UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects

Update require-run-as-non-root to honor exclusions

Merged Rob Ferguson requested to merge non-root-exclusion into main
All threads resolved!
2 files
+ 26
40
Compare changes
  • Side-by-side
  • Inline
Files
2
@@ -67,7 +67,7 @@ webhookTimeoutSeconds: {{ $webhookTimeoutSeconds }}
{{- $excludeContainers := (dig .name "parameters" "excludeContainers" nil .Values.policies) -}}
{{- if or $globalexcludeContainers $excludeContainers }}
- key: "{{ "{{" }} element.name {{ "}}" }}"
operator: AnyNotIn
operator: {{ .operator }}
value:
{{- if $globalexcludeContainers }}
{{- toYaml $globalexcludeContainers | nindent 10 -}}
Loading