UNCLASSIFIED - NO CUI

Disable PSPs on Gatekeeper

This is a follow on to https://repo1.dso.mil/platform-one/big-bang/apps/core/policy/-/issues/151 .

We were unable to disable PSPs in that issue due to an upstream RKE issue - https://github.com/rancher/rke2/issues/2156

This ticket can be closed by:

  • Disabling PSPs for Gatekeeper by default (value here)
  • Validate basic functionality & CI success
  • Validating pipeline for RKE2 works (use the test-ci::infra label with an MR pointing to your Gatekeeper branch)
  • Add release note to release issue for 1.38.0 (issue here) to indicate that certain k8s distros/versions may require you to re-enable PSPs, include the override value required
Edited by Micah Nagel