mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-28 10:28:36 +00:00
feat: support background mode configuration in kyverno-policies chart (#3299)
Signed-off-by: Charles-Edouard Brétéché <charled.breteche@gmail.com> Co-authored-by: shuting <shuting@nirmata.com>
This commit is contained in:
parent
c4075af3d1
commit
c79b66d3a3
19 changed files with 20 additions and 18 deletions
|
@ -22,7 +22,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: adding-capabilities
|
||||
match:
|
||||
|
|
|
@ -23,7 +23,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: host-namespaces
|
||||
match:
|
||||
|
|
|
@ -22,7 +22,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: host-path
|
||||
match:
|
||||
|
|
|
@ -22,7 +22,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: host-ports-none
|
||||
match:
|
||||
|
|
|
@ -23,7 +23,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: host-process-containers
|
||||
match:
|
||||
|
|
|
@ -21,7 +21,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: privileged-containers
|
||||
match:
|
||||
|
|
|
@ -23,7 +23,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: check-proc-mount
|
||||
match:
|
||||
|
|
|
@ -21,7 +21,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: selinux-type
|
||||
match:
|
||||
|
|
|
@ -24,7 +24,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: app-armor
|
||||
match:
|
||||
|
|
|
@ -18,7 +18,7 @@ metadata:
|
|||
requiring Kubernetes v1.19 or later, ensures that seccomp is unset or
|
||||
set to `RuntimeDefault` or `Localhost`.
|
||||
spec:
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
validationFailureAction: {{ .Values.validationFailureAction }}
|
||||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
|
|
|
@ -25,7 +25,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: check-sysctls
|
||||
match:
|
||||
|
|
|
@ -23,7 +23,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: check-runasgroup
|
||||
match:
|
||||
|
|
|
@ -23,7 +23,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: require-drop-all
|
||||
match:
|
||||
|
|
|
@ -21,7 +21,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: privilege-escalation
|
||||
match:
|
||||
|
|
|
@ -21,7 +21,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: run-as-non-root-user
|
||||
match:
|
||||
|
|
|
@ -22,7 +22,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: run-as-non-root
|
||||
match:
|
||||
|
|
|
@ -20,7 +20,7 @@ metadata:
|
|||
set to `RuntimeDefault` or `Localhost`. A known issue prevents a policy such as this
|
||||
using `anyPattern` from being persisted properly in Kubernetes 1.23.0-1.23.2.
|
||||
spec:
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
validationFailureAction: {{ .Values.validationFailureAction }}
|
||||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
|
|
|
@ -24,7 +24,7 @@ spec:
|
|||
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
|
||||
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
background: true
|
||||
background: {{ .Values.background }}
|
||||
rules:
|
||||
- name: restricted-volumes
|
||||
match:
|
||||
|
|
|
@ -52,3 +52,5 @@ policyExclude: {}
|
|||
nameOverride:
|
||||
# -- Additional labels
|
||||
customLabels: {}
|
||||
# Policies background mode
|
||||
background: true
|
||||
|
|
Loading…
Add table
Reference in a new issue