diff --git a/ray-operator/config/openshift/ray_operator_scc.yaml b/ray-operator/config/openshift/ray_operator_scc.yaml index 1246a5d57e..601c95de41 100644 --- a/ray-operator/config/openshift/ray_operator_scc.yaml +++ b/ray-operator/config/openshift/ray_operator_scc.yaml @@ -4,6 +4,12 @@ metadata: name: run-as-ray-user seLinuxContext: type: MustRunAs +defaultAllowPrivilegeEscalation: false +allowPrivilegeEscalation: false +seccompProfiles: + - runtime/default +requiredDropCapabilities: + - ALL runAsUser: type: MustRunAs uid: 1000