mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-28 10:28:36 +00:00
* feat: generate VAPs given celexceptions Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com> * chore: modify chainsaw tests Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com> * fix linter Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com> --------- Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
33 lines
892 B
YAML
33 lines
892 B
YAML
apiVersion: admissionregistration.k8s.io/v1
|
|
kind: ValidatingAdmissionPolicy
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/managed-by: kyverno
|
|
name: vpol-check-deployment-labels
|
|
ownerReferences:
|
|
- apiVersion: policies.kyverno.io/v1alpha1
|
|
kind: ValidatingPolicy
|
|
name: check-deployment-labels
|
|
spec:
|
|
failurePolicy: Fail
|
|
matchConditions:
|
|
- expression: '!(object.metadata.name == ''skipped-deployment'')'
|
|
name: check-name
|
|
matchConstraints:
|
|
resourceRules:
|
|
- apiGroups:
|
|
- apps
|
|
apiVersions:
|
|
- v1
|
|
operations:
|
|
- CREATE
|
|
- UPDATE
|
|
resources:
|
|
- deployments
|
|
variables:
|
|
- expression: has(object.metadata.labels) && 'env' in object.metadata.labels &&
|
|
object.metadata.labels['env'] == 'prod'
|
|
name: environment
|
|
validations:
|
|
- expression: variables.environment == true
|
|
message: Deployment labels must be env=prod
|