diff --git a/samples/DisallowNewCapabilities.md b/samples/DisallowNewCapabilities.md index 683d0534f8..d237d5696e 100644 --- a/samples/DisallowNewCapabilities.md +++ b/samples/DisallowNewCapabilities.md @@ -15,6 +15,8 @@ apiVersion: kyverno.io/v1 kind: ClusterPolicy metadata: name: disallow-new-capabilities + annotations: + pod-policies.kyverno.io/autogen-controllers: none spec: rules: - name: validate-add-capabilities diff --git a/samples/DisallowRootUser.md b/samples/DisallowRootUser.md index 3b09a786e1..7d5e991e97 100644 --- a/samples/DisallowRootUser.md +++ b/samples/DisallowRootUser.md @@ -28,8 +28,15 @@ spec: - spec: securityContext: runAsNonRoot: true + - spec: + securityContext: + runAsUser: ">0" - spec: containers: - securityContext: runAsNonRoot: true + - spec: + containers: + - securityContext: + runAsUser: ">0" ````