diff --git a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/README.md b/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/README.md deleted file mode 100644 index 59c07abdd1..0000000000 --- a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/README.md +++ /dev/null @@ -1,7 +0,0 @@ -## Description - -This test ensures the PSS checks with the new advanced support on exclusions are applied to the resources successfully. - -## Expected Behavior - -Two pods (`good-pod` & `excluded-pod`) should be created as it follows the baseline:latest `/proc MountType` PSS check and one pod (`bad-pod`) should not be created as it violate the baseline:latest `/proc MountType` PSS check. diff --git a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/bad-pod.yaml b/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/bad-pod.yaml deleted file mode 100644 index 148adde34d..0000000000 --- a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/bad-pod.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: v1 -kind: Pod -metadata: - name: bad-pod -spec: - containers: - - name: nginx1 - image: nginx - args: - - sleep - - 1d - securityContext: - procMount: unknown - initContainers: - - name: nginx1 - image: nginx - args: - - sleep - - 1d - securityContext: - procMount: other diff --git a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/chainsaw-test.yaml b/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/chainsaw-test.yaml deleted file mode 100644 index 1dbb3c4cb1..0000000000 --- a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/chainsaw-test.yaml +++ /dev/null @@ -1,24 +0,0 @@ -apiVersion: chainsaw.kyverno.io/v1alpha1 -kind: Test -metadata: - creationTimestamp: null - name: test-exclusion-procmount -spec: - steps: - - name: step-01 - try: - - apply: - file: policy.yaml - - assert: - file: policy-assert.yaml - - name: step-02 - try: - - apply: - expect: - - check: - ($error != null): true - file: bad-pod.yaml - - apply: - file: excluded-pod.yaml - - apply: - file: good-pod.yaml diff --git a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/excluded-pod.yaml b/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/excluded-pod.yaml deleted file mode 100644 index 5a6a6765a7..0000000000 --- a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/excluded-pod.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: v1 -kind: Pod -metadata: - name: excluded-pod -spec: - containers: - - name: nginx1 - image: nginx - args: - - sleep - - 1d - securityContext: - procMount: foo - initContainers: - - name: nginx2 - image: nginx - args: - - sleep - - 1d - securityContext: - procMount: bar diff --git a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/good-pod.yaml b/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/good-pod.yaml deleted file mode 100644 index 3ddbae6e47..0000000000 --- a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/good-pod.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: v1 -kind: Pod -metadata: - name: good-pod -spec: - containers: - - name: nginx1 - image: nginx - args: - - sleep - - 1d - securityContext: - procMount: default - initContainers: - - name: nginx2 - image: nginx - args: - - sleep - - 1d - securityContext: - procMount: default diff --git a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/policy-assert.yaml b/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/policy-assert.yaml deleted file mode 100644 index 4f48e3a387..0000000000 --- a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/policy-assert.yaml +++ /dev/null @@ -1,9 +0,0 @@ -apiVersion: kyverno.io/v1 -kind: ClusterPolicy -metadata: - name: test-exclusion-procmount -status: - conditions: - - reason: Succeeded - status: "True" - type: Ready diff --git a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/policy.yaml b/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/policy.yaml deleted file mode 100644 index 37c460c781..0000000000 --- a/test/conformance/chainsaw/validate/clusterpolicy/standard/psa/test-exclusion-procmount/policy.yaml +++ /dev/null @@ -1,31 +0,0 @@ -apiVersion: kyverno.io/v1 -kind: ClusterPolicy -metadata: - name: test-exclusion-procmount -spec: - background: true - validationFailureAction: Enforce - rules: - - name: test-exclusion-procmount - match: - any: - - resources: - kinds: - - Pod - validate: - podSecurity: - level: baseline - version: latest - exclude: - - controlName: "/proc Mount Type" - images: - - nginx - restrictedField: "spec.containers[*].securityContext.procMount" - values: - - "foo" - - controlName: "/proc Mount Type" - images: - - nginx - restrictedField: "spec.initContainers[*].securityContext.procMount" - values: - - "bar"