>
This commit is contained in:
parent
3b8fccd8cf
commit
5f1893c1a3
|
@ -10,3 +10,9 @@ spec:
|
||||||
sysctls:
|
sysctls:
|
||||||
- name: "net.ipv4.ip_unprivileged_port_start"
|
- name: "net.ipv4.ip_unprivileged_port_start"
|
||||||
value: "0"
|
value: "0"
|
||||||
|
securityContext:
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- "ALL"
|
||||||
|
add:
|
||||||
|
- "NET_BIND_SERVICE"
|
||||||
|
|
Loading…
Reference in New Issue