2025-02-11 19:05:22 +02:00
|
|
|
apiVersion: policies.kyverno.io/v1alpha1
|
2025-02-04 10:22:43 +01:00
|
|
|
kind: ValidatingPolicy
|
|
|
|
metadata:
|
|
|
|
name: check-deployment-labels
|
|
|
|
spec:
|
|
|
|
matchConstraints:
|
|
|
|
resourceRules:
|
|
|
|
- apiGroups: [apps]
|
|
|
|
apiVersions: [v1]
|
|
|
|
operations: [CREATE, UPDATE]
|
|
|
|
resources: [deployments]
|
|
|
|
variables:
|
|
|
|
- name: image
|
|
|
|
expression: >-
|
2025-03-17 16:53:32 +01:00
|
|
|
resource.GetImageData("ghcr.io/kyverno/kyverno:latest")
|
2025-02-04 10:22:43 +01:00
|
|
|
- name: accept
|
|
|
|
expression: >-
|
|
|
|
variables.image != null
|
|
|
|
validations:
|
|
|
|
- expression: >-
|
|
|
|
variables.accept
|
|
|
|
message: >-
|
|
|
|
Deployment must be accepted
|