File tree 3 files changed +58
-58
lines changed
charts/rbac-best-practices
rbac-best-practices/restrict-automount-sa-token
3 files changed +58
-58
lines changed Original file line number Diff line number Diff line change @@ -2,7 +2,7 @@ apiVersion: v2
2
2
name : rbac-best-practice-policies
3
3
description : Rbac Best Practice policy set
4
4
type : application
5
- version : 0.2.0
5
+ version : 0.2.1
6
6
appVersion : 0.1.0
7
7
keywords :
8
8
- kubernetes
Original file line number Diff line number Diff line change 24
24
- resources :
25
25
kinds :
26
26
- Pod
27
+ exclude :
28
+ any :
29
+ - resources :
30
+ kinds :
31
+ - Pod
32
+ selector :
33
+ matchLabels :
34
+ app : nirmata-kube-controller
35
+ - resources :
36
+ kinds :
37
+ - Pod
38
+ selector :
39
+ matchLabels :
40
+ app : otel-agent
41
+ - resources :
42
+ kinds :
43
+ - Pod
44
+ selector :
45
+ matchLabels :
46
+ app.kubernetes.io/name : nirmata-kyverno-operator
47
+ - resources :
48
+ kinds :
49
+ - Pod
50
+ selector :
51
+ matchLabels :
52
+ app.kubernetes.io/component : admission-controller
53
+ - resources :
54
+ kinds :
55
+ - Pod
56
+ selector :
57
+ matchLabels :
58
+ app.kubernetes.io/component : cleanup-controller
59
+ - resources :
60
+ kinds :
61
+ - Pod
62
+ selector :
63
+ matchLabels :
64
+ app.kubernetes.io/component : background-controller
65
+ - resources :
66
+ kinds :
67
+ - Pod
68
+ selector :
69
+ matchLabels :
70
+ app.kubernetes.io/component : reports-controller
71
+ - resources :
72
+ kinds :
73
+ - Pod
74
+ selector :
75
+ matchLabels :
76
+ batch.kubernetes.io/job-name : " kyverno-cleanup-admission-reports-*"
77
+ - resources :
78
+ kinds :
79
+ - Pod
80
+ selector :
81
+ matchLabels :
82
+ batch.kubernetes.io/job-name=kyverno : " cleanup-cluster-admission-reports-*"
27
83
preconditions :
28
84
all :
29
85
- key : " {{ request.\" object\" .metadata.labels.\" app.kubernetes.io/part-of\" || '' }}"
Original file line number Diff line number Diff line change 24
24
- resources :
25
25
kinds :
26
26
- Pod
27
- exclude :
28
- any :
29
- - resources :
30
- kinds :
31
- - Pod
32
- selector :
33
- matchLabels :
34
- app : nirmata-kube-controller
35
- - resources :
36
- kinds :
37
- - Pod
38
- selector :
39
- matchLabels :
40
- app : otel-agent
41
- - resources :
42
- kinds :
43
- - Pod
44
- selector :
45
- matchLabels :
46
- app.kubernetes.io/name : nirmata-kyverno-operator
47
- - resources :
48
- kinds :
49
- - Pod
50
- selector :
51
- matchLabels :
52
- app.kubernetes.io/component : admission-controller
53
- - resources :
54
- kinds :
55
- - Pod
56
- selector :
57
- matchLabels :
58
- app.kubernetes.io/component : cleanup-controller
59
- - resources :
60
- kinds :
61
- - Pod
62
- selector :
63
- matchLabels :
64
- app.kubernetes.io/component : background-controller
65
- - resources :
66
- kinds :
67
- - Pod
68
- selector :
69
- matchLabels :
70
- app.kubernetes.io/component : reports-controller
71
- - resources :
72
- kinds :
73
- - Pod
74
- selector :
75
- matchLabels :
76
- batch.kubernetes.io/job-name : " kyverno-cleanup-admission-reports-*"
77
- - resources :
78
- kinds :
79
- - Pod
80
- selector :
81
- matchLabels :
82
- batch.kubernetes.io/job-name=kyverno : " cleanup-cluster-admission-reports-*"
83
27
preconditions :
84
28
all :
85
29
- key : " {{ request.\" object\" .metadata.labels.\" app.kubernetes.io/part-of\" || '' }}"
89
33
message : " Auto-mounting of Service Account tokens is not allowed."
90
34
pattern :
91
35
spec :
92
- automountServiceAccountToken : " false"
36
+ automountServiceAccountToken : " false"
You can’t perform that action at this time.
0 commit comments