policyDefinitions/Kubernetes/forbidden-sysctl-interfaces/examples-good/example_good.yaml (18 lines of code) (raw):
apiVersion: v1
kind: Pod
metadata:
name: nginx-forbidden-sysctls
labels:
app: nginx-forbidden-sysctls
spec:
containers:
- name: nginx
image: nginx
resources:
limits:
cpu: "100m"
memory: "30Mi"
securityContext:
sysctls:
- name: net.ipv4.ip_local_port_range
value: "65536"