forked from alexeisnyk/juice-shop
-
Notifications
You must be signed in to change notification settings - Fork 0
/
privilegedDeployment.yaml
69 lines (69 loc) · 1.78 KB
/
privilegedDeployment.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
apiVersion: apps/v1
kind: Deployment
metadata:
name: snyk-deployment
labels:
app.kubernetes.io/name: snyk-deployment
helm.sh/chart: snyk-deployment-0.1.0
app.kubernetes.io/instance: snyk-deployment
app.kubernetes.io/version: "1.0"
app.kubernetes.io/managed-by: Tiller
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: snyk-deployment
app.kubernetes.io/instance: snyk-deployment
template:
metadata:
labels:
app.kubernetes.io/name: snyk-deployment
app.kubernetes.io/instance: snyk-deployment
spec:
hostPID: true
containers:
- name: snyk-deployment1
image: "orka/snyk-deployment:latest"
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 5000
protocol: TCP
livenessProbe:
httpGet:
path: /
port: http
readinessProbe:
httpGet:
path: /
port: http
- name: snyk-deployment2
image: "orka/snyk-deployment:latest"
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 5000
protocol: TCP
livenessProbe:
httpGet:
path: /
port: http
readinessProbe:
httpGet:
path: /
port: http
resources:
# limits:
# cpu: 100
# memory: 100
securityContext:
privileged: true
capabilities:
# drop:
# - all
add:
- CAP_SYS_ADMIN
volumes:
- name: dockersock
hostPath:
path: /var/run/docker.sock