Changelog
-
Added: Add securityContext definitions to wait-for-main init containers and task runner sidecar containers
-
Security: Add seccompProfile RuntimeDefault to pod security context (CIS 5.7.2)
-
Security: Enable readOnlyRootFilesystem for all containers with tmp, cache, and data emptyDir volumes and waitContainerSecurityContext (CIS 5.7.3)