docs: document how to use a different security context

This commit is contained in:
Martin Linkhorst 2018-10-02 17:55:21 +02:00
parent 6285b2c38d
commit 8163db497d
No known key found for this signature in database
GPG Key ID: CBE9EF3F75BAA5FD

View File

@ -0,0 +1,32 @@
# Running ExternalDNS with limited privileges
You can run ExternalDNS with reduced privileges since `v0.5.6` using the following `SecurityContext`.
```yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: external-dns
spec:
strategy:
type: Recreate
selector:
matchLabels:
app: external-dns
template:
metadata:
labels:
app: external-dns
spec:
containers:
- name: external-dns
image: registry.opensource.zalan.do/teapot/external-dns:v0.5.6 # minimum version is v0.5.6
args:
- ... # your arguments here
securityContext:
runAsNonRoot: true
runAsUser: 65534
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
```