Kubernetes cluster is present in Azure (AKS). Deployed CONFLUENCE and BITBUCKET using HEM CHARTS.
We are security hardening the pods in our cluster.
Running the following command shows BITBUCKET and CONFLUENCE pods violate the PodSecurity enforcement.
kubectl label --dry-run=server --overwrite ns --all pod-security.kubernetes.io/enforce=restricted
Result of the above is as follows:
Warning: bitbucket-0 (and 4 other pods): allowPrivilegeEscalation != false, unrestricted capabilities, runAsNonRoot != true, seccompProfile
Warning: confluence-0 (and 1 other pod): allowPrivilegeEscalation != false, unrestricted capabilities, runAsNonRoot != true, runAsUser=0, seccompProfile
The following HELM config values break the POD completely. POD goes into error state and will not run at all.
confluence:
containerSecurityContext:
capabilities:
drop:
- ALL
runAsNonRoot: true
What are the HELM config values to enforce POD security hardening?
Any help is highly appreciated.
Thanks in advance.