infra4talos/apps-kustomized/cert-manager-webhook-dnsimple/args.yaml
Martyn Ranyard 5f1893c1a3 add capabilities
Signed-off-by: Martyn Ranyard <m@rtyn.berlin>
2023-10-30 17:39:54 +01:00

18 lines
388 B
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
name: not-important
spec:
template:
spec:
containers:
- name: cert-manager-webhook-dnsimple
sysctls:
- name: "net.ipv4.ip_unprivileged_port_start"
value: "0"
securityContext:
capabilities:
drop:
- "ALL"
add:
- "NET_BIND_SERVICE"