Shuting Zhao
|
1bd8663e4c
|
add selinux best practice
|
2019-10-04 17:28:42 -07:00 |
|
Shuting Zhao
|
04c147eb77
|
add security context "fsgroup"
|
2019-10-04 16:50:23 -07:00 |
|
Shivkumar Dudhani
|
ed960ad277
|
Merge pull request #362 from nirmata/travis_build
skip documentation changes
|
2019-10-02 15:37:21 -07:00 |
|
shivkumar dudhani
|
d8ad99fdf1
|
skip documentation changes
|
2019-10-02 15:27:40 -07:00 |
|
Shivkumar Dudhani
|
aee401fe75
|
Merge pull request #361 from nirmata/documentation
update documentation
|
2019-10-02 15:05:21 -07:00 |
|
shivkumar dudhani
|
667efabc10
|
update documentation
|
2019-10-02 15:00:09 -07:00 |
|
shuting
|
e63a5ff97e
|
Merge pull request #360 from nirmata/356_feature
356 feature
|
2019-10-01 17:23:40 -07:00 |
|
shivkumar dudhani
|
c1e80f7218
|
wrap string
|
2019-10-01 17:16:43 -07:00 |
|
shivkumar dudhani
|
c4e263564f
|
CR: uncomment deadcode
|
2019-10-01 16:59:26 -07:00 |
|
shivkumar dudhani
|
7782c776f1
|
merge with master
|
2019-10-01 16:28:54 -07:00 |
|
Shivkumar Dudhani
|
e02d334dfc
|
Merge pull request #358 from nirmata/346_validate_policy
346 validate policy
|
2019-10-01 16:25:09 -07:00 |
|
shuting
|
31f5e9d50c
|
Merge pull request #359 from nirmata/355_feature
process policy in namespaces
|
2019-10-01 16:19:06 -07:00 |
|
shivkumar dudhani
|
be55c58ff5
|
update doc
|
2019-10-01 16:09:18 -07:00 |
|
Shuting Zhao
|
3ee2d57694
|
ignore kinds check on exclude resource description
|
2019-10-01 15:01:24 -07:00 |
|
Shuting Zhao
|
23c9212d67
|
fix hostpid/hostipc test runner
|
2019-10-01 14:53:58 -07:00 |
|
Shuting Zhao
|
5009e8abb7
|
change anypattern to pattern, refer #357
|
2019-10-01 14:45:16 -07:00 |
|
shivkumar dudhani
|
515a31199e
|
update equality operator
|
2019-10-01 13:08:34 -07:00 |
|
Shuting Zhao
|
a620c14c58
|
fix PR comment
|
2019-10-01 12:41:10 -07:00 |
|
shivkumar dudhani
|
17d80a08c0
|
introduce equality anchor
|
2019-10-01 12:35:14 -07:00 |
|
Shuting Zhao
|
8b174235df
|
add unit tests
|
2019-10-01 11:50:10 -07:00 |
|
shivkumar dudhani
|
c3a2256c1c
|
process policy in namespaces
|
2019-09-28 15:39:06 -07:00 |
|
shivkumar dudhani
|
5f686f782e
|
scenario
|
2019-09-28 14:44:29 -07:00 |
|
shivkumar dudhani
|
56b2d2990b
|
clean up
|
2019-09-28 14:20:39 -07:00 |
|
shivkumar dudhani
|
808cccb421
|
update validation logic
|
2019-09-28 14:09:46 -07:00 |
|
Shuting Zhao
|
28bb9c80b4
|
validate existing anchor of validate rule
|
2019-09-27 19:03:55 -07:00 |
|
Shuting Zhao
|
a72a73b8a9
|
fix warning
|
2019-09-27 16:35:09 -07:00 |
|
Shuting Zhao
|
8a7250ffef
|
refactor policy validation, moved to pkg/api/kyverno
|
2019-09-27 16:31:27 -07:00 |
|
Shuting Zhao
|
76ad9406b1
|
only allow one type of rule defined in a single rule
|
2019-09-26 18:02:24 -07:00 |
|
shivkumar dudhani
|
ae3059b858
|
unit test initial check
|
2019-09-26 11:00:30 -07:00 |
|
shivkumar dudhani
|
087efffd96
|
support existance on list type
|
2019-09-25 21:01:45 -07:00 |
|
shivkumar dudhani
|
974fff169a
|
support evaluation of nested values
|
2019-09-25 16:06:37 -07:00 |
|
shivkumar dudhani
|
c65f12b97b
|
initial commit
|
2019-09-25 15:12:33 -07:00 |
|
shuting
|
9992ab0f63
|
Merge pull request #353 from nirmata/best_practice_policies
update best practices
|
2019-09-18 12:39:02 -07:00 |
|
Shuting Zhao
|
d279d7fd77
|
update testrunner
|
2019-09-18 12:33:25 -07:00 |
|
Shuting Zhao
|
4a43eef696
|
correct spelling
|
2019-09-18 12:31:14 -07:00 |
|
Shuting Zhao
|
da3d48f020
|
update test scenario for non-root user
|
2019-09-17 18:51:16 -07:00 |
|
Shuting Zhao
|
658fb84e91
|
update best_practice Disallow privileged and privilege escalation
|
2019-09-17 18:42:08 -07:00 |
|
Shuting Zhao
|
f4eee4b30a
|
update best-practice run as non-root uesr
|
2019-09-17 18:36:24 -07:00 |
|
Shivkumar Dudhani
|
1a38e6bea6
|
Merge pull request #352 from nirmata/best_practice_policies
add best-practice: disallow_default_serviceaccount
|
2019-09-16 15:22:56 -07:00 |
|
Shuting Zhao
|
5e0415911a
|
add best-practice: policy_validate_disallow_default_serviceaccount
|
2019-09-16 14:16:54 -07:00 |
|
shuting
|
3d02f81434
|
Merge pull request #351 from nirmata/348_feature_wildcardsNamespaces
support wild cards for namespaces in rule resource description
|
2019-09-12 23:06:51 -07:00 |
|
shuting
|
bd73dd7b0e
|
Merge pull request #350 from nirmata/349_bug
349 bug
|
2019-09-12 23:02:35 -07:00 |
|
shivkumar dudhani
|
44af35d6e4
|
support wild cards for namespaces in rule resource description
|
2019-09-12 17:11:55 -07:00 |
|
shivkumar dudhani
|
c77e5df6c0
|
missing file
|
2019-09-12 15:04:46 -07:00 |
|
shivkumar dudhani
|
5dab189743
|
fix event resource name + add filtered kinds to policy controller & namespace + fix messages
|
2019-09-12 15:04:35 -07:00 |
|
Shivkumar Dudhani
|
fdc4703258
|
Merge pull request #343 from nirmata/best_practice_policies
Update best practice policies
|
2019-09-10 12:47:10 -07:00 |
|
Shuting Zhao
|
e6a5b1ceb8
|
add namespace_quota testrunner
|
2019-09-10 12:27:21 -07:00 |
|
Shuting Zhao
|
2e22c21164
|
add policy_validate_disallow_node_port.yaml
|
2019-09-10 11:57:33 -07:00 |
|
shuting
|
6004ab0a29
|
Rename resource_validate_hostPID_hostIPC.yaml to resource_validate_hostpid_hostipc.yaml
|
2019-09-10 00:04:33 -07:00 |
|
shuting
|
fd7614ae23
|
Rename policy_validate_hostPID_hosIPC.yaml to policy_validate_hostpid_hosipc.yaml
|
2019-09-10 00:03:49 -07:00 |
|