1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-05 07:26:55 +00:00

Tag v1.7.5 (#4874)

Signed-off-by: ShutingZhao <shuting@nirmata.com>

Signed-off-by: ShutingZhao <shuting@nirmata.com>
This commit is contained in:
shuting 2022-10-11 20:52:12 +08:00 committed by GitHub
parent 925d5fcddd
commit 6e430a7ca7
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
9 changed files with 149 additions and 97 deletions

View file

@ -1,8 +1,8 @@
apiVersion: v2
type: application
name: kyverno-policies
version: v2.5.4
appVersion: v1.7.4
version: v2.5.5
appVersion: v1.7.5
icon: https://github.com/kyverno/kyverno/raw/main/img/logo.png
description: Kubernetes Pod Security Standards implemented as Kyverno policies
keywords:

View file

@ -2,7 +2,7 @@
Kubernetes Pod Security Standards implemented as Kyverno policies
![Version: v2.5.4](https://img.shields.io/badge/Version-v2.5.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v1.7.4](https://img.shields.io/badge/AppVersion-v1.7.4-informational?style=flat-square)
![Version: v2.5.5](https://img.shields.io/badge/Version-v2.5.5-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v1.7.5](https://img.shields.io/badge/AppVersion-v1.7.5-informational?style=flat-square)
## About

View file

@ -1,8 +1,8 @@
apiVersion: v2
type: application
name: kyverno
version: v2.5.4
appVersion: v1.7.4
version: v2.5.5
appVersion: v1.7.5
icon: https://github.com/kyverno/kyverno/raw/main/img/logo.png
description: Kubernetes Native Policy Management
keywords:

View file

@ -2,7 +2,7 @@
Kubernetes Native Policy Management
![Version: v2.5.4](https://img.shields.io/badge/Version-v2.5.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v1.7.4](https://img.shields.io/badge/AppVersion-v1.7.4-informational?style=flat-square)
![Version: v2.5.5](https://img.shields.io/badge/Version-v2.5.5-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v1.7.5](https://img.shields.io/badge/AppVersion-v1.7.5-informational?style=flat-square)
## About

View file

@ -12,7 +12,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: clusterpolicies.kyverno.io
spec:
group: kyverno.io
@ -1643,7 +1643,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: clusterpolicyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -1913,7 +1913,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: clusterreportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -2183,7 +2183,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: generaterequests.kyverno.io
spec:
group: kyverno.io
@ -2358,7 +2358,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: policies.kyverno.io
spec:
group: kyverno.io
@ -3989,7 +3989,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: policyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -4259,7 +4259,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: reportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -4529,7 +4529,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: updaterequests.kyverno.io
spec:
group: kyverno.io

View file

@ -7,7 +7,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno
---
apiVersion: apiextensions.k8s.io/v1
@ -21,7 +21,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: clusterpolicies.kyverno.io
spec:
group: kyverno.io
@ -2608,7 +2608,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: clusterpolicyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -2974,7 +2974,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: clusterreportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -3340,7 +3340,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: generaterequests.kyverno.io
spec:
group: kyverno.io
@ -3530,7 +3530,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: policies.kyverno.io
spec:
group: kyverno.io
@ -6119,7 +6119,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: policyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -6484,7 +6484,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: reportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -6850,7 +6850,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: updaterequests.kyverno.io
spec:
group: kyverno.io
@ -7239,7 +7239,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno-service-account
namespace: kyverno
---
@ -7252,7 +7252,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:leaderelection
namespace: kyverno
rules:
@ -7286,7 +7286,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-generaterequest
rules:
@ -7312,7 +7312,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-policies
rules:
@ -7339,7 +7339,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-policyreport
rules:
@ -7366,7 +7366,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-reportchangerequest
rules:
@ -7393,7 +7393,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:events
rules:
- apiGroups:
@ -7415,7 +7415,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:generate
rules:
- apiGroups:
@ -7462,7 +7462,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:policies
rules:
- apiGroups:
@ -7515,7 +7515,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:userinfo
rules:
- apiGroups:
@ -7538,7 +7538,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:view
rules:
- apiGroups:
@ -7559,7 +7559,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:webhook
rules:
- apiGroups:
@ -7585,7 +7585,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:leaderelection
namespace: kyverno
roleRef:
@ -7606,7 +7606,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:events
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7626,7 +7626,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:generate
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7646,7 +7646,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:policies
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7666,7 +7666,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:userinfo
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7686,7 +7686,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:view
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7706,7 +7706,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:webhook
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7731,7 +7731,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno
namespace: kyverno
---
@ -7747,7 +7747,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno-metrics
namespace: kyverno
---
@ -7760,7 +7760,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno-svc
namespace: kyverno
spec:
@ -7781,7 +7781,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno-svc-metrics
namespace: kyverno
spec:
@ -7802,7 +7802,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno
namespace: kyverno
spec:
@ -7824,7 +7824,7 @@ spec:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
spec:
affinity:
podAntiAffinity:
@ -7859,7 +7859,7 @@ spec:
value: kyverno-svc
- name: TUF_ROOT
value: /.sigstore
image: ghcr.io/kyverno/kyverno:v1.7.4
image: ghcr.io/kyverno/kyverno:v1.7.5
imagePullPolicy: Always
livenessProbe:
failureThreshold: 2
@ -7914,7 +7914,7 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.namespace
image: ghcr.io/kyverno/kyvernopre:v1.7.4
image: ghcr.io/kyverno/kyvernopre:v1.7.5
imagePullPolicy: Always
name: kyverno-pre
resources:

View file

@ -7,21 +7,21 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.8.0
controller-gen.kubebuilder.io/version: v0.9.1-0.20220629131006-1878064c4cdf
creationTimestamp: null
labels:
app.kubernetes.io/component: kyverno
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: clusterpolicies.kyverno.io
spec:
group: kyverno.io
@ -297,6 +297,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces
names. Each name supports wildcard characters
@ -362,6 +363,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role
@ -405,6 +407,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
type: array
@ -512,6 +515,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces
names. Each name supports wildcard characters
@ -577,6 +581,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role
@ -620,6 +625,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
type: array
@ -716,6 +722,7 @@ spec:
requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces names.
Each name supports wildcard characters "*" (matches
@ -775,6 +782,7 @@ spec:
requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role names
@ -817,6 +825,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
generate:
@ -1007,6 +1016,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces
names. Each name supports wildcard characters
@ -1072,6 +1082,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role
@ -1115,6 +1126,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
type: array
@ -1222,6 +1234,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces
names. Each name supports wildcard characters
@ -1287,6 +1300,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role
@ -1330,6 +1344,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
type: array
@ -1426,6 +1441,7 @@ spec:
requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces names.
Each name supports wildcard characters "*" (matches
@ -1485,6 +1501,7 @@ spec:
requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role names
@ -1527,6 +1544,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
mutate:
@ -2583,14 +2601,14 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.8.0
controller-gen.kubebuilder.io/version: v0.9.1-0.20220629131006-1878064c4cdf
creationTimestamp: null
labels:
app.kubernetes.io/component: kyverno
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: clusterpolicyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -2718,6 +2736,7 @@ spec:
are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
resources:
description: Resources is an optional reference to the resource
checked by the policy and rule
@ -2781,6 +2800,7 @@ spec:
description: 'UID of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids'
type: string
type: object
x-kubernetes-map-type: atomic
type: array
result:
description: Result indicates the outcome of the policy rule execution
@ -2869,6 +2889,7 @@ spec:
description: 'UID of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids'
type: string
type: object
x-kubernetes-map-type: atomic
scopeSelector:
description: ScopeSelector is an optional selector for multiple scopes
(e.g. Pods). Either one of, or none of, but not both of, Scope or ScopeSelector
@ -2912,6 +2933,7 @@ spec:
contains only "value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
summary:
description: PolicyReportSummary provides a summary of results
properties:
@ -2945,14 +2967,14 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.8.0
controller-gen.kubebuilder.io/version: v0.9.1-0.20220629131006-1878064c4cdf
creationTimestamp: null
labels:
app.kubernetes.io/component: kyverno
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: clusterreportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -3080,6 +3102,7 @@ spec:
are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
resources:
description: Resources is an optional reference to the resource
checked by the policy and rule
@ -3143,6 +3166,7 @@ spec:
description: 'UID of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids'
type: string
type: object
x-kubernetes-map-type: atomic
type: array
result:
description: Result indicates the outcome of the policy rule execution
@ -3231,6 +3255,7 @@ spec:
description: 'UID of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids'
type: string
type: object
x-kubernetes-map-type: atomic
scopeSelector:
description: ScopeSelector is an optional selector for multiple scopes
(e.g. Pods). Either one of, or none of, but not both of, Scope or ScopeSelector
@ -3274,6 +3299,7 @@ spec:
contains only "value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
summary:
description: PolicyReportSummary provides a summary of results
properties:
@ -3307,14 +3333,14 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.8.0
controller-gen.kubebuilder.io/version: v0.9.1-0.20220629131006-1878064c4cdf
creationTimestamp: null
labels:
app.kubernetes.io/component: kyverno
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: generaterequests.kyverno.io
spec:
group: kyverno.io
@ -3497,14 +3523,14 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.8.0
controller-gen.kubebuilder.io/version: v0.9.1-0.20220629131006-1878064c4cdf
creationTimestamp: null
labels:
app.kubernetes.io/component: kyverno
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: policies.kyverno.io
spec:
group: kyverno.io
@ -3781,6 +3807,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces
names. Each name supports wildcard characters
@ -3846,6 +3873,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role
@ -3889,6 +3917,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
type: array
@ -3996,6 +4025,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces
names. Each name supports wildcard characters
@ -4061,6 +4091,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role
@ -4104,6 +4135,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
type: array
@ -4200,6 +4232,7 @@ spec:
requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces names.
Each name supports wildcard characters "*" (matches
@ -4259,6 +4292,7 @@ spec:
requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role names
@ -4301,6 +4335,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
generate:
@ -4491,6 +4526,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces
names. Each name supports wildcard characters
@ -4556,6 +4592,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role
@ -4599,6 +4636,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
type: array
@ -4706,6 +4744,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces
names. Each name supports wildcard characters
@ -4771,6 +4810,7 @@ spec:
"value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role
@ -4814,6 +4854,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
type: array
@ -4910,6 +4951,7 @@ spec:
requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
namespaces:
description: Namespaces is a list of namespaces names.
Each name supports wildcard characters "*" (matches
@ -4969,6 +5011,7 @@ spec:
requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
type: object
roles:
description: Roles is the list of namespaced role names
@ -5011,6 +5054,7 @@ spec:
- kind
- name
type: object
x-kubernetes-map-type: atomic
type: array
type: object
mutate:
@ -6068,14 +6112,14 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.8.0
controller-gen.kubebuilder.io/version: v0.9.1-0.20220629131006-1878064c4cdf
creationTimestamp: null
labels:
app.kubernetes.io/component: kyverno
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: policyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -6202,6 +6246,7 @@ spec:
are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
resources:
description: Resources is an optional reference to the resource
checked by the policy and rule
@ -6265,6 +6310,7 @@ spec:
description: 'UID of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids'
type: string
type: object
x-kubernetes-map-type: atomic
type: array
result:
description: Result indicates the outcome of the policy rule execution
@ -6353,6 +6399,7 @@ spec:
description: 'UID of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids'
type: string
type: object
x-kubernetes-map-type: atomic
scopeSelector:
description: ScopeSelector is an optional selector for multiple scopes
(e.g. Pods). Either one of, or none of, but not both of, Scope or ScopeSelector
@ -6396,6 +6443,7 @@ spec:
contains only "value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
summary:
description: PolicyReportSummary provides a summary of results
properties:
@ -6429,14 +6477,14 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.8.0
controller-gen.kubebuilder.io/version: v0.9.1-0.20220629131006-1878064c4cdf
creationTimestamp: null
labels:
app.kubernetes.io/component: kyverno
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: reportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -6564,6 +6612,7 @@ spec:
are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
resources:
description: Resources is an optional reference to the resource
checked by the policy and rule
@ -6627,6 +6676,7 @@ spec:
description: 'UID of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids'
type: string
type: object
x-kubernetes-map-type: atomic
type: array
result:
description: Result indicates the outcome of the policy rule execution
@ -6715,6 +6765,7 @@ spec:
description: 'UID of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids'
type: string
type: object
x-kubernetes-map-type: atomic
scopeSelector:
description: ScopeSelector is an optional selector for multiple scopes
(e.g. Pods). Either one of, or none of, but not both of, Scope or ScopeSelector
@ -6758,6 +6809,7 @@ spec:
contains only "value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
summary:
description: PolicyReportSummary provides a summary of results
properties:
@ -6791,14 +6843,14 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.8.0
controller-gen.kubebuilder.io/version: v0.9.1-0.20220629131006-1878064c4cdf
creationTimestamp: null
labels:
app.kubernetes.io/component: kyverno
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: updaterequests.kyverno.io
spec:
group: kyverno.io
@ -7187,7 +7239,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno-service-account
namespace: kyverno
---
@ -7200,7 +7252,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:leaderelection
namespace: kyverno
rules:
@ -7234,7 +7286,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-generaterequest
rules:
@ -7260,7 +7312,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-policies
rules:
@ -7287,7 +7339,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-policyreport
rules:
@ -7314,7 +7366,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-reportchangerequest
rules:
@ -7341,7 +7393,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:events
rules:
- apiGroups:
@ -7363,7 +7415,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:generate
rules:
- apiGroups:
@ -7410,7 +7462,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:policies
rules:
- apiGroups:
@ -7463,7 +7515,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:userinfo
rules:
- apiGroups:
@ -7486,7 +7538,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:view
rules:
- apiGroups:
@ -7507,7 +7559,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:webhook
rules:
- apiGroups:
@ -7533,7 +7585,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:leaderelection
namespace: kyverno
roleRef:
@ -7554,7 +7606,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:events
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7574,7 +7626,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:generate
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7594,7 +7646,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:policies
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7614,7 +7666,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:userinfo
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7634,7 +7686,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:view
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7654,7 +7706,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno:webhook
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7679,7 +7731,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno
namespace: kyverno
---
@ -7695,7 +7747,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno-metrics
namespace: kyverno
---
@ -7708,7 +7760,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno-svc
namespace: kyverno
spec:
@ -7729,7 +7781,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno-svc-metrics
namespace: kyverno
spec:
@ -7750,7 +7802,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
name: kyverno
namespace: kyverno
spec:
@ -7772,7 +7824,7 @@ spec:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
spec:
affinity:
podAntiAffinity:
@ -7807,7 +7859,7 @@ spec:
value: kyverno-svc
- name: TUF_ROOT
value: /.sigstore
image: ghcr.io/kyverno/kyverno:v1.7.4
image: ghcr.io/kyverno/kyverno:v1.7.5
imagePullPolicy: Always
livenessProbe:
failureThreshold: 2
@ -7862,7 +7914,7 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.namespace
image: ghcr.io/kyverno/kyvernopre:v1.7.4
image: ghcr.io/kyverno/kyvernopre:v1.7.5
imagePullPolicy: Always
name: kyverno-pre
resources:

View file

@ -9,6 +9,6 @@ transformers:
images:
- name: ghcr.io/kyverno/kyverno
newTag: v1.7.4
newTag: v1.7.5
- name: ghcr.io/kyverno/kyvernopre
newTag: v1.7.4
newTag: v1.7.5

View file

@ -4,7 +4,7 @@ kind: LabelTransformer
metadata:
name: labelTransformer
labels:
app.kubernetes.io/version: v1.7.4
app.kubernetes.io/version: v1.7.5
fieldSpecs:
- path: metadata/labels
create: true