UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects

add non-root-user-istio exception

Merged Robert Massey requested to merge require-non-root-user-exception into main
All threads resolved!

General MR

Summary

Using upstream recommended template to exclude resources to exclude all istio-init containers from require-non-root-user ClusterPolicy

https://kyverno.io/docs/writing-policies/exceptions/

Relates #54

Relevant logs/screenshots

(Include any relevant logs/screenshots)

Edited by Robert Massey

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
    • Resolved by Michael Martin

      I have a general question on these changes -- do we need these changes when we have the existing exceptions in bigbang/chart/templates/kyverno-policies/values.yaml e.g.:

            excludeContainers:
              - istio-init

      These excludes are on the require-non-root-group and require-non-root-user` rules.

      Edited by Michael Martin
  • Robert Massey resolved all threads

    resolved all threads

  • Robert Massey added 1 commit

    added 1 commit

    Compare with previous version

  • Michael Martin resolved all threads

    resolved all threads

  • Michael Martin approved this merge request

    approved this merge request

  • Michael Martin mentioned in commit f8458b33

    mentioned in commit f8458b33

  • merged

  • mentioned in merge request big-bang/bigbang!3434 (merged)

  • Please register or sign in to reply
    Loading