When using Pod Security Admission in the Agents namespace
with the restricted Pod Security Standard, the
jnlp container cannot be scheduled without overriding its container definition with a securityContext.
This option allows to automatically inject in the jnlp container a securityContext that is suitable for the use
of the restricted Pod Security Standard.
This is the securityContext that will be used for the jnlp container with that option:
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault