diff --git a/charts/kubewarden-defaults/questions.yaml b/charts/kubewarden-defaults/questions.yaml index 7ba6dad2..1da30e76 100644 --- a/charts/kubewarden-defaults/questions.yaml +++ b/charts/kubewarden-defaults/questions.yaml @@ -51,7 +51,7 @@ questions: Number of replicas of the PolicyServer Deployment group: "Default PolicyServer HA" # no-privilege-escalation policy settings - - variable: recommendedPolicies.allowPrivilegeEscalationPolicy.settings.default_allow_privilege_escalation + - variable: recommendedPolicies.allowPrivilegeEscalationPolicy.settings.allowPrivilegeEscalation description: >- This policy works by inspecting the containers and init containers of a Pod. If any of these containers have `allowPrivilegeEscalation` enabled, the Pod diff --git a/charts/kubewarden-defaults/templates/allow-privileged-escalation-policy.yaml b/charts/kubewarden-defaults/templates/allow-privileged-escalation-policy.yaml index 15c8acfc..e293a946 100644 --- a/charts/kubewarden-defaults/templates/allow-privileged-escalation-policy.yaml +++ b/charts/kubewarden-defaults/templates/allow-privileged-escalation-policy.yaml @@ -21,5 +21,5 @@ spec: operations: ["CREATE"] # kubernetes doesn't allow to add/remove privileged containers to an already running pod mutating: true settings: - {{- toYaml .Values.recommendedPolicies.allowPrivilegeEscalationPolicy.settings | replace "|\n" "" | nindent 2 }} + {{- toYaml .Values.recommendedPolicies.allowPrivilegeEscalationPolicy.settings | replace "|\n" "" | nindent 4 }} {{ end }} diff --git a/charts/kubewarden-defaults/templates/capabilities-policy.yaml b/charts/kubewarden-defaults/templates/capabilities-policy.yaml index 527f6799..863b402c 100644 --- a/charts/kubewarden-defaults/templates/capabilities-policy.yaml +++ b/charts/kubewarden-defaults/templates/capabilities-policy.yaml @@ -23,5 +23,5 @@ spec: - UPDATE mutating: true settings: - {{- toYaml .Values.recommendedPolicies.capabilitiesPolicy.settings | replace "|\n" "" | nindent 2 }} + {{- toYaml .Values.recommendedPolicies.capabilitiesPolicy.settings | replace "|\n" "" | nindent 4 }} {{ end }} diff --git a/charts/kubewarden-defaults/templates/host-namespace-policy.yaml b/charts/kubewarden-defaults/templates/host-namespace-policy.yaml index 001cb632..ae0825c7 100644 --- a/charts/kubewarden-defaults/templates/host-namespace-policy.yaml +++ b/charts/kubewarden-defaults/templates/host-namespace-policy.yaml @@ -23,5 +23,5 @@ spec: - UPDATE mutating: false settings: - {{- toYaml .Values.recommendedPolicies.hostNamespacePolicy.settings | replace "|\n" "" | nindent 2 }} + {{- toYaml .Values.recommendedPolicies.hostNamespacePolicy.settings | replace "|\n" "" | nindent 4 }} {{ end }} diff --git a/charts/kubewarden-defaults/templates/host-path-policy.yaml b/charts/kubewarden-defaults/templates/host-path-policy.yaml index 1fa5e39f..b3e15438 100644 --- a/charts/kubewarden-defaults/templates/host-path-policy.yaml +++ b/charts/kubewarden-defaults/templates/host-path-policy.yaml @@ -23,5 +23,5 @@ spec: - UPDATE mutating: false settings: - {{- toYaml .Values.recommendedPolicies.hostPathsPolicy.settings | replace "|\n" "" | nindent 2 }} + {{- toYaml .Values.recommendedPolicies.hostPathsPolicy.settings | replace "|\n" "" | nindent 4 }} {{ end }} diff --git a/charts/kubewarden-defaults/templates/pod-privileged-policy.yaml b/charts/kubewarden-defaults/templates/pod-privileged-policy.yaml index 68e3ac32..7c448ceb 100644 --- a/charts/kubewarden-defaults/templates/pod-privileged-policy.yaml +++ b/charts/kubewarden-defaults/templates/pod-privileged-policy.yaml @@ -34,5 +34,5 @@ spec: operations: ["CREATE", "UPDATE"] mutating: false settings: - {{- toYaml .Values.recommendedPolicies.podPrivilegedPolicy.settings | replace "|\n" "" | nindent 2 }} + {{- toYaml .Values.recommendedPolicies.podPrivilegedPolicy.settings | replace "|\n" "" | nindent 4 }} {{ end }} diff --git a/charts/kubewarden-defaults/templates/user-group-policy.yaml b/charts/kubewarden-defaults/templates/user-group-policy.yaml index e69df328..a532925d 100644 --- a/charts/kubewarden-defaults/templates/user-group-policy.yaml +++ b/charts/kubewarden-defaults/templates/user-group-policy.yaml @@ -21,5 +21,5 @@ spec: operations: ["CREATE"] # kubernetes doesn't allow to add/remove privileged containers to an already running pod mutating: true settings: - {{- toYaml .Values.recommendedPolicies.userGroupPolicy.settings | replace "|\n" "" | nindent 2 }} + {{- toYaml .Values.recommendedPolicies.userGroupPolicy.settings | replace "|\n" "" | nindent 4 }} {{ end }} diff --git a/charts/kubewarden-defaults/values.yaml b/charts/kubewarden-defaults/values.yaml index 6836d3f8..12de668e 100644 --- a/charts/kubewarden-defaults/values.yaml +++ b/charts/kubewarden-defaults/values.yaml @@ -135,7 +135,7 @@ recommendedPolicies: tag: v0.2.6 name: "no-privilege-escalation" settings: - default_allow_privilege_escalation: false + allowPrivilegeEscalation: false hostNamespacePolicy: module: repository: "kubewarden/policies/host-namespaces-psp"