mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-31 03:45:17 +00:00
19 lines
473 B
YAML
19 lines
473 B
YAML
|
apiVersion: policies.kyverno.io/v1alpha1
|
||
|
kind: ValidatingPolicy
|
||
|
metadata:
|
||
|
name: disallow-host-path
|
||
|
spec:
|
||
|
matchConstraints:
|
||
|
resourceRules:
|
||
|
- apiGroups: [""]
|
||
|
apiVersions: ["v1"]
|
||
|
operations: ["CREATE", "UPDATE"]
|
||
|
resources: ["pods"]
|
||
|
variables:
|
||
|
- name: cm
|
||
|
expression: >-
|
||
|
context.GetConfigMap(object.metadata.namespace, "policy-cm")
|
||
|
validations:
|
||
|
- expression: >-
|
||
|
object.metadata.name == variables.cm.data.name
|