UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects

Update require-run-as-non-root to honor exclusions

Merged Rob Ferguson requested to merge non-root-exclusion into main
All threads resolved!
1 file
+ 2
3
Compare changes
  • Side-by-side
  • Inline
@@ -36,9 +36,8 @@ spec:
{{- include "kyverno-policies.excludeContainersPrecondition" (merge (dict "name" $name) .) | nindent 4 }}
anyPattern:
- (securityContext):
=(runAsUser): ">0"
- (securityContext):
=(runAsNonRoot): "true"
=(runAsUser): "!0"
=(runAsNonRoot): "!false"
- list: request.object.spec.[ephemeralContainers, initContainers, containers][]
preconditions:
all:
Loading