Skip to content

Commit 74387e8

Browse files
committed
chore: excluded jobs and cronjobs
Signed-off-by: Ved Ratan <[email protected]>
1 parent 459b449 commit 74387e8

File tree

1 file changed

+20
-2
lines changed

1 file changed

+20
-2
lines changed

charts/rbac-best-practices/pols/restrict-automount-sa-token.yaml

+20-2
Original file line numberDiff line numberDiff line change
@@ -73,13 +73,31 @@ spec:
7373
- Pod
7474
selector:
7575
matchLabels:
76-
batch.kubernetes.io/job-name: "kyverno-cleanup-admission-reports-*"
76+
job-name: "kyverno-cleanup-admission-reports-*"
7777
- resources:
7878
kinds:
7979
- Pod
8080
selector:
8181
matchLabels:
82-
batch.kubernetes.io/job-name=kyverno: "cleanup-cluster-admission-reports-*"
82+
job-name: "kyverno-cleanup-cluster-admission-reports-*"
83+
- resources:
84+
kinds:
85+
- Pod
86+
selector:
87+
matchLabels:
88+
job-name: "kyverno-cleanup-ephemeral-reports-*"
89+
- resources:
90+
kinds:
91+
- Pod
92+
selector:
93+
matchLabels:
94+
job-name: "kyverno-cleanup-cluster-ephemeral-reports-*"
95+
- resources:
96+
kinds:
97+
- Pod
98+
selector:
99+
matchLabels:
100+
job-name: "kyverno-cleanup-update-requests-*"
83101
preconditions:
84102
all:
85103
- key: "{{ request.\"object\".metadata.labels.\"app.kubernetes.io/part-of\" || '' }}"

0 commit comments

Comments
 (0)