华为云UCS-k8spspapparmor:符合策略实例的资源定义

时间:2024-09-12 15:06:02

符合策略实例的资源定义

示例中apparmor的值在上述定义的允许范围内,符合策略实例。

apiVersion: v1
kind: Pod
metadata:
  name: nginx-apparmor-allowed
  annotations:
    # apparmor.security.beta.kubernetes.io/pod: unconfined # runtime/default
    container.apparmor.security.beta.kubernetes.io/nginx: runtime/default
  labels:
    app: nginx-apparmor
spec:
  containers:
  - name: nginx
    image: nginx
support.huaweicloud.com/usermanual-ucs/ucs_01_0229.html