apiVersion: v1
kind: Pod
metadata:
name: nginx
spec:
securityContext:
runAsNonRoot: true (1)
seccompProfile:
type: RuntimeDefault (2)
containers:
- image: nginx
name: nginx
volumeMounts:
- mountPath: /var/run/secrets/tokens
name: vault-token
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: [ALL]
serviceAccountName: build-robot (3)
volumes:
- name: vault-token
projected:
sources:
- serviceAccountToken:
path: vault-token (4)
expirationSeconds: 7200 (5)
audience: vault (6)