mirror of https://github.com/linkerd/linkerd2.git
The patch provided by @ihcsim applies correct values for the securityContext during injection, namely: `allowPrivilegeEscalation = false`, `readOnlyRootFilesystem = true`, and the capabilities are copied from the primary container. Additionally, the proxy-init container securityContext has been updated with appropriate values. Signed-off-by: Cody Vandermyn <cody.vandermyn@nordstrom.com> |
||
---|---|---|
.. | ||
api | ||
cmd | ||
gen | ||
identity | ||
k8s | ||
proxy-injector | ||
script | ||
sp-validator | ||
tap | ||
webhook | ||
Dockerfile |