1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-28 10:28:36 +00:00

feat: support background mode configuration in kyverno-policies chart (#3299)

Signed-off-by: Charles-Edouard Brétéché <charled.breteche@gmail.com>

Co-authored-by: shuting <shuting@nirmata.com>
This commit is contained in:
Charles-Edouard Brétéché 2022-02-24 17:31:51 +01:00 committed by GitHub
parent c4075af3d1
commit c79b66d3a3
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
19 changed files with 20 additions and 18 deletions

View file

@ -22,7 +22,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: adding-capabilities
match:

View file

@ -23,7 +23,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: host-namespaces
match:

View file

@ -22,7 +22,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: host-path
match:

View file

@ -22,7 +22,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: host-ports-none
match:

View file

@ -23,7 +23,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: host-process-containers
match:

View file

@ -21,7 +21,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: privileged-containers
match:

View file

@ -23,7 +23,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: check-proc-mount
match:

View file

@ -21,7 +21,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: selinux-type
match:

View file

@ -24,7 +24,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: app-armor
match:

View file

@ -18,7 +18,7 @@ metadata:
requiring Kubernetes v1.19 or later, ensures that seccomp is unset or
set to `RuntimeDefault` or `Localhost`.
spec:
background: true
background: {{ .Values.background }}
validationFailureAction: {{ .Values.validationFailureAction }}
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}

View file

@ -25,7 +25,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: check-sysctls
match:

View file

@ -23,7 +23,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: check-runasgroup
match:

View file

@ -23,7 +23,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: require-drop-all
match:

View file

@ -21,7 +21,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: privilege-escalation
match:

View file

@ -21,7 +21,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: run-as-non-root-user
match:

View file

@ -22,7 +22,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: run-as-non-root
match:

View file

@ -20,7 +20,7 @@ metadata:
set to `RuntimeDefault` or `Localhost`. A known issue prevents a policy such as this
using `anyPattern` from being persisted properly in Kubernetes 1.23.0-1.23.2.
spec:
background: true
background: {{ .Values.background }}
validationFailureAction: {{ .Values.validationFailureAction }}
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}

View file

@ -24,7 +24,7 @@ spec:
{{- with concat (index .Values "validationFailureActionOverrides" "all") (default list (index .Values "validationFailureActionOverrides" $name)) }}
validationFailureActionOverrides: {{ toYaml . | nindent 4 }}
{{- end }}
background: true
background: {{ .Values.background }}
rules:
- name: restricted-volumes
match:

View file

@ -52,3 +52,5 @@ policyExclude: {}
nameOverride:
# -- Additional labels
customLabels: {}
# Policies background mode
background: true