File tree 6 files changed +23
-18
lines changed
6 files changed +23
-18
lines changed Original file line number Diff line number Diff line change 1
1
apiVersion : admissionregistration.x-k8s.io/v1alpha1
2
2
kind : ValidatingAdmissionPolicy
3
3
metadata :
4
- name : cluster-policy-attach
4
+ name : cluster-policy-deny- attach
5
5
spec :
6
6
matchConstraints :
7
7
resourceRules :
18
18
apiVersion : admissionregistration.x-k8s.io/v1alpha1
19
19
kind : ValidatingAdmissionPolicyBinding
20
20
metadata :
21
- name : cluster-policy-attach-binding
21
+ name : cluster-policy-deny- attach-binding
22
22
spec :
23
- policyName : cluster-policy-attach
23
+ policyName : cluster-policy-deny- attach
24
24
validationActions :
25
+ - Deny
25
26
- Audit
Original file line number Diff line number Diff line change 1
1
apiVersion : admissionregistration.x-k8s.io/v1alpha1
2
2
kind : ValidatingAdmissionPolicy
3
3
metadata :
4
- name : cluster-policy-exec
4
+ name : cluster-policy-deny- exec
5
5
spec :
6
6
matchConstraints :
7
7
resourceRules :
18
18
apiVersion : admissionregistration.x-k8s.io/v1alpha1
19
19
kind : ValidatingAdmissionPolicyBinding
20
20
metadata :
21
- name : cluster-policy-exec-binding
21
+ name : cluster-policy-deny- exec-binding
22
22
spec :
23
- policyName : cluster-policy-exec
23
+ policyName : cluster-policy-deny- exec
24
24
validationActions :
25
25
- Audit
Original file line number Diff line number Diff line change 1
1
apiVersion : admissionregistration.x-k8s.io/v1alpha1
2
2
kind : ValidatingAdmissionPolicy
3
3
metadata :
4
- name : cluster-policy-hostMount
4
+ name : cluster-policy-deny- hostMount
5
5
spec :
6
6
matchConstraints :
7
7
resourceRules :
32
32
apiVersion : admissionregistration.x-k8s.io/v1alpha1
33
33
kind : ValidatingAdmissionPolicyBinding
34
34
metadata :
35
- name : cluster-policy-hostMount-binding
35
+ name : cluster-policy-deny- hostMount-binding
36
36
spec :
37
- policyName : cluster-policy-hostMount
37
+ policyName : cluster-policy-deny- hostMount
38
38
validationActions :
39
+ - Deny
39
40
- Audit
Original file line number Diff line number Diff line change @@ -21,7 +21,7 @@ settings:
21
21
apiVersion : admissionregistration.x-k8s.io/v1alpha1
22
22
kind : ValidatingAdmissionPolicy
23
23
metadata :
24
- name : cluster-policy-insecure-capabilities
24
+ name : cluster-policy-deny- insecure-capabilities
25
25
spec :
26
26
failurePolicy : Fail
27
27
paramKind :
@@ -70,10 +70,11 @@ spec:
70
70
apiVersion : admissionregistration.x-k8s.io/v1alpha1
71
71
kind : ValidatingAdmissionPolicyBinding
72
72
metadata :
73
- name : cluster-policy-insecure-capabilities-binding
73
+ name : cluster-policy-deny- insecure-capabilities-binding
74
74
spec :
75
- policyName : cluster-policy-insecure-capabilities
75
+ policyName : cluster-policy-deny- insecure-capabilities
76
76
paramRef :
77
77
name : basic-policy-configuration
78
78
validationActions :
79
+ - Deny
79
80
- Audit
Original file line number Diff line number Diff line change 1
1
apiVersion : admissionregistration.x-k8s.io/v1alpha1
2
2
kind : ValidatingAdmissionPolicy
3
3
metadata :
4
- name : cluster-policy-portforward
4
+ name : cluster-policy-deny- portforward
5
5
spec :
6
6
matchConstraints :
7
7
resourceRules :
18
18
apiVersion : admissionregistration.x-k8s.io/v1alpha1
19
19
kind : ValidatingAdmissionPolicyBinding
20
20
metadata :
21
- name : cluster-policy-portforward-binding
21
+ name : cluster-policy-deny- portforward-binding
22
22
spec :
23
- policyName : cluster-policy-portforward
23
+ policyName : cluster-policy-deny- portforward
24
24
validationActions :
25
+ - Deny
25
26
- Audit
Original file line number Diff line number Diff line change 1
1
apiVersion : admissionregistration.x-k8s.io/v1alpha1
2
2
kind : ValidatingAdmissionPolicy
3
3
metadata :
4
- name : cluster-policy-priviliged-flag
4
+ name : cluster-policy-deny- priviliged-flag
5
5
spec :
6
6
failurePolicy : Fail
7
7
matchConstraints :
50
50
apiVersion : admissionregistration.x-k8s.io/v1alpha1
51
51
kind : ValidatingAdmissionPolicyBinding
52
52
metadata :
53
- name : cluster-policy-privileged-flag-binding
53
+ name : cluster-policy-deny- privileged-flag-binding
54
54
spec :
55
- policyName : cluster-policy-priviliged-flag
55
+ policyName : cluster-policy-deny- priviliged-flag
56
56
validationActions :
57
+ - Deny
57
58
- Audit
You can’t perform that action at this time.
0 commit comments