2025-02-03 13:53:57 +01:00
|
|
|
apiVersion: admissionregistration.k8s.io/v1
|
|
|
|
kind: ValidatingWebhookConfiguration
|
|
|
|
metadata:
|
|
|
|
labels:
|
|
|
|
webhook.kyverno.io/managed-by: kyverno
|
|
|
|
name: kyverno-resource-validating-webhook-cfg
|
|
|
|
webhooks:
|
|
|
|
- admissionReviewVersions:
|
|
|
|
- v1
|
|
|
|
clientConfig:
|
|
|
|
service:
|
|
|
|
name: kyverno-svc
|
|
|
|
namespace: kyverno
|
2025-03-17 20:31:37 +08:00
|
|
|
path: /policies/vpol/validate/fail
|
2025-02-03 13:53:57 +01:00
|
|
|
port: 443
|
|
|
|
failurePolicy: Fail
|
|
|
|
matchPolicy: Equivalent
|
|
|
|
name: vpol.validate.kyverno.svc-fail
|
|
|
|
namespaceSelector: {}
|
|
|
|
objectSelector: {}
|
|
|
|
rules:
|
|
|
|
- apiGroups:
|
|
|
|
- apps
|
|
|
|
apiVersions:
|
|
|
|
- v1
|
|
|
|
operations:
|
|
|
|
- CREATE
|
|
|
|
- UPDATE
|
|
|
|
resources:
|
|
|
|
- deployments
|
|
|
|
scope: '*'
|
|
|
|
- apiGroups:
|
|
|
|
- apps
|
|
|
|
apiVersions:
|
|
|
|
- v1
|
|
|
|
operations:
|
|
|
|
- DELETE
|
|
|
|
resources:
|
|
|
|
- configmaps
|
|
|
|
scope: '*'
|
|
|
|
sideEffects: NoneOnDryRun
|
|
|
|
timeoutSeconds: 10
|