policyDefinitions/Kubernetes/selinux/examples-good/example_good.yaml (20 lines of code) (raw):
apiVersion: v1
kind: Pod
metadata:
name: nginx-selinux
labels:
app: nginx-selinux
spec:
containers:
- name: nginx
image: nginx
securityContext:
seLinuxOptions:
level: s0:c123,c456
user: system_u
role: object_r
type: svirt_sandbox_file_t
resources:
limits:
cpu: "100m"
memory: "30Mi"