Skip to content

Commit 74b06ac

Browse files
authored
Merge pull request #375 from jvanz/issue374
fix: mutating policies targets pod only.
2 parents e0a923b + bc5c3a0 commit 74b06ac

File tree

2 files changed

+0
-24
lines changed

2 files changed

+0
-24
lines changed

charts/kubewarden-defaults/templates/allow-privileged-escalation-policy.yaml

-12
Original file line numberDiff line numberDiff line change
@@ -19,18 +19,6 @@ spec:
1919
apiVersions: ["v1"]
2020
resources: ["pods"]
2121
operations: ["CREATE"] # kubernetes doesn't allow to add/remove privileged containers to an already running pod
22-
- apiGroups: [""]
23-
apiVersions: ["v1"]
24-
resources: ["replicationcontrollers"]
25-
operations: ["CREATE", "UPDATE"]
26-
- apiGroups: ["apps"]
27-
apiVersions: ["v1"]
28-
resources: ["deployments","replicasets","statefulsets","daemonsets"]
29-
operations: ["CREATE", "UPDATE"]
30-
- apiGroups: ["batch"]
31-
apiVersions: ["v1"]
32-
resources: ["jobs","cronjobs"]
33-
operations: ["CREATE", "UPDATE"]
3422
mutating: true
3523
settings:
3624
default_allow_privilege_escalation: false

charts/kubewarden-defaults/templates/user-group-policy.yaml

-12
Original file line numberDiff line numberDiff line change
@@ -19,18 +19,6 @@ spec:
1919
apiVersions: ["v1"]
2020
resources: ["pods"]
2121
operations: ["CREATE"] # kubernetes doesn't allow to add/remove privileged containers to an already running pod
22-
- apiGroups: [""]
23-
apiVersions: ["v1"]
24-
resources: ["replicationcontrollers"]
25-
operations: ["CREATE", "UPDATE"]
26-
- apiGroups: ["apps"]
27-
apiVersions: ["v1"]
28-
resources: ["deployments","replicasets","statefulsets","daemonsets"]
29-
operations: ["CREATE", "UPDATE"]
30-
- apiGroups: ["batch"]
31-
apiVersions: ["v1"]
32-
resources: ["jobs","cronjobs"]
33-
operations: ["CREATE", "UPDATE"]
3422
mutating: true
3523
settings:
3624
run_as_user:

0 commit comments

Comments
 (0)