Skip to content

Commit c64663e

Browse files
committed
Adding deny to polices
Signed-off-by: Amit Schendel <[email protected]>
1 parent c3292d8 commit c64663e

File tree

6 files changed

+23
-18
lines changed

6 files changed

+23
-18
lines changed

runtime-policies/attach/policy.yaml

+4-3
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
apiVersion: admissionregistration.x-k8s.io/v1alpha1
22
kind: ValidatingAdmissionPolicy
33
metadata:
4-
name: cluster-policy-attach
4+
name: cluster-policy-deny-attach
55
spec:
66
matchConstraints:
77
resourceRules:
@@ -18,8 +18,9 @@ spec:
1818
apiVersion: admissionregistration.x-k8s.io/v1alpha1
1919
kind: ValidatingAdmissionPolicyBinding
2020
metadata:
21-
name: cluster-policy-attach-binding
21+
name: cluster-policy-deny-attach-binding
2222
spec:
23-
policyName: cluster-policy-attach
23+
policyName: cluster-policy-deny-attach
2424
validationActions:
25+
- Deny
2526
- Audit

runtime-policies/exec/policy.yaml

+3-3
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
apiVersion: admissionregistration.x-k8s.io/v1alpha1
22
kind: ValidatingAdmissionPolicy
33
metadata:
4-
name: cluster-policy-exec
4+
name: cluster-policy-deny-exec
55
spec:
66
matchConstraints:
77
resourceRules:
@@ -18,8 +18,8 @@ spec:
1818
apiVersion: admissionregistration.x-k8s.io/v1alpha1
1919
kind: ValidatingAdmissionPolicyBinding
2020
metadata:
21-
name: cluster-policy-exec-binding
21+
name: cluster-policy-deny-exec-binding
2222
spec:
23-
policyName: cluster-policy-exec
23+
policyName: cluster-policy-deny-exec
2424
validationActions:
2525
- Audit

runtime-policies/hostmount/policy.yaml

+4-3
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
apiVersion: admissionregistration.x-k8s.io/v1alpha1
22
kind: ValidatingAdmissionPolicy
33
metadata:
4-
name: cluster-policy-hostMount
4+
name: cluster-policy-deny-hostMount
55
spec:
66
matchConstraints:
77
resourceRules:
@@ -32,8 +32,9 @@ spec:
3232
apiVersion: admissionregistration.x-k8s.io/v1alpha1
3333
kind: ValidatingAdmissionPolicyBinding
3434
metadata:
35-
name: cluster-policy-hostMount-binding
35+
name: cluster-policy-deny-hostMount-binding
3636
spec:
37-
policyName: cluster-policy-hostMount
37+
policyName: cluster-policy-deny-hostMount
3838
validationActions:
39+
- Deny
3940
- Audit

runtime-policies/insecure-capabilities/policy.yaml

+4-3
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ settings:
2121
apiVersion: admissionregistration.x-k8s.io/v1alpha1
2222
kind: ValidatingAdmissionPolicy
2323
metadata:
24-
name: cluster-policy-insecure-capabilities
24+
name: cluster-policy-deny-insecure-capabilities
2525
spec:
2626
failurePolicy: Fail
2727
paramKind:
@@ -70,10 +70,11 @@ spec:
7070
apiVersion: admissionregistration.x-k8s.io/v1alpha1
7171
kind: ValidatingAdmissionPolicyBinding
7272
metadata:
73-
name: cluster-policy-insecure-capabilities-binding
73+
name: cluster-policy-deny-insecure-capabilities-binding
7474
spec:
75-
policyName: cluster-policy-insecure-capabilities
75+
policyName: cluster-policy-deny-insecure-capabilities
7676
paramRef:
7777
name: basic-policy-configuration
7878
validationActions:
79+
- Deny
7980
- Audit

runtime-policies/portforward/policy.yaml

+4-3
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
apiVersion: admissionregistration.x-k8s.io/v1alpha1
22
kind: ValidatingAdmissionPolicy
33
metadata:
4-
name: cluster-policy-portforward
4+
name: cluster-policy-deny-portforward
55
spec:
66
matchConstraints:
77
resourceRules:
@@ -18,8 +18,9 @@ spec:
1818
apiVersion: admissionregistration.x-k8s.io/v1alpha1
1919
kind: ValidatingAdmissionPolicyBinding
2020
metadata:
21-
name: cluster-policy-portforward-binding
21+
name: cluster-policy-deny-portforward-binding
2222
spec:
23-
policyName: cluster-policy-portforward
23+
policyName: cluster-policy-deny-portforward
2424
validationActions:
25+
- Deny
2526
- Audit

runtime-policies/privileged/policy.yaml

+4-3
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
apiVersion: admissionregistration.x-k8s.io/v1alpha1
22
kind: ValidatingAdmissionPolicy
33
metadata:
4-
name: cluster-policy-priviliged-flag
4+
name: cluster-policy-deny-priviliged-flag
55
spec:
66
failurePolicy: Fail
77
matchConstraints:
@@ -50,8 +50,9 @@ spec:
5050
apiVersion: admissionregistration.x-k8s.io/v1alpha1
5151
kind: ValidatingAdmissionPolicyBinding
5252
metadata:
53-
name: cluster-policy-privileged-flag-binding
53+
name: cluster-policy-deny-privileged-flag-binding
5454
spec:
55-
policyName: cluster-policy-priviliged-flag
55+
policyName: cluster-policy-deny-priviliged-flag
5656
validationActions:
57+
- Deny
5758
- Audit

0 commit comments

Comments
 (0)