1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-28 02:18:15 +00:00

chore: use Enforce instead of enforce in kuttl tests (#6763)

Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
This commit is contained in:
Charles-Edouard Brétéché 2023-04-03 15:36:30 +02:00 committed by GitHub
parent 389a64fe18
commit 8f84d222ef
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
33 changed files with 33 additions and 33 deletions

View file

@ -13,7 +13,7 @@ metadata:
a specific version of an application Pod. This policy validates that the image
specifies a tag and that it is not called `latest`.
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
background: true
rules:
- name: validate-image-tag

View file

@ -6,7 +6,7 @@ metadata:
pod-policies.kyverno.io/autogen-controllers: none
spec:
mutateExistingOnPolicyUpdate: false
validationFailureAction: enforce
validationFailureAction: Enforce
rules:
- name: propagate org label from namespace
match:

View file

@ -6,7 +6,7 @@ metadata:
pod-policies.kyverno.io/autogen-controllers: none
spec:
mutateExistingOnPolicyUpdate: true
validationFailureAction: enforce
validationFailureAction: Enforce
rules:
- name: propagate org label from namespace
match:

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: external-metrics-policy
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
background: false
rules:
- name: external-metrics-rule

View file

@ -4,7 +4,7 @@ metadata:
name: external-metrics-policy-default
namespace: default
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
background: false
rules:
- name: external-metrics-rule-default

View file

@ -24,4 +24,4 @@ spec:
metadata:
labels:
app.kubernetes.io/name: "?*"
validationFailureAction: enforce
validationFailureAction: Enforce

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: require-owner
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
background: false
rules:
- name: check-owner

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: rds-enforce-final-snapshot
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
rules:
- name: rds-enforce-final-snapshot
match:

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: verify-image
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
background: false
rules:
- name: verify-image

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: sample
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
rules:
- name: check-container-image
match:

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: check-trustable-images
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
rules:
- name: only-allow-trusted-images
match:

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: test-x509-decode
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
rules:
- name: test-x509-decode
match:

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: validate-resources
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
background: false
webhookTimeoutSeconds: 30
failurePolicy: Fail

View file

@ -5,7 +5,7 @@ metadata:
annotations:
pod-policies.kyverno.io/autogen-controllers: none
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
background: false
rules:

View file

@ -35,7 +35,7 @@ metadata:
key in a ConfigMap called `key` in the `default` Namespace
and also a Namespace key in the same ConfigMap.
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
background: true
rules:
- name: check-image-with-two-keys

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: tasks-keyless
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
rules:
- name: verify-images

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: tasks-complex
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
rules:
- name: verify-images
match:

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: tasks-no-extractor
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
rules:
- name: verify-images
match:

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: tasks-simple
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
rules:
- name: verify-images
match:

View file

@ -8,7 +8,7 @@ kind: ClusterPolicy
metadata:
name: keyed-basic-policy
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
background: false
webhookTimeoutSeconds: 30
failurePolicy: Fail

View file

@ -8,7 +8,7 @@ kind: ClusterPolicy
metadata:
name: secret-in-keys
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
background: false
webhookTimeoutSeconds: 30
failurePolicy: Fail

View file

@ -6,7 +6,7 @@ metadata:
annotations:
pod-policies.kyverno.io/autogen-controllers: none
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
background: false
rules:

View file

@ -5,7 +5,7 @@ metadata:
annotations:
pod-policies.kyverno.io/autogen-controllers: none
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
background: false
rules:

View file

@ -5,7 +5,7 @@ metadata:
annotations:
pod-policies.kyverno.io/autogen-controllers: none
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
background: false
rules:

View file

@ -24,4 +24,4 @@ spec:
predicateType: https://slsa.dev/provenance/v0.2
imageReferences:
- ghcr.io/chipzoller/zulu*
validationFailureAction: enforce
validationFailureAction: Enforce

View file

@ -5,7 +5,7 @@ metadata:
annotations:
pod-policies.kyverno.io/autogen-controllers: none
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
background: false
rules:

View file

@ -5,7 +5,7 @@ metadata:
annotations:
pod-policies.kyverno.io/autogen-controllers: none
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
background: false
rules:

View file

@ -5,7 +5,7 @@ metadata:
annotations:
pod-policies.kyverno.io/autogen-controllers: none
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
background: false
rules:

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: keyless-mutatedigest-verifydigest-required
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
rules:
- name: check-builder-id-keyless

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: keyless-nomutatedigest-noverifydigest-norequired
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
rules:
- name: check-builder-id-keyless

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: keyless-nomutatedigest-noverifydigest-required
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
rules:
- name: check-builder-id-keyless

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: mutatedigest-policy
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
rules:
- name: mutatedigest-rule

View file

@ -3,7 +3,7 @@ kind: ClusterPolicy
metadata:
name: mutatedigest-policy
spec:
validationFailureAction: enforce
validationFailureAction: Enforce
webhookTimeoutSeconds: 30
rules:
- name: mutatedigest-rule