UNCLASSIFIED - NO CUI

kyvernoPolicies update to 3.3.4-bb.24

Package Merge Request

Package Changes

https://repo1.dso.mil/big-bang/product/packages/kyverno-policies/-/blob/3.3.4-bb.24/CHANGELOG.md

Package MR

big-bang/product/packages/kyverno-policies!303 (merged)

For Issue

Closes big-bang/product/packages/kyverno-policies#201 (closed)

Upgrade Notices

The default enabled and validationFailureAction settings for most policies have been updated to match those set in the bigbang umbrella chart. This change has no impact on those using the chart with bigbang, and only impacts those who may be using the chart independently.

  • disallow-image-tags is now enabled and enforced by default.
  • disallow-namespaces is now enabled and enforced by default.
  • disallow-nodeport-services is now enforced by default.
  • require-image-signature is now disabled and not enforced by default.
  • require-host-path-mount is now enforced by default.
  • require-host-path-mount-pv is now enforced by default.
  • require-host-path-write is now enforced by default.
  • restrict-image-registries is now enforced by default.
Edited by Jonathan Braswell

Merge request reports

Loading