1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-09 09:26:54 +00:00
kyverno/examples/best_practices
2019-09-04 11:08:56 -07:00
..
resources start best practice policies 2019-09-04 11:08:25 -07:00
README.md start best practice policies 2019-09-04 11:08:25 -07:00
validate_container_security_context.yaml rebase master 2019-09-04 11:08:56 -07:00
validate_default_namespace.yaml start best practice policies 2019-09-04 11:08:25 -07:00
validate_host_network_port.yaml start best practice policies 2019-09-04 11:08:25 -07:00
validate_host_path.yaml start best practice policies 2019-09-04 11:08:25 -07:00
validate_image_registries.yaml start best practice policies 2019-09-04 11:08:25 -07:00
validate_image_tag.yaml start best practice policies 2019-09-04 11:08:25 -07:00
validate_pod_probes.yaml start best practice policies 2019-09-04 11:08:25 -07:00
validate_pod_resources.yaml start best practice policies 2019-09-04 11:08:25 -07:00

Best Practice Policies

This folder contains recommended policies

Best practice Policy
Run as non-root user
Disallow privileged and privilege escalation
Disallow use of host networking and ports
Disallow use of host filesystem
Disallow hostPOD and hostIPC
Require read only root filesystem
Disallow node ports
Allow trusted registries
Require resource requests and limits container_resources.yaml
Require pod liveness and readiness probes
Require an image tag
Disallow latest tag and pull IfNotPresent
Require a namespace (disallow default)
Disallow use of kube-system namespace
Prevent mounting of service account secret
Require a default network policy
Require namespace quotas and limit ranges