policyDefinitions/Kubernetes/enforce-apparmor-profile/examples-good/example_good.yaml (13 lines of code) (raw):
apiVersion: v1
kind: Pod
metadata:
name: nginx-apparmor
annotations:
# Assuming policy applied with allowedProfiles including 'runtime/default'
apparmor.security.beta.kubernetes.io/pod: runtime/default
container.apparmor.security.beta.kubernetes.io/nginx: runtime/default
labels:
app: nginx-apparmor
spec:
containers:
- name: nginx
image: nginx