- Set memory request to 1Gi - Set memory limit to 2Gi
- Set runAsNonRoot and runAsUser to 65534 (nobody) - Disable privilege escalation - Drop all Linux capabilities - Use RuntimeDefault seccomp profile - Applies to both migration job and main deployment