This is the new AWS CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::Batch::JobDefinition EksContainerSecurityContext
The security context for a job. For more information, see Configure a
    security context for a pod or container
Syntax
To declare this entity in your AWS CloudFormation template, use the following syntax:
JSON
{ "AllowPrivilegeEscalation" :Boolean, "Privileged" :Boolean, "ReadOnlyRootFilesystem" :Boolean, "RunAsGroup" :Integer, "RunAsNonRoot" :Boolean, "RunAsUser" :Integer}
YAML
AllowPrivilegeEscalation:BooleanPrivileged:BooleanReadOnlyRootFilesystem:BooleanRunAsGroup:IntegerRunAsNonRoot:BooleanRunAsUser:Integer
Properties
- AllowPrivilegeEscalation
- 
                    Whether or not a container or a Kubernetes pod is allowed to gain more privileges than its parent process. The default value is false.Required: No Type: Boolean Update requires: No interruption 
- Privileged
- 
                    When this parameter is true, the container is given elevated permissions on the host container instance. The level of permissions are similar to therootuser permissions. The default value isfalse. This parameter maps toprivilegedpolicy in the Privileged pod security policiesin the Kubernetes documentation. Required: No Type: Boolean Update requires: No interruption 
- ReadOnlyRootFilesystem
- 
                    When this parameter is true, the container is given read-only access to its root file system. The default value isfalse. This parameter maps toReadOnlyRootFilesystempolicy in the Volumes and file systems pod security policiesin the Kubernetes documentation. Required: No Type: Boolean Update requires: No interruption 
- RunAsGroup
- 
                    When this parameter is specified, the container is run as the specified group ID ( gid). If this parameter isn't specified, the default is the group that's specified in the image metadata. This parameter maps toRunAsGroupandMustRunAspolicy in the Users and groups pod security policiesin the Kubernetes documentation. Required: No Type: Integer Update requires: No interruption 
- RunAsNonRoot
- 
                    When this parameter is specified, the container is run as a user with a uidother than 0. If this parameter isn't specified, so such rule is enforced. This parameter maps toRunAsUserandMustRunAsNonRootpolicy in the Users and groups pod security policiesin the Kubernetes documentation. Required: No Type: Boolean Update requires: No interruption 
- RunAsUser
- 
                    When this parameter is specified, the container is run as the specified user ID ( uid). If this parameter isn't specified, the default is the user that's specified in the image metadata. This parameter maps toRunAsUserandMustRanAspolicy in the Users and groups pod security policiesin the Kubernetes documentation. Required: No Type: Integer Update requires: No interruption