mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-22 15:50:36 +00:00
Signed-off-by: Mohd Kamaal <mohdkamaal2019@gmail.com> Co-authored-by: Vishal Choudhary <vishal.choudhary@nirmata.com> Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
26 lines
No EOL
932 B
YAML
26 lines
No EOL
932 B
YAML
apiVersion: policies.kyverno.io/v1alpha1
|
|
kind: ValidatingPolicy
|
|
metadata:
|
|
name: check-deployment-labels
|
|
annotations:
|
|
policies.kyverno.io/title: Check Deployment Labels
|
|
policies.kyverno.io/category: Other
|
|
policies.kyverno.io/severity: medium
|
|
spec:
|
|
validationActions:
|
|
- Audit
|
|
matchConstraints:
|
|
resourceRules:
|
|
- apiGroups: [apps]
|
|
apiVersions: [v1]
|
|
operations: [CREATE, UPDATE]
|
|
resources: [deployments]
|
|
variables:
|
|
- name: environment
|
|
expression: >-
|
|
has(object.metadata.labels) && 'env' in object.metadata.labels && object.metadata.labels['env'] == 'prod'
|
|
validations:
|
|
- expression: >-
|
|
variables.environment == true
|
|
messageExpression: >-
|
|
'Deployment labels must be env=prod' + (has(object.metadata.labels) && 'env' in object.metadata.labels ? ' but found env=' + string(object.metadata.labels['env']) : ' but no env label is present') |