From 53b36cf98c9ab9b73f7203f2c426e7d0a352b880 Mon Sep 17 00:00:00 2001 From: Sachin Sampras M Date: Thu, 17 Sep 2026 12:05:41 +0100 Subject: [PATCH] fix: harden operator manager pod with readOnlyRootFilesystem and resource limits Add readOnlyRootFilesystem: true to the manager container SecurityContext to meet restricted Pod Security Standards and prevent filesystem tampering. Set resource requests/limits (CPU 10m/500m, Memory 64Mi/256Mi) to prevent unbounded resource consumption. Signed-off-by: Sachin Sampras M --- config/manager/manager.yaml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/config/manager/manager.yaml b/config/manager/manager.yaml index ad9b58c1..7481ffba 100644 --- a/config/manager/manager.yaml +++ b/config/manager/manager.yaml @@ -73,6 +73,7 @@ spec: ports: [] securityContext: allowPrivilegeEscalation: false + readOnlyRootFilesystem: true capabilities: drop: - "ALL" @@ -90,7 +91,13 @@ spec: periodSeconds: 10 # TODO(user): Configure the resources accordingly based on the project requirements. # More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ - resources: {} + resources: + requests: + cpu: 10m + memory: 64Mi + limits: + cpu: 500m + memory: 256Mi volumeMounts: [] volumes: [] serviceAccountName: controller-manager