File tree 7 files changed +20
-6
lines changed
charts/kubewarden-defaults/templates
7 files changed +20
-6
lines changed Original file line number Diff line number Diff line change @@ -68,3 +68,11 @@ namespaceSelector:
68
68
{ {- " " -} }
69
69
{ {- end -} }
70
70
{ {- end -} }
71
+
72
+ { {- define " policy-module" -} }
73
+ { {- if or (not .registry) (hasPrefix " http" .module) -} }
74
+ { {- printf " %s" .module -} }
75
+ { {- else -} }
76
+ { {- printf " %s/%s" .registry .module -} }
77
+ { {- end -} }
78
+ { {- end } }
Original file line number Diff line number Diff line change @@ -10,7 +10,8 @@ metadata:
10
10
name : {{ $.Values.recommendedPolicies.allowPrivilegeEscalationPolicy.name }}
11
11
spec :
12
12
mode : {{ $.Values.recommendedPolicies.defaultPolicyMode }}
13
- module : ' {{ template "system_default_registry" . }}{{ $.Values.recommendedPolicies.allowPrivilegeEscalationPolicy.module }}'
13
+ {{ $scope := dict "module" $.Values.recommendedPolicies.allowPrivilegeEscalationPolicy.module "registry" $.Values.common.cattle.systemDefaultRegistry }}
14
+ module : {{ template "policy-module" $scope }}
14
15
{{ include "policy-namespace-selector" . | indent 2}}
15
16
rules :
16
17
- apiGroups : [""]
Original file line number Diff line number Diff line change @@ -10,7 +10,8 @@ metadata:
10
10
name : {{ $.Values.recommendedPolicies.capabilitiesPolicy.name }}
11
11
spec :
12
12
mode : {{ $.Values.recommendedPolicies.defaultPolicyMode }}
13
- module : ' {{ template "system_default_registry" . }}{{ $.Values.recommendedPolicies.capabilitiesPolicy.module }}'
13
+ {{ $scope := dict "module" $.Values.recommendedPolicies.capabilitiesPolicy.module "registry" $.Values.common.cattle.systemDefaultRegistry }}
14
+ module : {{ template "policy-module" $scope }}
14
15
{{ include "policy-namespace-selector" . | indent 2}}
15
16
rules :
16
17
- apiGroups : [""]
Original file line number Diff line number Diff line change @@ -10,7 +10,8 @@ metadata:
10
10
name : {{ $.Values.recommendedPolicies.hostNamespacePolicy.name }}
11
11
spec :
12
12
mode : {{ $.Values.recommendedPolicies.defaultPolicyMode }}
13
- module : ' {{ template "system_default_registry" . }}{{ $.Values.recommendedPolicies.hostNamespacePolicy.module }}'
13
+ {{ $scope := dict "module" $.Values.recommendedPolicies.hostNamespacePolicy.module "registry" $.Values.common.cattle.systemDefaultRegistry }}
14
+ module : {{ template "policy-module" $scope }}
14
15
{{ include "policy-namespace-selector" . | indent 2}}
15
16
rules :
16
17
- apiGroups : [""]
Original file line number Diff line number Diff line change @@ -10,7 +10,8 @@ metadata:
10
10
name : {{ $.Values.recommendedPolicies.hostPathsPolicy.name }}
11
11
spec :
12
12
mode : {{ $.Values.recommendedPolicies.defaultPolicyMode }}
13
- module : ' {{ template "system_default_registry" . }}{{ $.Values.recommendedPolicies.hostPathsPolicy.module }}'
13
+ {{ $scope := dict "module" $.Values.recommendedPolicies.hostPathsPolicy.module "registry" $.Values.common.cattle.systemDefaultRegistry }}
14
+ module : {{ template "policy-module" $scope }}
14
15
{{ include "policy-namespace-selector" . | indent 2}}
15
16
rules :
16
17
- apiGroups : [""]
Original file line number Diff line number Diff line change @@ -10,7 +10,8 @@ metadata:
10
10
name : {{ $.Values.recommendedPolicies.podPrivilegedPolicy.name }}
11
11
spec :
12
12
mode : {{ $.Values.recommendedPolicies.defaultPolicyMode }}
13
- module : ' {{ template "system_default_registry" . }}{{ $.Values.recommendedPolicies.podPrivilegedPolicy.module }}'
13
+ {{ $scope := dict "module" $.Values.recommendedPolicies.podPrivilegedPolicy.module "registry" $.Values.common.cattle.systemDefaultRegistry }}
14
+ module : {{ template "policy-module" $scope }}
14
15
{{ include "policy-namespace-selector" . | indent 2}}
15
16
rules :
16
17
- apiGroups : [""]
Original file line number Diff line number Diff line change @@ -10,7 +10,8 @@ metadata:
10
10
name : {{ $.Values.recommendedPolicies.userGroupPolicy.name }}
11
11
spec :
12
12
mode : {{ $.Values.recommendedPolicies.defaultPolicyMode }}
13
- module : ' {{ template "system_default_registry" . }}{{ $.Values.recommendedPolicies.userGroupPolicy.module }}'
13
+ {{ $scope := dict "module" $.Values.recommendedPolicies.userGroupPolicy.module "registry" $.Values.common.cattle.systemDefaultRegistry }}
14
+ module : {{ template "policy-module" $scope }}
14
15
{{ include "policy-namespace-selector" . | indent 2}}
15
16
rules :
16
17
- apiGroups : [""]
You can’t perform that action at this time.
0 commit comments