Skip to main content

KubernetesPodSecurityRule

Resource KubernetesPodSecurityRule in pulumi-portainer.
15 min read

Resource KubernetesPodSecurityRule in pulumi-portainer.

Pulumi type: portainer:index/kubernetesPodSecurityRule:KubernetesPodSecurityRule.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
allowFlexVolumesKubernetesPodSecurityRuleAllowFlexVolumes (input)noWhich FlexVolume drivers are permitted.
allowPrivilegeEscalationbooleannoWhether to block containers that may escalate their privileges.
allowProcMountKubernetesPodSecurityRuleAllowProcMount (input)noWhich proc mount types are permitted.
appArmorKubernetesPodSecurityRuleAppArmor (input)noWhich AppArmor profiles are permitted.
capabilitiesKubernetesPodSecurityRuleCapabilities (input)noWhich Linux capabilities a container may hold.
enabledbooleannoWhether the pod security rule is enforced at all. With this off, the individual sections below are stored but do nothing.
endpointIdnumberyesIdentifier of the Kubernetes environment the rule applies to.
forbiddenSysctlsKubernetesPodSecurityRuleForbiddenSysctls (input)noWhich sysctls a pod may not set.
hostFilesystemKubernetesPodSecurityRuleHostFilesystem (input)noWhich host paths a pod may mount.
hostNamespacesbooleannoWhether to block pods that join the host's namespaces.
hostPortsKubernetesPodSecurityRuleHostPorts (input)noWhich host ports a pod may bind, and whether host networking is allowed at all.
kubernetesPodSecurityRuleIdstringno
privilegedContainersbooleannoWhether to block privileged containers.
readOnlyRootFilesystembooleannoWhether to require a read-only root filesystem.
restrictDefaultNamespacebooleannoWhether to stop workloads being deployed into the default namespace.
restrictSecretsbooleannoWhether to restrict access to secrets.
secCompKubernetesPodSecurityRuleSecComp (input)noWhich seccomp profiles are permitted.
selinuxKubernetesPodSecurityRuleSelinux (input)noWhich SELinux contexts are permitted.
usersKubernetesPodSecurityRuleUsers (input)noWhich user and group identities a pod may run as.
volumeTypesKubernetesPodSecurityRuleVolumeTypes (input)noWhich volume types a pod may use.

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
allowFlexVolumesKubernetesPodSecurityRuleAllowFlexVolumes (output)noWhich FlexVolume drivers are permitted.
allowPrivilegeEscalationbooleannoWhether to block containers that may escalate their privileges.
allowProcMountKubernetesPodSecurityRuleAllowProcMount (output)noWhich proc mount types are permitted.
appArmorKubernetesPodSecurityRuleAppArmor (output)noWhich AppArmor profiles are permitted.
capabilitiesKubernetesPodSecurityRuleCapabilities (output)noWhich Linux capabilities a container may hold.
enabledbooleannoWhether the pod security rule is enforced at all. With this off, the individual sections below are stored but do nothing.
endpointIdnumbernoIdentifier of the Kubernetes environment the rule applies to.
forbiddenSysctlsKubernetesPodSecurityRuleForbiddenSysctls (output)noWhich sysctls a pod may not set.
hostFilesystemKubernetesPodSecurityRuleHostFilesystem (output)noWhich host paths a pod may mount.
hostNamespacesbooleannoWhether to block pods that join the host's namespaces.
hostPortsKubernetesPodSecurityRuleHostPorts (output)noWhich host ports a pod may bind, and whether host networking is allowed at all.
kubernetesPodSecurityRuleIdstringno
privilegedContainersbooleannoWhether to block privileged containers.
readOnlyRootFilesystembooleannoWhether to require a read-only root filesystem.
restrictDefaultNamespacebooleannoWhether to stop workloads being deployed into the default namespace.
restrictSecretsbooleannoWhether to restrict access to secrets.
secCompKubernetesPodSecurityRuleSecComp (output)noWhich seccomp profiles are permitted.
selinuxKubernetesPodSecurityRuleSelinux (output)noWhich SELinux contexts are permitted.
usersKubernetesPodSecurityRuleUsers (output)noWhich user and group identities a pod may run as.
volumeTypesKubernetesPodSecurityRuleVolumeTypes (output)noWhich volume types a pod may use.

KubernetesPodSecurityRuleAllowFlexVolumes (input)#

Input object KubernetesPodSecurityRuleAllowFlexVolumes. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedVolumesstring[]noFlexVolume drivers a pod may use.
enabledbooleannoWhether this section is enforced.

KubernetesPodSecurityRuleAllowProcMount (input)#

Input object KubernetesPodSecurityRuleAllowProcMount. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
enabledbooleannoWhether this section is enforced.
procMountTypestringnoThe proc mount type to permit, for example Default or Unmasked.

KubernetesPodSecurityRuleAppArmor (input)#

Input object KubernetesPodSecurityRuleAppArmor. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
enabledbooleannoWhether this section is enforced.
typesstring[]noAppArmor profiles a pod may use.

KubernetesPodSecurityRuleCapabilities (input)#

Input object KubernetesPodSecurityRuleCapabilities. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedsstring[]noCapabilities a container may add.
enabledbooleannoWhether this section is enforced.
requiredDropsstring[]noCapabilities every container has to drop.

KubernetesPodSecurityRuleForbiddenSysctls (input)#

Input object KubernetesPodSecurityRuleForbiddenSysctls. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
enabledbooleannoWhether this section is enforced.
sysctlsstring[]noSysctls a pod may not set.

KubernetesPodSecurityRuleHostFilesystem (input)#

Input object KubernetesPodSecurityRuleHostFilesystem. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedPathsKubernetesPodSecurityRuleHostFilesystemAllowedPath (input)[]noHost paths a pod may mount. Repeatable.
enabledbooleannoWhether this section is enforced.

KubernetesPodSecurityRuleHostFilesystemAllowedPath (input)#

Input object KubernetesPodSecurityRuleHostFilesystemAllowedPath. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
pathPrefixstringyesPath prefix that may be mounted.
readonlybooleannoWhether the mount has to be read-only.

KubernetesPodSecurityRuleHostPorts (input)#

Input object KubernetesPodSecurityRuleHostPorts. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
enabledbooleannoWhether this section is enforced.
hostNetworkbooleannoWhether a pod may use the host's network namespace.
maxnumbernoHighest host port a pod may bind.
minnumbernoLowest host port a pod may bind.

KubernetesPodSecurityRuleSecComp (input)#

Input object KubernetesPodSecurityRuleSecComp. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
enabledbooleannoWhether this section is enforced.
typesstring[]noSeccomp profiles a pod may use.

KubernetesPodSecurityRuleSelinux (input)#

Input object KubernetesPodSecurityRuleSelinux. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedContextsKubernetesPodSecurityRuleSelinuxAllowedContext (input)[]noSELinux contexts a pod may run under. Repeatable.
enabledbooleannoWhether this section is enforced.

KubernetesPodSecurityRuleSelinuxAllowedContext (input)#

Input object KubernetesPodSecurityRuleSelinuxAllowedContext. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
levelstringnoSELinux level.
rolestringnoSELinux role.
typestringnoSELinux type.
userstringnoSELinux user.

KubernetesPodSecurityRuleUsers (input)#

Input object KubernetesPodSecurityRuleUsers. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
enabledbooleannoWhether this section is enforced.
fsGroupsKubernetesPodSecurityRuleUsersFsGroups (input)noStrategy and ranges for the pod's filesystem groups.
runAsGroupKubernetesPodSecurityRuleUsersRunAsGroup (input)noStrategy and ranges for the group a container runs as.
runAsUserKubernetesPodSecurityRuleUsersRunAsUser (input)noStrategy and ranges for the user a container runs as.
supplementalGroupsKubernetesPodSecurityRuleUsersSupplementalGroups (input)noStrategy and ranges for the pod's supplemental groups.

KubernetesPodSecurityRuleUsersFsGroups (input)#

Input object KubernetesPodSecurityRuleUsersFsGroups. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
idRangesKubernetesPodSecurityRuleUsersFsGroupsIdRange (input)[]noPermitted identifier ranges. Repeatable.
typestringnoStrategy, for example MustRunAs or RunAsAny.

KubernetesPodSecurityRuleUsersFsGroupsIdRange (input)#

Input object KubernetesPodSecurityRuleUsersFsGroupsIdRange. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
maxnumberyesHighest identifier in the range.
minnumberyesLowest identifier in the range.

KubernetesPodSecurityRuleUsersRunAsGroup (input)#

Input object KubernetesPodSecurityRuleUsersRunAsGroup. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
idRangesKubernetesPodSecurityRuleUsersRunAsGroupIdRange (input)[]noPermitted identifier ranges. Repeatable.
typestringnoStrategy, for example MustRunAs or RunAsAny.

KubernetesPodSecurityRuleUsersRunAsGroupIdRange (input)#

Input object KubernetesPodSecurityRuleUsersRunAsGroupIdRange. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
maxnumberyesHighest identifier in the range.
minnumberyesLowest identifier in the range.

KubernetesPodSecurityRuleUsersRunAsUser (input)#

Input object KubernetesPodSecurityRuleUsersRunAsUser. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
idRangesKubernetesPodSecurityRuleUsersRunAsUserIdRange (input)[]noPermitted identifier ranges. Repeatable.
typestringnoStrategy, for example MustRunAs or RunAsAny.

KubernetesPodSecurityRuleUsersRunAsUserIdRange (input)#

Input object KubernetesPodSecurityRuleUsersRunAsUserIdRange. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
maxnumberyesHighest identifier in the range.
minnumberyesLowest identifier in the range.

KubernetesPodSecurityRuleUsersSupplementalGroups (input)#

Input object KubernetesPodSecurityRuleUsersSupplementalGroups. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
idRangesKubernetesPodSecurityRuleUsersSupplementalGroupsIdRange (input)[]noPermitted identifier ranges. Repeatable.
typestringnoStrategy, for example MustRunAs or RunAsAny.

KubernetesPodSecurityRuleUsersSupplementalGroupsIdRange (input)#

Input object KubernetesPodSecurityRuleUsersSupplementalGroupsIdRange. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
maxnumberyesHighest identifier in the range.
minnumberyesLowest identifier in the range.

KubernetesPodSecurityRuleVolumeTypes (input)#

Input object KubernetesPodSecurityRuleVolumeTypes. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedTypesstring[]noVolume types a pod may use, for example configMap or emptyDir.
enabledbooleannoWhether this section is enforced.

KubernetesPodSecurityRuleAllowFlexVolumes (output)#

Output object KubernetesPodSecurityRuleAllowFlexVolumes. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedVolumesstring[]noFlexVolume drivers a pod may use.
enabledbooleannoWhether this section is enforced.

KubernetesPodSecurityRuleAllowProcMount (output)#

Output object KubernetesPodSecurityRuleAllowProcMount. Fields below belong to this object.

PropertyTypeAlways presentDescription
enabledbooleannoWhether this section is enforced.
procMountTypestringnoThe proc mount type to permit, for example Default or Unmasked.

KubernetesPodSecurityRuleAppArmor (output)#

Output object KubernetesPodSecurityRuleAppArmor. Fields below belong to this object.

PropertyTypeAlways presentDescription
enabledbooleannoWhether this section is enforced.
typesstring[]noAppArmor profiles a pod may use.

KubernetesPodSecurityRuleCapabilities (output)#

Output object KubernetesPodSecurityRuleCapabilities. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedsstring[]noCapabilities a container may add.
enabledbooleannoWhether this section is enforced.
requiredDropsstring[]noCapabilities every container has to drop.

KubernetesPodSecurityRuleForbiddenSysctls (output)#

Output object KubernetesPodSecurityRuleForbiddenSysctls. Fields below belong to this object.

PropertyTypeAlways presentDescription
enabledbooleannoWhether this section is enforced.
sysctlsstring[]noSysctls a pod may not set.

KubernetesPodSecurityRuleHostFilesystem (output)#

Output object KubernetesPodSecurityRuleHostFilesystem. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedPathsKubernetesPodSecurityRuleHostFilesystemAllowedPath (output)[]noHost paths a pod may mount. Repeatable.
enabledbooleannoWhether this section is enforced.

KubernetesPodSecurityRuleHostFilesystemAllowedPath (output)#

Output object KubernetesPodSecurityRuleHostFilesystemAllowedPath. Fields below belong to this object.

PropertyTypeAlways presentDescription
pathPrefixstringyesPath prefix that may be mounted.
readonlybooleannoWhether the mount has to be read-only.

KubernetesPodSecurityRuleHostPorts (output)#

Output object KubernetesPodSecurityRuleHostPorts. Fields below belong to this object.

PropertyTypeAlways presentDescription
enabledbooleannoWhether this section is enforced.
hostNetworkbooleannoWhether a pod may use the host's network namespace.
maxnumbernoHighest host port a pod may bind.
minnumbernoLowest host port a pod may bind.

KubernetesPodSecurityRuleSecComp (output)#

Output object KubernetesPodSecurityRuleSecComp. Fields below belong to this object.

PropertyTypeAlways presentDescription
enabledbooleannoWhether this section is enforced.
typesstring[]noSeccomp profiles a pod may use.

KubernetesPodSecurityRuleSelinux (output)#

Output object KubernetesPodSecurityRuleSelinux. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedContextsKubernetesPodSecurityRuleSelinuxAllowedContext (output)[]noSELinux contexts a pod may run under. Repeatable.
enabledbooleannoWhether this section is enforced.

KubernetesPodSecurityRuleSelinuxAllowedContext (output)#

Output object KubernetesPodSecurityRuleSelinuxAllowedContext. Fields below belong to this object.

PropertyTypeAlways presentDescription
levelstringnoSELinux level.
rolestringnoSELinux role.
typestringnoSELinux type.
userstringnoSELinux user.

KubernetesPodSecurityRuleUsers (output)#

Output object KubernetesPodSecurityRuleUsers. Fields below belong to this object.

PropertyTypeAlways presentDescription
enabledbooleannoWhether this section is enforced.
fsGroupsKubernetesPodSecurityRuleUsersFsGroups (output)noStrategy and ranges for the pod's filesystem groups.
runAsGroupKubernetesPodSecurityRuleUsersRunAsGroup (output)noStrategy and ranges for the group a container runs as.
runAsUserKubernetesPodSecurityRuleUsersRunAsUser (output)noStrategy and ranges for the user a container runs as.
supplementalGroupsKubernetesPodSecurityRuleUsersSupplementalGroups (output)noStrategy and ranges for the pod's supplemental groups.

KubernetesPodSecurityRuleUsersFsGroups (output)#

Output object KubernetesPodSecurityRuleUsersFsGroups. Fields below belong to this object.

PropertyTypeAlways presentDescription
idRangesKubernetesPodSecurityRuleUsersFsGroupsIdRange (output)[]noPermitted identifier ranges. Repeatable.
typestringnoStrategy, for example MustRunAs or RunAsAny.

KubernetesPodSecurityRuleUsersFsGroupsIdRange (output)#

Output object KubernetesPodSecurityRuleUsersFsGroupsIdRange. Fields below belong to this object.

PropertyTypeAlways presentDescription
maxnumberyesHighest identifier in the range.
minnumberyesLowest identifier in the range.

KubernetesPodSecurityRuleUsersRunAsGroup (output)#

Output object KubernetesPodSecurityRuleUsersRunAsGroup. Fields below belong to this object.

PropertyTypeAlways presentDescription
idRangesKubernetesPodSecurityRuleUsersRunAsGroupIdRange (output)[]noPermitted identifier ranges. Repeatable.
typestringnoStrategy, for example MustRunAs or RunAsAny.

KubernetesPodSecurityRuleUsersRunAsGroupIdRange (output)#

Output object KubernetesPodSecurityRuleUsersRunAsGroupIdRange. Fields below belong to this object.

PropertyTypeAlways presentDescription
maxnumberyesHighest identifier in the range.
minnumberyesLowest identifier in the range.

KubernetesPodSecurityRuleUsersRunAsUser (output)#

Output object KubernetesPodSecurityRuleUsersRunAsUser. Fields below belong to this object.

PropertyTypeAlways presentDescription
idRangesKubernetesPodSecurityRuleUsersRunAsUserIdRange (output)[]noPermitted identifier ranges. Repeatable.
typestringnoStrategy, for example MustRunAs or RunAsAny.

KubernetesPodSecurityRuleUsersRunAsUserIdRange (output)#

Output object KubernetesPodSecurityRuleUsersRunAsUserIdRange. Fields below belong to this object.

PropertyTypeAlways presentDescription
maxnumberyesHighest identifier in the range.
minnumberyesLowest identifier in the range.

KubernetesPodSecurityRuleUsersSupplementalGroups (output)#

Output object KubernetesPodSecurityRuleUsersSupplementalGroups. Fields below belong to this object.

PropertyTypeAlways presentDescription
idRangesKubernetesPodSecurityRuleUsersSupplementalGroupsIdRange (output)[]noPermitted identifier ranges. Repeatable.
typestringnoStrategy, for example MustRunAs or RunAsAny.

KubernetesPodSecurityRuleUsersSupplementalGroupsIdRange (output)#

Output object KubernetesPodSecurityRuleUsersSupplementalGroupsIdRange. Fields below belong to this object.

PropertyTypeAlways presentDescription
maxnumberyesHighest identifier in the range.
minnumberyesLowest identifier in the range.

KubernetesPodSecurityRuleVolumeTypes (output)#

Output object KubernetesPodSecurityRuleVolumeTypes. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedTypesstring[]noVolume types a pod may use, for example configMap or emptyDir.
enabledbooleannoWhether this section is enforced.