From 2cf1eb1a241f99e88451fcc166bb399e3527a52c Mon Sep 17 00:00:00 2001 From: sysdig Date: Fri, 16 Aug 2024 01:34:31 +0000 Subject: [PATCH] * Sysdig - remediate load-gen for control "Container with writable root file system" --- sock-shop/loadgen.yaml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/sock-shop/loadgen.yaml b/sock-shop/loadgen.yaml index b68cbb3..a0eb70f 100644 --- a/sock-shop/loadgen.yaml +++ b/sock-shop/loadgen.yaml @@ -33,4 +33,6 @@ spec: memory: 200Mi requests: cpu: 100m - memory: 50Mi \ No newline at end of file + memory: 50Mi + securityContext: + readOnlyRootFilesystem: true