mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-31 03:45:17 +00:00
chore: use Enforce instead of enforce in kuttl tests (#6763)
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
This commit is contained in:
parent
389a64fe18
commit
8f84d222ef
33 changed files with 33 additions and 33 deletions
|
@ -13,7 +13,7 @@ metadata:
|
||||||
a specific version of an application Pod. This policy validates that the image
|
a specific version of an application Pod. This policy validates that the image
|
||||||
specifies a tag and that it is not called `latest`.
|
specifies a tag and that it is not called `latest`.
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
background: true
|
background: true
|
||||||
rules:
|
rules:
|
||||||
- name: validate-image-tag
|
- name: validate-image-tag
|
||||||
|
|
|
@ -6,7 +6,7 @@ metadata:
|
||||||
pod-policies.kyverno.io/autogen-controllers: none
|
pod-policies.kyverno.io/autogen-controllers: none
|
||||||
spec:
|
spec:
|
||||||
mutateExistingOnPolicyUpdate: false
|
mutateExistingOnPolicyUpdate: false
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
rules:
|
rules:
|
||||||
- name: propagate org label from namespace
|
- name: propagate org label from namespace
|
||||||
match:
|
match:
|
||||||
|
|
|
@ -6,7 +6,7 @@ metadata:
|
||||||
pod-policies.kyverno.io/autogen-controllers: none
|
pod-policies.kyverno.io/autogen-controllers: none
|
||||||
spec:
|
spec:
|
||||||
mutateExistingOnPolicyUpdate: true
|
mutateExistingOnPolicyUpdate: true
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
rules:
|
rules:
|
||||||
- name: propagate org label from namespace
|
- name: propagate org label from namespace
|
||||||
match:
|
match:
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: external-metrics-policy
|
name: external-metrics-policy
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
- name: external-metrics-rule
|
- name: external-metrics-rule
|
||||||
|
|
|
@ -4,7 +4,7 @@ metadata:
|
||||||
name: external-metrics-policy-default
|
name: external-metrics-policy-default
|
||||||
namespace: default
|
namespace: default
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
- name: external-metrics-rule-default
|
- name: external-metrics-rule-default
|
||||||
|
|
|
@ -24,4 +24,4 @@ spec:
|
||||||
metadata:
|
metadata:
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: "?*"
|
app.kubernetes.io/name: "?*"
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: require-owner
|
name: require-owner
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
- name: check-owner
|
- name: check-owner
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: rds-enforce-final-snapshot
|
name: rds-enforce-final-snapshot
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
rules:
|
rules:
|
||||||
- name: rds-enforce-final-snapshot
|
- name: rds-enforce-final-snapshot
|
||||||
match:
|
match:
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: verify-image
|
name: verify-image
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
- name: verify-image
|
- name: verify-image
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: sample
|
name: sample
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
rules:
|
rules:
|
||||||
- name: check-container-image
|
- name: check-container-image
|
||||||
match:
|
match:
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: check-trustable-images
|
name: check-trustable-images
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
rules:
|
rules:
|
||||||
- name: only-allow-trusted-images
|
- name: only-allow-trusted-images
|
||||||
match:
|
match:
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: test-x509-decode
|
name: test-x509-decode
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
rules:
|
rules:
|
||||||
- name: test-x509-decode
|
- name: test-x509-decode
|
||||||
match:
|
match:
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: validate-resources
|
name: validate-resources
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
background: false
|
background: false
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
failurePolicy: Fail
|
failurePolicy: Fail
|
||||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
||||||
annotations:
|
annotations:
|
||||||
pod-policies.kyverno.io/autogen-controllers: none
|
pod-policies.kyverno.io/autogen-controllers: none
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
|
|
|
@ -35,7 +35,7 @@ metadata:
|
||||||
key in a ConfigMap called `key` in the `default` Namespace
|
key in a ConfigMap called `key` in the `default` Namespace
|
||||||
and also a Namespace key in the same ConfigMap.
|
and also a Namespace key in the same ConfigMap.
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
background: true
|
background: true
|
||||||
rules:
|
rules:
|
||||||
- name: check-image-with-two-keys
|
- name: check-image-with-two-keys
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: tasks-keyless
|
name: tasks-keyless
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
rules:
|
rules:
|
||||||
- name: verify-images
|
- name: verify-images
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: tasks-complex
|
name: tasks-complex
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
rules:
|
rules:
|
||||||
- name: verify-images
|
- name: verify-images
|
||||||
match:
|
match:
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: tasks-no-extractor
|
name: tasks-no-extractor
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
rules:
|
rules:
|
||||||
- name: verify-images
|
- name: verify-images
|
||||||
match:
|
match:
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: tasks-simple
|
name: tasks-simple
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
rules:
|
rules:
|
||||||
- name: verify-images
|
- name: verify-images
|
||||||
match:
|
match:
|
||||||
|
|
|
@ -8,7 +8,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: keyed-basic-policy
|
name: keyed-basic-policy
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
background: false
|
background: false
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
failurePolicy: Fail
|
failurePolicy: Fail
|
||||||
|
|
|
@ -8,7 +8,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: secret-in-keys
|
name: secret-in-keys
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
background: false
|
background: false
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
failurePolicy: Fail
|
failurePolicy: Fail
|
||||||
|
|
|
@ -6,7 +6,7 @@ metadata:
|
||||||
annotations:
|
annotations:
|
||||||
pod-policies.kyverno.io/autogen-controllers: none
|
pod-policies.kyverno.io/autogen-controllers: none
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
||||||
annotations:
|
annotations:
|
||||||
pod-policies.kyverno.io/autogen-controllers: none
|
pod-policies.kyverno.io/autogen-controllers: none
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
||||||
annotations:
|
annotations:
|
||||||
pod-policies.kyverno.io/autogen-controllers: none
|
pod-policies.kyverno.io/autogen-controllers: none
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
|
|
|
@ -24,4 +24,4 @@ spec:
|
||||||
predicateType: https://slsa.dev/provenance/v0.2
|
predicateType: https://slsa.dev/provenance/v0.2
|
||||||
imageReferences:
|
imageReferences:
|
||||||
- ghcr.io/chipzoller/zulu*
|
- ghcr.io/chipzoller/zulu*
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
||||||
annotations:
|
annotations:
|
||||||
pod-policies.kyverno.io/autogen-controllers: none
|
pod-policies.kyverno.io/autogen-controllers: none
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
||||||
annotations:
|
annotations:
|
||||||
pod-policies.kyverno.io/autogen-controllers: none
|
pod-policies.kyverno.io/autogen-controllers: none
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
|
|
|
@ -5,7 +5,7 @@ metadata:
|
||||||
annotations:
|
annotations:
|
||||||
pod-policies.kyverno.io/autogen-controllers: none
|
pod-policies.kyverno.io/autogen-controllers: none
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
background: false
|
background: false
|
||||||
rules:
|
rules:
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: keyless-mutatedigest-verifydigest-required
|
name: keyless-mutatedigest-verifydigest-required
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
rules:
|
rules:
|
||||||
- name: check-builder-id-keyless
|
- name: check-builder-id-keyless
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: keyless-nomutatedigest-noverifydigest-norequired
|
name: keyless-nomutatedigest-noverifydigest-norequired
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
rules:
|
rules:
|
||||||
- name: check-builder-id-keyless
|
- name: check-builder-id-keyless
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: keyless-nomutatedigest-noverifydigest-required
|
name: keyless-nomutatedigest-noverifydigest-required
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
rules:
|
rules:
|
||||||
- name: check-builder-id-keyless
|
- name: check-builder-id-keyless
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: mutatedigest-policy
|
name: mutatedigest-policy
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
rules:
|
rules:
|
||||||
- name: mutatedigest-rule
|
- name: mutatedigest-rule
|
||||||
|
|
|
@ -3,7 +3,7 @@ kind: ClusterPolicy
|
||||||
metadata:
|
metadata:
|
||||||
name: mutatedigest-policy
|
name: mutatedigest-policy
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: enforce
|
validationFailureAction: Enforce
|
||||||
webhookTimeoutSeconds: 30
|
webhookTimeoutSeconds: 30
|
||||||
rules:
|
rules:
|
||||||
- name: mutatedigest-rule
|
- name: mutatedigest-rule
|
||||||
|
|
Loading…
Add table
Reference in a new issue