Newer
Older
bbtests:
enabled: true
waitforready:
imagePullSecrets:
- name: private-registry
excludeContainers:
- not-me
- or-me
exclude:
any:
- resources:
namespaces:
- kyverno-policies
names:
- kyverno-policies-script-test*
policies:
clone-configs:
enabled: true
parameters:
clone:
- name: clone-configs-1
kind: ConfigMap
- 'kyverno-policies-bbtest/test: disallowed'
- kyverno-policies-bbtest/disallowed
disallow-deprecated-apis:
disallow-image-tags:
enabled: true
disallow-istio-injection-bypass:
enabled: true
disallow-labels:
enabled: true
parameters:
disallow:
- 'kyverno-policies-bbtest/test: disallowed'
- kyverno-policies-bbtest/disallowed
disallow-namespaces:
enabled: true
enabled: true
disallow-rbac-on-default-serviceaccounts:
enabled: true
enabled: true
parameters:
- effect: NoSchedule
key: notallowed
value: 'false'
- effect: '*NoSchedule'
key: disa??owed
value: 'true'
require-annotations:
enabled: true
parameters:
- 'kyverno-policies-bbtest/test: required'
- kyverno-policies-bbtest/required
- imageReferences:
- "ghcr.io/kyverno/test-verify-image:*"
attestors:
- count: 1
entries:
- keys:
publicKeys: |-
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE8nXRh950IZbRj8Ra/N9sbqOPZrfM
5/KAQN0/KjHcorm/J5yctVd7iEcnessRQjU917hmKO6JWVGHpDguIyakZA==
-----END PUBLIC KEY-----
- imageReferences:
- "registry1.dso.mil/ironbank/*"
attestors:
- count: 1
entries:
- keys:
publicKeys: |-
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE7CjMGH005DFFz6mffqTIGurBt6fL
UfTZxuEDFRBS8mFJx1xw8DEVvjMibLTtqmAoJxUmzmGFgzz+LV875syVEg==
-----END PUBLIC KEY-----
# Ironbank images are rebuilt nightly and tags are not immutable
mutateDigest: false
verifyDigest: false
- 'kyverno-policies-bbtest/test: required'
- kyverno-policies-bbtest/required
enabled: true
require-probes:
enabled: true
require-requests-equal-limits:
enabled: true
restrict-capabilities:
restrict-external-ips:
enabled: true
parameters:
allow:
restrict-host-path-mount:
enabled: true
parameters:
allow:
restrict-host-path-mount-pv:
enabled: true
parameters:
allow:
- /tmp/allowed
- '63999'
- '>= 64000 & < 65000'
- '> 65000'
update-image-pull-policy:
enabled: true
parameters:
update:
update-image-registry:
enabled: true
parameters:
update:
- from: replace.image.registry
to: registry1.dso.mil

Chris Harden
committed
update-automountserviceaccounttokens:
enabled: true
namespaces:
- namespace: update-automountserviceaccounttokens-2
serviceAccounts:
- update-token-automount-2