1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-06 16:06:56 +00:00

Tag 1.7.0-rc3 (#4036)

Signed-off-by: ShutingZhao <shuting@nirmata.com>
This commit is contained in:
shuting 2022-05-30 17:01:16 +08:00 committed by GitHub
parent 1f4575678c
commit de41b176f6
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
9 changed files with 280 additions and 138 deletions

View file

@ -1,8 +1,8 @@
apiVersion: v2
type: application
name: kyverno-policies
version: v2.4.0-rc2
appVersion: v1.7.0-rc2
version: v2.4.0-rc3
appVersion: v1.7.0-rc3
icon: https://github.com/kyverno/kyverno/raw/main/img/logo.png
description: Kubernetes Pod Security Standards implemented as Kyverno policies
keywords:

View file

@ -2,7 +2,7 @@
Kubernetes Pod Security Standards implemented as Kyverno policies
![Version: v2.4.0-rc2](https://img.shields.io/badge/Version-v2.4.0--rc2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v1.7.0-rc2](https://img.shields.io/badge/AppVersion-v1.7.0--rc2-informational?style=flat-square)
![Version: v2.4.0-rc3](https://img.shields.io/badge/Version-v2.4.0--rc3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v1.7.0-rc3](https://img.shields.io/badge/AppVersion-v1.7.0--rc3-informational?style=flat-square)
## About

View file

@ -1,8 +1,8 @@
apiVersion: v2
type: application
name: kyverno
version: v2.4.0-rc2
appVersion: v1.7.0-rc2
version: v2.4.0-rc3
appVersion: v1.7.0-rc3
icon: https://github.com/kyverno/kyverno/raw/main/img/logo.png
description: Kubernetes Native Policy Management
keywords:

View file

@ -2,7 +2,7 @@
Kubernetes Native Policy Management
![Version: v2.4.0-rc2](https://img.shields.io/badge/Version-v2.4.0--rc2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v1.7.0-rc2](https://img.shields.io/badge/AppVersion-v1.7.0--rc2-informational?style=flat-square)
![Version: v2.4.0-rc3](https://img.shields.io/badge/Version-v2.4.0--rc3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v1.7.0-rc3](https://img.shields.io/badge/AppVersion-v1.7.0--rc3-informational?style=flat-square)
## About

View file

@ -12,7 +12,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: clusterpolicies.kyverno.io
spec:
group: kyverno.io
@ -1625,7 +1625,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: clusterpolicyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -1891,7 +1891,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: clusterreportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -2157,7 +2157,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: generaterequests.kyverno.io
spec:
group: kyverno.io
@ -2332,7 +2332,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: policies.kyverno.io
spec:
group: kyverno.io
@ -3945,7 +3945,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: policyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -4211,7 +4211,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: reportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -4477,7 +4477,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: updaterequests.kyverno.io
spec:
group: kyverno.io

View file

@ -7,7 +7,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno
---
apiVersion: apiextensions.k8s.io/v1
@ -21,7 +21,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: clusterpolicies.kyverno.io
spec:
group: kyverno.io
@ -2590,7 +2590,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: clusterpolicyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -2952,7 +2952,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: clusterreportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -3314,7 +3314,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: generaterequests.kyverno.io
spec:
group: kyverno.io
@ -3504,7 +3504,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: policies.kyverno.io
spec:
group: kyverno.io
@ -6075,7 +6075,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: policyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -6436,7 +6436,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: reportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -6798,7 +6798,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: updaterequests.kyverno.io
spec:
group: kyverno.io
@ -7187,7 +7187,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno-service-account
namespace: kyverno
---
@ -7200,7 +7200,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:leaderelection
namespace: kyverno
rules:
@ -7234,7 +7234,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-generaterequest
rules:
@ -7260,7 +7260,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-policies
rules:
@ -7287,7 +7287,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-policyreport
rules:
@ -7314,7 +7314,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-reportchangerequest
rules:
@ -7341,7 +7341,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:events
rules:
- apiGroups:
@ -7363,7 +7363,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:generate
rules:
- apiGroups:
@ -7410,7 +7410,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:policies
rules:
- apiGroups:
@ -7463,7 +7463,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:userinfo
rules:
- apiGroups:
@ -7486,7 +7486,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:view
rules:
- apiGroups:
@ -7507,7 +7507,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:webhook
rules:
- apiGroups:
@ -7533,7 +7533,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:leaderelection
namespace: kyverno
roleRef:
@ -7554,7 +7554,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:events
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7574,7 +7574,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:generate
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7594,7 +7594,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:policies
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7614,7 +7614,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:userinfo
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7634,7 +7634,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:view
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7654,7 +7654,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:webhook
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7678,7 +7678,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno
namespace: kyverno
---
@ -7694,7 +7694,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno-metrics
namespace: kyverno
---
@ -7707,7 +7707,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno-svc
namespace: kyverno
spec:
@ -7728,7 +7728,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno-svc-metrics
namespace: kyverno
spec:
@ -7749,7 +7749,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno
namespace: kyverno
spec:
@ -7771,7 +7771,7 @@ spec:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
spec:
affinity:
podAntiAffinity:
@ -7806,7 +7806,7 @@ spec:
value: kyverno-svc
- name: TUF_ROOT
value: /.sigstore
image: ghcr.io/kyverno/kyverno:v1.7.0-rc2
image: ghcr.io/kyverno/kyverno:v1.7.0-rc3
imagePullPolicy: Always
livenessProbe:
failureThreshold: 2
@ -7861,7 +7861,7 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.namespace
image: ghcr.io/kyverno/kyvernopre:v1.7.0-rc2
image: ghcr.io/kyverno/kyvernopre:v1.7.0-rc3
imagePullPolicy: Always
name: kyverno-pre
resources:

View file

@ -7,7 +7,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno
---
apiVersion: apiextensions.k8s.io/v1
@ -21,7 +21,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: clusterpolicies.kyverno.io
spec:
group: kyverno.io
@ -2578,12 +2578,6 @@ spec:
storage: true
subresources:
status: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
@ -2596,7 +2590,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: clusterpolicyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -2946,12 +2940,6 @@ spec:
served: true
storage: true
subresources: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
@ -2964,7 +2952,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: clusterreportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -3314,12 +3302,6 @@ spec:
served: true
storage: true
subresources: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
@ -3332,7 +3314,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: generaterequests.kyverno.io
spec:
group: kyverno.io
@ -3510,12 +3492,6 @@ spec:
storage: true
subresources:
status: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
@ -3528,7 +3504,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: policies.kyverno.io
spec:
group: kyverno.io
@ -6087,12 +6063,6 @@ spec:
storage: true
subresources:
status: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
@ -6105,7 +6075,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: policyreports.wgpolicyk8s.io
spec:
group: wgpolicyk8s.io
@ -6454,12 +6424,6 @@ spec:
served: true
storage: true
subresources: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
@ -6472,7 +6436,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: reportchangerequests.kyverno.io
spec:
group: kyverno.io
@ -6822,12 +6786,6 @@ spec:
served: true
storage: true
subresources: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
@ -6840,7 +6798,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: updaterequests.kyverno.io
spec:
group: kyverno.io
@ -6904,7 +6862,197 @@ spec:
and operation details
properties:
admissionRequest:
description: AdmissionRequest describes the admission.Attributes
for the admission request.
properties:
dryRun:
description: DryRun indicates that modifications will
definitely not be persisted for this request. Defaults
to false.
type: boolean
kind:
description: Kind is the fully-qualified type of object
being submitted (for example, v1.Pod or autoscaling.v1.Scale)
properties:
group:
type: string
kind:
type: string
version:
type: string
required:
- group
- kind
- version
type: object
name:
description: Name is the name of the object as presented
in the request. On a CREATE operation, the client may
omit name and rely on the server to generate the name. If
that is the case, this field will contain an empty string.
type: string
namespace:
description: Namespace is the namespace associated with
the request (if any).
type: string
object:
description: Object is the object from the incoming request.
type: object
x-kubernetes-preserve-unknown-fields: true
oldObject:
description: OldObject is the existing object. Only populated
for DELETE and UPDATE requests.
type: object
x-kubernetes-preserve-unknown-fields: true
operation:
description: Operation is the operation being performed.
This may be different than the operation requested.
e.g. a patch can result in either a CREATE or UPDATE
Operation.
type: string
options:
description: Options is the operation option structure
of the operation being performed. e.g. `meta.k8s.io/v1.DeleteOptions`
or `meta.k8s.io/v1.CreateOptions`. This may be different
than the options the caller provided. e.g. for a patch
request the performed Operation might be a CREATE, in
which case the Options will a `meta.k8s.io/v1.CreateOptions`
even though the caller provided `meta.k8s.io/v1.PatchOptions`.
type: object
x-kubernetes-preserve-unknown-fields: true
requestKind:
description: "RequestKind is the fully-qualified type
of the original API request (for example, v1.Pod or
autoscaling.v1.Scale). If this is specified and differs
from the value in \"kind\", an equivalent match and
conversion was performed. \n For example, if deployments
can be modified via apps/v1 and apps/v1beta1, and a
webhook registered a rule of `apiGroups:[\"apps\"],
apiVersions:[\"v1\"], resources: [\"deployments\"]`
and `matchPolicy: Equivalent`, an API request to apps/v1beta1
deployments would be converted and sent to the webhook
with `kind: {group:\"apps\", version:\"v1\", kind:\"Deployment\"}`
(matching the rule the webhook registered for), and
`requestKind: {group:\"apps\", version:\"v1beta1\",
kind:\"Deployment\"}` (indicating the kind of the original
API request). \n See documentation for the \"matchPolicy\"
field in the webhook configuration type for more details."
properties:
group:
type: string
kind:
type: string
version:
type: string
required:
- group
- kind
- version
type: object
requestResource:
description: "RequestResource is the fully-qualified resource
of the original API request (for example, v1.pods).
If this is specified and differs from the value in \"resource\",
an equivalent match and conversion was performed. \n
For example, if deployments can be modified via apps/v1
and apps/v1beta1, and a webhook registered a rule of
`apiGroups:[\"apps\"], apiVersions:[\"v1\"], resources:
[\"deployments\"]` and `matchPolicy: Equivalent`, an
API request to apps/v1beta1 deployments would be converted
and sent to the webhook with `resource: {group:\"apps\",
version:\"v1\", resource:\"deployments\"}` (matching
the resource the webhook registered for), and `requestResource:
{group:\"apps\", version:\"v1beta1\", resource:\"deployments\"}`
(indicating the resource of the original API request).
\n See documentation for the \"matchPolicy\" field in
the webhook configuration type."
properties:
group:
type: string
resource:
type: string
version:
type: string
required:
- group
- resource
- version
type: object
requestSubResource:
description: RequestSubResource is the name of the subresource
of the original API request, if any (for example, "status"
or "scale") If this is specified and differs from the
value in "subResource", an equivalent match and conversion
was performed. See documentation for the "matchPolicy"
field in the webhook configuration type.
type: string
resource:
description: Resource is the fully-qualified resource
being requested (for example, v1.pods)
properties:
group:
type: string
resource:
type: string
version:
type: string
required:
- group
- resource
- version
type: object
subResource:
description: SubResource is the subresource being requested,
if any (for example, "status" or "scale")
type: string
uid:
description: UID is an identifier for the individual request/response.
It allows us to distinguish instances of requests which
are otherwise identical (parallel requests, requests
when earlier requests did not modify etc) The UID is
meant to track the round trip (request/response) between
the KAS and the WebHook, not the user request. It is
suitable for correlating log entries between the webhook
and apiserver, for either auditing or debugging.
type: string
userInfo:
description: UserInfo is information about the requesting
user
properties:
extra:
additionalProperties:
description: ExtraValue masks the value so protobuf
can generate
items:
type: string
type: array
description: Any additional information provided by
the authenticator.
type: object
groups:
description: The names of groups this user is a part
of.
items:
type: string
type: array
uid:
description: A unique value that identifies this user
across time. If this user is deleted and another
user by the same name is added, they will have different
UIDs.
type: string
username:
description: The name that uniquely identifies this
user among all active users.
type: string
type: object
required:
- kind
- operation
- resource
- uid
- userInfo
type: object
operation:
description: Operation is the type of resource operation being
checked for admission control
@ -7029,12 +7177,6 @@ spec:
storage: true
subresources:
status: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: v1
kind: ServiceAccount
@ -7045,7 +7187,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno-service-account
namespace: kyverno
---
@ -7058,7 +7200,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:leaderelection
namespace: kyverno
rules:
@ -7092,7 +7234,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-generaterequest
rules:
@ -7118,7 +7260,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-policies
rules:
@ -7145,7 +7287,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-policyreport
rules:
@ -7172,7 +7314,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
rbac.authorization.k8s.io/aggregate-to-admin: "true"
name: kyverno:admin-reportchangerequest
rules:
@ -7199,7 +7341,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:events
rules:
- apiGroups:
@ -7221,7 +7363,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:generate
rules:
- apiGroups:
@ -7268,7 +7410,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:policies
rules:
- apiGroups:
@ -7321,7 +7463,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:userinfo
rules:
- apiGroups:
@ -7344,7 +7486,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:view
rules:
- apiGroups:
@ -7365,7 +7507,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:webhook
rules:
- apiGroups:
@ -7391,7 +7533,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:leaderelection
namespace: kyverno
roleRef:
@ -7412,7 +7554,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:events
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7432,7 +7574,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:generate
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7452,7 +7594,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:policies
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7472,7 +7614,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:userinfo
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7492,7 +7634,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:view
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7512,7 +7654,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno:webhook
roleRef:
apiGroup: rbac.authorization.k8s.io
@ -7536,7 +7678,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno
namespace: kyverno
---
@ -7552,7 +7694,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno-metrics
namespace: kyverno
---
@ -7565,7 +7707,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno-svc
namespace: kyverno
spec:
@ -7586,7 +7728,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno-svc-metrics
namespace: kyverno
spec:
@ -7607,7 +7749,7 @@ metadata:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
name: kyverno
namespace: kyverno
spec:
@ -7629,7 +7771,7 @@ spec:
app.kubernetes.io/instance: kyverno
app.kubernetes.io/name: kyverno
app.kubernetes.io/part-of: kyverno
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
spec:
affinity:
podAntiAffinity:
@ -7664,7 +7806,7 @@ spec:
value: kyverno-svc
- name: TUF_ROOT
value: /.sigstore
image: ghcr.io/kyverno/kyverno:v1.7.0-rc2
image: ghcr.io/kyverno/kyverno:v1.7.0-rc3
imagePullPolicy: Always
livenessProbe:
failureThreshold: 2
@ -7719,7 +7861,7 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.namespace
image: ghcr.io/kyverno/kyvernopre:v1.7.0-rc2
image: ghcr.io/kyverno/kyvernopre:v1.7.0-rc3
imagePullPolicy: Always
name: kyverno-pre
resources:

View file

@ -9,6 +9,6 @@ transformers:
images:
- name: ghcr.io/kyverno/kyverno
newTag: v1.7.0-rc2
newTag: v1.7.0-rc3
- name: ghcr.io/kyverno/kyvernopre
newTag: v1.7.0-rc2
newTag: v1.7.0-rc3

View file

@ -4,7 +4,7 @@ kind: LabelTransformer
metadata:
name: labelTransformer
labels:
app.kubernetes.io/version: v1.7.0-rc2
app.kubernetes.io/version: v1.7.0-rc3
fieldSpecs:
- path: metadata/labels
create: true