1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2024-12-14 11:57:48 +00:00
kyverno/documentation/writing-policies-background.md
2020-02-06 00:04:19 -08:00

1.3 KiB

documentation / Writing Policies / Background Processing

Background processing

Kyverno applies policies during admission control and to existing resources in the cluster that may have been created before a policy was created. The application of policies to existing resources is referred to as background processing.

Note, that Kyverno does not mutate existing resources, and will only report policy violation for existing resources that do not match mutation, validation, or generation rules.

A policy is always enabled for processing during admission control. However, policy rules that rely on request information (e.g. {{request.userInfo}}) cannot be applied to existing resource in the background mode as the user information is not available outside of the admission controller. Hence, these rules must use the boolean flag {spec.background} to disable background processing.

spec:
  background: true
  rules:
  - name: default-deny-ingress

The default value of background is true. When a policy is created or modified, the policy validation logic will report an error if a rule uses userInfo and does not set background to false.

Read Next >> Testing Policies