policyDefinitions/Kubernetes/selinux/examples-good/example_good.yaml (20 lines of code) (raw):

apiVersion: v1 kind: Pod metadata: name: nginx-selinux labels: app: nginx-selinux spec: containers: - name: nginx image: nginx securityContext: seLinuxOptions: level: s0:c123,c456 user: system_u role: object_r type: svirt_sandbox_file_t resources: limits: cpu: "100m" memory: "30Mi"