华为云UCS-k8spspforbiddensysctls:不符合策略实例的资源定义

时间:2024-09-12 15:06:02

不符合策略实例的资源定义

示例中sysctls的name(kernel.msgmax)不符合策略实例。

apiVersion: v1
kind: Pod
metadata:
  name: nginx-forbidden-sysctls-disallowed
  labels:
    app: nginx-forbidden-sysctls
spec:
  containers:
    - name: nginx
      image: nginx
  securityContext:
    sysctls:
      - name: kernel.msgmax
        value: "65536"
      - name: net.core.somaxconn
        value: "1024"
support.huaweicloud.com/usermanual-ucs/ucs_01_0226.html