Question: exclusions to PodSecurity sub-rule #1041
Unanswered
sachintiptur
asked this question in
Q&A
Replies: 1 comment
-
Converted to discussion. Because that control is applicable at the Pod level and not container level, the way you'd have to achieve it is by using the standalone policy and modifying it or using a Policy Exception against that policy. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I am trying to write a clusterpolicy using PodSecurity sub-rule at restricted level. Though this acts as a single rule and simplifies policy writing, I am finding difficulty in excluding some controls for some of the pods. As
images
can be used for only some of the container levelcontrolName
, I am not able to mention exclusions forcontrolName
that does not support images. For ex:controlName: Volume Types
cannot have image level exclusions.Is there any way to achieve this using PodSecurity sub-rule to mention exclusions?
Kyverno version: 1.12
Beta Was this translation helpful? Give feedback.
All reactions