1 {{- if .Values.rbac.create }}
2 {{- if .Values.rbac.pspEnabled }}
3 apiVersion: extensions/v1beta1
4 kind: PodSecurityPolicy
6 labels: {{ include "prometheus-node-exporter.labels" . | indent 4 }}
7 name: {{ template "prometheus-node-exporter.fullname" . }}
10 # Required to prevent escalations to root.
11 # allowPrivilegeEscalation: false
12 # This is redundant with non-root + disallow privilege escalation,
13 # but we can provide it for defense in depth.
14 #requiredDropCapabilities:
16 # Allow core volume types.
23 - 'persistentVolumeClaim'
32 # Permits the container to run with root privileges as well.
35 # This policy assumes the nodes are using AppArmor rather than SELinux.
40 # Forbid adding the root group.
46 # Forbid adding the root group.
49 readOnlyRootFilesystem: false