codex: Add securityContext to pod

This commit is contained in:
2026-01-15 10:22:42 +01:00
parent 5d6fe5572b
commit 21ec3a04ab

View File

@@ -83,6 +83,15 @@ spec:
envFrom:
- secretRef:
name: azure-keyvault
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- "ALL"
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: "RuntimeDefault"
dnsPolicy: ClusterFirst
restartPolicy: Always
schedulerName: default-scheduler