Add pod security labels to managed namespace for Rook-Ceph

This commit is contained in:
Marco van Zijl 2025-11-08 20:13:13 +01:00
parent a851391af3
commit 6094ec5247
2 changed files with 5 additions and 11 deletions

View File

@ -27,3 +27,8 @@ spec:
syncOptions:
- CreateNamespace=true
- ServerSideApply=true
managedNamespaceMetadata:
labels:
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/warn: privileged

View File

@ -22,14 +22,3 @@ rook-ceph:
limits:
cpu: 500m
memory: 512Mi
# Ensure namespace has proper labels for Talos
extraObjects:
- apiVersion: v1
kind: Namespace
metadata:
name: rook-ceph
labels:
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/warn: privileged