mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-28 02:18:15 +00:00
chore: use Enforce instead of enforce in kuttl tests (#6763)
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
This commit is contained in:
parent
389a64fe18
commit
8f84d222ef
33 changed files with 33 additions and 33 deletions
|
@ -13,7 +13,7 @@ metadata:
|
|||
a specific version of an application Pod. This policy validates that the image
|
||||
specifies a tag and that it is not called `latest`.
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
background: true
|
||||
rules:
|
||||
- name: validate-image-tag
|
||||
|
|
|
@ -6,7 +6,7 @@ metadata:
|
|||
pod-policies.kyverno.io/autogen-controllers: none
|
||||
spec:
|
||||
mutateExistingOnPolicyUpdate: false
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
rules:
|
||||
- name: propagate org label from namespace
|
||||
match:
|
||||
|
|
|
@ -6,7 +6,7 @@ metadata:
|
|||
pod-policies.kyverno.io/autogen-controllers: none
|
||||
spec:
|
||||
mutateExistingOnPolicyUpdate: true
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
rules:
|
||||
- name: propagate org label from namespace
|
||||
match:
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: external-metrics-policy
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
background: false
|
||||
rules:
|
||||
- name: external-metrics-rule
|
||||
|
|
|
@ -4,7 +4,7 @@ metadata:
|
|||
name: external-metrics-policy-default
|
||||
namespace: default
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
background: false
|
||||
rules:
|
||||
- name: external-metrics-rule-default
|
||||
|
|
|
@ -24,4 +24,4 @@ spec:
|
|||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: "?*"
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: require-owner
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
background: false
|
||||
rules:
|
||||
- name: check-owner
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: rds-enforce-final-snapshot
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
rules:
|
||||
- name: rds-enforce-final-snapshot
|
||||
match:
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: verify-image
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
background: false
|
||||
rules:
|
||||
- name: verify-image
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: sample
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
rules:
|
||||
- name: check-container-image
|
||||
match:
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: check-trustable-images
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
rules:
|
||||
- name: only-allow-trusted-images
|
||||
match:
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: test-x509-decode
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
rules:
|
||||
- name: test-x509-decode
|
||||
match:
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: validate-resources
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
background: false
|
||||
webhookTimeoutSeconds: 30
|
||||
failurePolicy: Fail
|
||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
|||
annotations:
|
||||
pod-policies.kyverno.io/autogen-controllers: none
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
background: false
|
||||
rules:
|
||||
|
|
|
@ -35,7 +35,7 @@ metadata:
|
|||
key in a ConfigMap called `key` in the `default` Namespace
|
||||
and also a Namespace key in the same ConfigMap.
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
background: true
|
||||
rules:
|
||||
- name: check-image-with-two-keys
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: tasks-keyless
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
rules:
|
||||
- name: verify-images
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: tasks-complex
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
rules:
|
||||
- name: verify-images
|
||||
match:
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: tasks-no-extractor
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
rules:
|
||||
- name: verify-images
|
||||
match:
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: tasks-simple
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
rules:
|
||||
- name: verify-images
|
||||
match:
|
||||
|
|
|
@ -8,7 +8,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: keyed-basic-policy
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
background: false
|
||||
webhookTimeoutSeconds: 30
|
||||
failurePolicy: Fail
|
||||
|
|
|
@ -8,7 +8,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: secret-in-keys
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
background: false
|
||||
webhookTimeoutSeconds: 30
|
||||
failurePolicy: Fail
|
||||
|
|
|
@ -6,7 +6,7 @@ metadata:
|
|||
annotations:
|
||||
pod-policies.kyverno.io/autogen-controllers: none
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
background: false
|
||||
rules:
|
||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
|||
annotations:
|
||||
pod-policies.kyverno.io/autogen-controllers: none
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
background: false
|
||||
rules:
|
||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
|||
annotations:
|
||||
pod-policies.kyverno.io/autogen-controllers: none
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
background: false
|
||||
rules:
|
||||
|
|
|
@ -24,4 +24,4 @@ spec:
|
|||
predicateType: https://slsa.dev/provenance/v0.2
|
||||
imageReferences:
|
||||
- ghcr.io/chipzoller/zulu*
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
|||
annotations:
|
||||
pod-policies.kyverno.io/autogen-controllers: none
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
background: false
|
||||
rules:
|
||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
|||
annotations:
|
||||
pod-policies.kyverno.io/autogen-controllers: none
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
background: false
|
||||
rules:
|
||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
|||
annotations:
|
||||
pod-policies.kyverno.io/autogen-controllers: none
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
background: false
|
||||
rules:
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: keyless-mutatedigest-verifydigest-required
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
rules:
|
||||
- name: check-builder-id-keyless
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: keyless-nomutatedigest-noverifydigest-norequired
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
rules:
|
||||
- name: check-builder-id-keyless
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: keyless-nomutatedigest-noverifydigest-required
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
rules:
|
||||
- name: check-builder-id-keyless
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: mutatedigest-policy
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
rules:
|
||||
- name: mutatedigest-rule
|
||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
|||
metadata:
|
||||
name: mutatedigest-policy
|
||||
spec:
|
||||
validationFailureAction: enforce
|
||||
validationFailureAction: Enforce
|
||||
webhookTimeoutSeconds: 30
|
||||
rules:
|
||||
- name: mutatedigest-rule
|
||||
|
|
Loading…
Add table
Reference in a new issue