···664664 },
665665 },
666666 SecurityContext: &corev1.SecurityContext{
667667- Privileged: truePtr, // Still no privileged containers
667667+ Privileged: truePtr, // Still no privileged containers
668668 AllowPrivilegeEscalation: falsePtr, // Still no privilege escalation
669669- ReadOnlyRootFilesystem: falsePtr, // Possible with distroless
669669+ ReadOnlyRootFilesystem: falsePtr, // Possible with distroless
670670 RunAsNonRoot: falsePtr, // Root required for USB
671671 RunAsUser: &rootUserId,
672672 SeccompProfile: &corev1.SeccompProfile{