云容器引擎 CCE-PodSecurityPolicy配置:恢复原始Pod安全策略

时间:2023-11-01 16:25:55

恢复原始Pod安全策略

如果您已经修改默认Pod安全策略后,想恢复原始Pod安全策略,请执行以下操作。

  1. 创建一个名为policy.yaml的描述文件。其中,policy.yaml为自定义名称,您可以随意命名。

    vi policy.yaml

    描述文件内容如下。

    apiVersion: policy/v1beta1kind: PodSecurityPolicymetadata:  name: psp-global  annotations:    seccomp.security.alpha.kubernetes.io/allowedProfileNames: '*'spec:  privileged: true  allowPrivilegeEscalation: true  allowedCapabilities:    - '*'  volumes:    - '*'  hostNetwork: true  hostPorts:    - min: 0      max: 65535  hostIPC: true  hostPID: true  runAsUser:    rule: 'RunAsAny'  seLinux:    rule: 'RunAsAny'  supplementalGroups:    rule: 'RunAsAny'  fsGroup:    rule: 'RunAsAny' ---kind: ClusterRoleapiVersion: rbac.authorization.k8s.io/v1metadata:  name: psp-globalrules:  - apiGroups:      - "*"    resources:      - podsecuritypolicies    resourceNames:      - psp-global    verbs:      - use ---apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata:  name: psp-globalroleRef:  kind: ClusterRole  name: psp-global  apiGroup: rbac.authorization.k8s.iosubjects:- kind: Group  name: system:authenticated  apiGroup: rbac.authorization.k8s.io

  2. 执行如下命令:

    kubectl apply -f policy.yaml

support.huaweicloud.com/usermanual-cce/cce_10_0275.html