-
Notifications
You must be signed in to change notification settings - Fork 314
Open
Description
Hello,
The rationale behind the Require Requests and Limits for emptyDir policy is preventing the backing medium overrun:
policies/other/require-emptydir-requests-limits/require-emptydir-requests-limits.yaml
Lines 14 to 18 in 12a6878
| Pods which mount emptyDir volumes may be allowed to potentially overrun | |
| the medium backing the emptyDir volume. This sample ensures that any | |
| initContainers or containers mounting an emptyDir volume have | |
| ephemeral-storage requests and limits set. Policy will be skipped if | |
| the volume has already a sizeLimit set. |
However, the policy considers only one medium. ephemeral-storage is the wrong resource for memory-backed (medium: Memory) volumes.
In addition, I believe this precondition is obsolete:
policies/other/require-emptydir-requests-limits/require-emptydir-requests-limits.yaml
Lines 38 to 42 in 12a6878
| - key: "{{request.operation || 'BACKGROUND'}}" | |
| operator: AnyIn | |
| value: | |
| - CREATE | |
| - UPDATE |
Metadata
Metadata
Assignees
Labels
No labels