Summary
EKS clusters with OPA Gatekeeper enforce runAsGroup. Harness supports Pod Spec Overlay for CI stage Kubernetes infrastructure, but Container steps in Custom stages don’t expose Pod Spec Overlay or a runAsGroup field, causing admission failures unless users manually edit YAML per pipeline/step.
Current Behavior
Custom-stage Container step UI exposes Run as User / Run as Non Root / Privileged / Capabilities, but not runAsGroup or Pod Spec Overlay.
Adding podSpecOverlay directly in YAML works, but must be repeated everywhere.
Request
  • Allow a default/inherited Pod Spec Overlay at Kubernetes infrastructure/connector/account/org/project level applied to all K8s step executions (CI + non-CI).