--- allowHostDirVolumePlugin: false allowHostIPC: false allowHostNetwork: false allowHostPID: false allowHostPorts: false allowPrivilegeEscalation: true allowPrivilegedContainer: false allowedCapabilities: null apiVersion: security.openshift.io/v1 defaultAddCapabilities: null fsGroup: type: RunAsAny groups: [] kind: SecurityContextConstraints metadata: annotations: include.release.openshift.io/ibm-cloud-managed: "true" include.release.openshift.io/self-managed-high-availability: "true" include.release.openshift.io/single-node-developer: "true" kubernetes.io/description: nonroot provides all features of the restricted SCC but allows users to run with any non-root UID. The user must specify the UID or it must be specified on the by the manifest of the container runtime. release.openshift.io/create-only: "true" creationTimestamp: "2025-10-11T10:24:20Z" generation: 1 managedFields: - apiVersion: security.openshift.io/v1 fieldsType: FieldsV1 fieldsV1: f:allowHostDirVolumePlugin: {} f:allowHostIPC: {} f:allowHostNetwork: {} f:allowHostPID: {} f:allowHostPorts: {} f:allowPrivilegeEscalation: {} f:allowPrivilegedContainer: {} f:allowedCapabilities: {} f:defaultAddCapabilities: {} f:fsGroup: .: {} f:type: {} f:groups: {} f:metadata: f:annotations: .: {} f:include.release.openshift.io/ibm-cloud-managed: {} f:include.release.openshift.io/self-managed-high-availability: {} f:include.release.openshift.io/single-node-developer: {} f:kubernetes.io/description: {} f:release.openshift.io/create-only: {} f:priority: {} f:readOnlyRootFilesystem: {} f:requiredDropCapabilities: {} f:runAsUser: .: {} f:type: {} f:seLinuxContext: .: {} f:type: {} f:supplementalGroups: .: {} f:type: {} f:users: {} f:volumes: {} manager: cluster-bootstrap operation: Update time: "2025-10-11T10:24:20Z" name: nonroot resourceVersion: "345" uid: b6509c08-e1a8-49f0-a6c4-b74331af3801 priority: null readOnlyRootFilesystem: false requiredDropCapabilities: - KILL - MKNOD - SETUID - SETGID runAsUser: type: MustRunAsNonRoot seLinuxContext: type: MustRunAs supplementalGroups: type: RunAsAny users: [] volumes: - configMap - csi - downwardAPI - emptyDir - ephemeral - persistentVolumeClaim - projected - secret