diff --git a/charts/execution-beacon/templates/statefulset.yaml b/charts/execution-beacon/templates/statefulset.yaml index 0120ba882..0dba834e2 100644 --- a/charts/execution-beacon/templates/statefulset.yaml +++ b/charts/execution-beacon/templates/statefulset.yaml @@ -50,7 +50,15 @@ spec: image: "{{ .Values.global.initImage.repository }}:{{ .Values.global.initImage.tag }}" imagePullPolicy: {{ .Values.global.initImage.pullPolicy }} securityContext: - {{- toYaml .Values.global.securityContext | nindent 12 }} + runAsNonRoot: false + runAsUser: 0 + capabilities: + add: + - CHOWN + - FOWNER + - DAC_OVERRIDE + drop: + - ALL env: - name: POD_IP valueFrom: