diff --git a/contrib/spark/spark-operator/base/kustomization.yaml b/contrib/spark/spark-operator/base/kustomization.yaml index d91984f7c..9c628e56e 100644 --- a/contrib/spark/spark-operator/base/kustomization.yaml +++ b/contrib/spark/spark-operator/base/kustomization.yaml @@ -16,11 +16,39 @@ patches: capabilities: drop: ["ALL"] runAsNonRoot: true + runAsUser: 185 + seccompProfile: + type: RuntimeDefault + - target: + kind: Deployment + labelSelector: "app.kubernetes.io/name=spark-operator" + patch: |- + - op: add + path: /spec/template/spec/containers/0/securityContext + value: + allowPrivilegeEscalation: false + capabilities: + drop: ["ALL"] + runAsNonRoot: true + runAsUser: 185 seccompProfile: type: RuntimeDefault - target: kind: Deployment name: spark-operator-webhook + patch: |- + apiVersion: apps/v1 + kind: Deployment + metadata: + name: spark-operator-webhook + spec: + template: + metadata: + annotations: + sidecar.istio.io/inject: "false" + - target: + kind: Deployment + name: spark-operator-controller patch: |- apiVersion: apps/v1 kind: Deployment