change kube-webhook create/patch to runAsUser: distroless
explicitly run as 65532 (distroless nonroot user) so kube-webhook works on selinux enforcing systems that don't allow root elevation
UNCLASSIFIED - NO CUI
ATTENTION: Immediate action is required to maintain compatibility with P1 services. Please visit https://p1notifications.dso.mil and see the "DSO.MIL Certificates Renewal" announcement under the "Notifications" section for more details.
explicitly run as 65532 (distroless nonroot user) so kube-webhook works on selinux enforcing systems that don't allow root elevation
UNCLASSIFIED - NO CUI