mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-10 01:46:55 +00:00
21 lines
568 B
YAML
21 lines
568 B
YAML
|
apiVersion: kyverno.io/v2alpha1
|
||
|
kind: ValidatingPolicy
|
||
|
metadata:
|
||
|
name: check-deployment-labels
|
||
|
spec:
|
||
|
matchConstraints:
|
||
|
resourceRules:
|
||
|
- apiGroups: [apps]
|
||
|
apiVersions: [v1]
|
||
|
operations: [CREATE, UPDATE]
|
||
|
resources: [deployments]
|
||
|
variables:
|
||
|
- name: environment
|
||
|
expression: >-
|
||
|
has(object.metadata.labels) && 'env' in object.metadata.labels && object.metadata.labels['env'] == 'prod'
|
||
|
validations:
|
||
|
- expression: >-
|
||
|
variables.environment == true
|
||
|
message: >-
|
||
|
Deployment labels must be env=prod
|