UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects
Commit 99a3701e authored by Ryan Garcia's avatar Ryan Garcia :dizzy: Committed by Ryan Garcia
Browse files

Merge branch '767-twistlock-def-vio' into 'master'

Update gatekeeper violations for twistlock-defenders selinuxPolicy

Closes #767

See merge request platform-one/big-bang/bigbang!890
parent 8a491569
No related branches found
No related tags found
No related merge requests found
......@@ -109,12 +109,20 @@ violations: # Try to keep this in alpha order to make it easier to find keys
{{- end }}
{{- end }}
{{- if .Values.logging.enabled }}
{{- if or .Values.logging.enabled .Values.twistlock.enabled }}
selinuxPolicy:
{{- if .Values.logging.enabled }}
match:
excludedNamespaces:
# FluentBit needs selinux option type spc_t
- logging
{{- end }}
{{- if .Values.twistlock.enabled }}
parameters:
excludedResources:
# Twistlock Defenders need selinux option type spc_t
- twistlock/twistlock-defender
{{- end }}
{{- end }}
{{- if or .Values.fluentbit.enabled (or .Values.twistlock.enabled .Values.monitoring.enabled) }}
......@@ -165,4 +173,4 @@ violations: # Try to keep this in alpha order to make it easier to find keys
{{- end }}
{{- end }}
{{ toYaml $overlays }}
{{- end }}
\ No newline at end of file
{{- end }}
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment