gardener / gardener-extension-provider-azure

Gardener extension controller for the Azure cloud provider (https://azure.microsoft.com).

Home Page:https://gardener.cloud

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Support fsGroupPolicy: File for Pod security context

abbi-gaurav opened this issue · comments

How to categorize this issue?

/area security
/kind enhancement
/platform azure

What would you like to be added:
Provide support for enable fsGroupPolicy: File in the Pod security context.
Comments from Dev
It seems to be enabled by default in newer releases, so as a first estimation it shouldn’t be much effort to do so

Why is this needed:
Better security for the workloads

@abbi-gaurav Label area/todo does not exist.

/assign

Short status update I didn't find the time to look further into it.
I'm planning to have a look into until end of the week.