1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-10 01:46:55 +00:00
kyverno/test/conformance/chainsaw/validating-policies/context/configmap/policy.yaml
Charles-Edouard Brétéché 884a77a044
feat: add context provider in admission handling (#12070)
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2025-02-03 19:11:31 +02:00

23 lines
688 B
YAML

apiVersion: kyverno.io/v2alpha1
kind: ValidatingPolicy
metadata:
name: check-deployment-labels
spec:
matchConstraints:
resourceRules:
- apiGroups: [apps]
apiVersions: [v1]
operations: [CREATE, UPDATE]
resources: [deployments]
variables:
- name: cm
expression: >-
context.GetConfigMap(object.metadata.namespace, "policy-cm")
- name: environment
expression: >-
has(object.metadata.labels) && 'env' in object.metadata.labels && object.metadata.labels['env'] == variables.cm.data.env
validations:
- expression: >-
variables.environment == true
message: >-
Deployment labels must be env=prod