1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-05 15:37:19 +00:00

fix: do not exclude kube-system service accounts by default (#7225)

Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
This commit is contained in:
Charles-Edouard Brétéché 2023-05-18 00:23:30 +02:00 committed by GitHub
parent d99c000b17
commit 6cf0f36339
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
3 changed files with 5 additions and 7 deletions

View file

@ -258,8 +258,8 @@ The chart values are organised per component.
| config.annotations | object | `{}` | Additional annotations to add to the configmap. | | config.annotations | object | `{}` | Additional annotations to add to the configmap. |
| config.enableDefaultRegistryMutation | bool | `true` | Enable registry mutation for container images. Enabled by default. | | config.enableDefaultRegistryMutation | bool | `true` | Enable registry mutation for container images. Enabled by default. |
| config.defaultRegistry | string | `"docker.io"` | The registry hostname used for the image mutation. | | config.defaultRegistry | string | `"docker.io"` | The registry hostname used for the image mutation. |
| config.excludeGroups | list | `["system:serviceaccounts:kube-system","system:nodes"]` | Exclude groups | | config.excludeGroups | list | `["system:nodes"]` | Exclude groups |
| config.excludeUsernames | list | `["!system:kube-scheduler"]` | Exclude usernames | | config.excludeUsernames | list | `[]` | Exclude usernames |
| config.excludeRoles | list | `[]` | Exclude roles | | config.excludeRoles | list | `[]` | Exclude roles |
| config.excludeClusterRoles | list | `[]` | Exclude roles | | config.excludeClusterRoles | list | `[]` | Exclude roles |
| config.generateSuccessEvents | bool | `false` | Generate success events. | | config.generateSuccessEvents | bool | `false` | Generate success events. |

View file

@ -55,12 +55,11 @@ config:
# -- Exclude groups # -- Exclude groups
excludeGroups: excludeGroups:
- system:serviceaccounts:kube-system
- system:nodes - system:nodes
# -- Exclude usernames # -- Exclude usernames
excludeUsernames: excludeUsernames: []
- '!system:kube-scheduler' # - '!system:kube-scheduler'
# -- Exclude roles # -- Exclude roles
excludeRoles: [] excludeRoles: []

View file

@ -76,8 +76,7 @@ data:
enableDefaultRegistryMutation: "true" enableDefaultRegistryMutation: "true"
defaultRegistry: "docker.io" defaultRegistry: "docker.io"
generateSuccessEvents: "false" generateSuccessEvents: "false"
excludeGroups: "system:serviceaccounts:kube-system,system:nodes" excludeGroups: "system:nodes"
excludeUsernames: "!system:kube-scheduler"
resourceFilters: >- resourceFilters: >-
[*/*,kyverno,*] [*/*,kyverno,*]
[Event,*,*] [Event,*,*]