apiVersion: apps/v1 kind: Deployment metadata: name: kms-deployment labels: app: kms spec: replicas: 1 selector: matchLabels: app: kms template: metadata: labels: app: kms spec: containers: - name: kms image: teddysun/kms ports: - containerPort: 1688 resources: requests: cpu: "100m" memory: "128Mi" limits: cpu: "500m" memory: "512Mi" securityContext: runAsNonRoot: true runAsUser: 1000