-
Notifications
You must be signed in to change notification settings - Fork 240
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: add best practices policies in CEL expressions #925
feat: add best practices policies in CEL expressions #925
Commits on Mar 6, 2024
-
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 747b0e8 - Browse repository at this point
Copy the full SHA 747b0e8View commit details -
convert restrict-node-port to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 9a4eca2 - Browse repository at this point
Copy the full SHA 9a4eca2View commit details -
move resource files to test folders to avoid cross referencing
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for c87dea8 - Browse repository at this point
Copy the full SHA c87dea8View commit details -
Configuration menu - View commit details
-
Copy full SHA for 66550fb - Browse repository at this point
Copy the full SHA 66550fbView commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for a19e614 - Browse repository at this point
Copy the full SHA a19e614View commit details -
copy restrict-service-external-ips
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 793c146 - Browse repository at this point
Copy the full SHA 793c146View commit details
Commits on Mar 7, 2024
-
convert restrict-service-external-ips to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 7a0fc6a - Browse repository at this point
Copy the full SHA 7a0fc6aView commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 2466c52 - Browse repository at this point
Copy the full SHA 2466c52View commit details -
convert require-ro-rootfs to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 8ca2823 - Browse repository at this point
Copy the full SHA 8ca2823View commit details -
copy restrict-image-registries
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for cc534a2 - Browse repository at this point
Copy the full SHA cc534a2View commit details -
convert restrict-image-registries to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 70c4712 - Browse repository at this point
Copy the full SHA 70c4712View commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 9cbc613 - Browse repository at this point
Copy the full SHA 9cbc613View commit details -
convert disallow-latest-tag to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 7266245 - Browse repository at this point
Copy the full SHA 7266245View commit details
Commits on Mar 8, 2024
-
copy disallow-default-namespace
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 56680c9 - Browse repository at this point
Copy the full SHA 56680c9View commit details -
convert disallow-default-namespace to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for deefeee - Browse repository at this point
Copy the full SHA deefeeeView commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for c0b203a - Browse repository at this point
Copy the full SHA c0b203aView commit details -
convert disallow-helm-tiller to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 2908df9 - Browse repository at this point
Copy the full SHA 2908df9View commit details
Commits on Mar 9, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 5291e6d - Browse repository at this point
Copy the full SHA 5291e6dView commit details -
copy disallow-empty-ingress-host
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for cc5a3da - Browse repository at this point
Copy the full SHA cc5a3daView commit details -
set original disallow-empty-ingress-host to Audit
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 13f8cb5 - Browse repository at this point
Copy the full SHA 13f8cb5View commit details -
convert disallow-empty-ingress-host to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for b29888f - Browse repository at this point
Copy the full SHA b29888fView commit details -
patch cel policy to set it to Enforce in chainsaw test
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 1347c26 - Browse repository at this point
Copy the full SHA 1347c26View commit details
Commits on Mar 10, 2024
-
fix: update semantically wrong chainsaw test resources in original re…
…quire-drop-all policy Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 638431a - Browse repository at this point
Copy the full SHA 638431aView commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for c1cf234 - Browse repository at this point
Copy the full SHA c1cf234View commit details -
convert require-drop-all to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 625ee8e - Browse repository at this point
Copy the full SHA 625ee8eView commit details -
update workflow to test policies in best-practices-cel folder
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 0283264 - Browse repository at this point
Copy the full SHA 0283264View commit details -
fix duplicate container names in require-probes chainsaw test
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for e206f7c - Browse repository at this point
Copy the full SHA e206f7cView commit details -
Configuration menu - View commit details
-
Copy full SHA for c3b399e - Browse repository at this point
Copy the full SHA c3b399eView commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 13f20c0 - Browse repository at this point
Copy the full SHA 13f20c0View commit details
Commits on Mar 14, 2024
-
require-ro-rootfs: fix selector does not match template labels
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 3405d61 - Browse repository at this point
Copy the full SHA 3405d61View commit details -
require-ro-rootfs: fix duplicate container names
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 6f0f536 - Browse repository at this point
Copy the full SHA 6f0f536View commit details -
disallow-helm-tiller: fix invalid container naming
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 28a0b2b - Browse repository at this point
Copy the full SHA 28a0b2bView commit details -
require-labels: fix selector does not match template labels
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 4deb30c - Browse repository at this point
Copy the full SHA 4deb30cView commit details -
restrict-image-registries: fix selector does not match template labels
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 1ee5e25 - Browse repository at this point
Copy the full SHA 1ee5e25View commit details -
Configuration menu - View commit details
-
Copy full SHA for 9527da4 - Browse repository at this point
Copy the full SHA 9527da4View commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for e809be1 - Browse repository at this point
Copy the full SHA e809be1View commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 62fc668 - Browse repository at this point
Copy the full SHA 62fc668View commit details -
convert disallow-cri-sock-mount to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for f26b1b2 - Browse repository at this point
Copy the full SHA f26b1b2View commit details -
remove duplicate expressins in require-drop-all
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 9579075 - Browse repository at this point
Copy the full SHA 9579075View commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 46574a1 - Browse repository at this point
Copy the full SHA 46574a1View commit details -
require-drop-cap-net-raw: fix duplicate container names
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 2d25227 - Browse repository at this point
Copy the full SHA 2d25227View commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for de2993a - Browse repository at this point
Copy the full SHA de2993aView commit details
Commits on Mar 15, 2024
-
rename pods to distinguish them
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 057814d - Browse repository at this point
Copy the full SHA 057814dView commit details -
convert require-drop-cap-net-raw to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 618b7c8 - Browse repository at this point
Copy the full SHA 618b7c8View commit details -
copy require-pod-requests-limits
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 1fc12c0 - Browse repository at this point
Copy the full SHA 1fc12c0View commit details -
convert require-pod-requests-limits to cel
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for fdb9a00 - Browse repository at this point
Copy the full SHA fdb9a00View commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for ffe9192 - Browse repository at this point
Copy the full SHA ffe9192View commit details -
add new line at end of file where not present
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for f3f84ec - Browse repository at this point
Copy the full SHA f3f84ecView commit details -
Configuration menu - View commit details
-
Copy full SHA for 42808ba - Browse repository at this point
Copy the full SHA 42808baView commit details -
Configuration menu - View commit details
-
Copy full SHA for c13bf5a - Browse repository at this point
Copy the full SHA c13bf5aView commit details -
Configuration menu - View commit details
-
Copy full SHA for 6298f7e - Browse repository at this point
Copy the full SHA 6298f7eView commit details -
remove celPreconditions until it behaves as expected
Related to issue kyverno/kyverno#9884 Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for b71dc85 - Browse repository at this point
Copy the full SHA b71dc85View commit details -
Configuration menu - View commit details
-
Copy full SHA for 8bef250 - Browse repository at this point
Copy the full SHA 8bef250View commit details
Commits on Mar 16, 2024
-
The update to goodpod01 fails not due to Kyverno blocking it, but rather because Kubernetes doesn't permit such modifications on pods. Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 48675be - Browse repository at this point
Copy the full SHA 48675beView commit details
Commits on Mar 18, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 8c6b717 - Browse repository at this point
Copy the full SHA 8c6b717View commit details
Commits on Mar 25, 2024
-
Configuration menu - View commit details
-
Copy full SHA for db6f0a4 - Browse repository at this point
Copy the full SHA db6f0a4View commit details -
use variables to remove duplicate logic
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 51a0c3e - Browse repository at this point
Copy the full SHA 51a0c3eView commit details
Commits on Mar 26, 2024
-
remove unnecessary whitespace in require-ro-rootfs
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for cc3be8a - Browse repository at this point
Copy the full SHA cc3be8aView commit details -
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 734f9f2 - Browse repository at this point
Copy the full SHA 734f9f2View commit details
Commits on Apr 4, 2024
-
Combine expressions into 1 rule to generate VAPs
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 9f493ed - Browse repository at this point
Copy the full SHA 9f493edView commit details
Commits on Apr 19, 2024
-
copy kyverno tests for disallow-default-namespace
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 8e133b7 - Browse repository at this point
Copy the full SHA 8e133b7View commit details -
Configuration menu - View commit details
-
Copy full SHA for bc57d09 - Browse repository at this point
Copy the full SHA bc57d09View commit details
Commits on May 15, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 044a419 - Browse repository at this point
Copy the full SHA 044a419View commit details
Commits on May 16, 2024
-
Configuration menu - View commit details
-
Copy full SHA for bb48b70 - Browse repository at this point
Copy the full SHA bb48b70View commit details -
Configuration menu - View commit details
-
Copy full SHA for 6a71ee2 - Browse repository at this point
Copy the full SHA 6a71ee2View commit details
Commits on May 22, 2024
-
Configuration menu - View commit details
-
Copy full SHA for cad31da - Browse repository at this point
Copy the full SHA cad31daView commit details
Commits on May 30, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 3cda1d5 - Browse repository at this point
Copy the full SHA 3cda1d5View commit details -
fix issue caused in cel policies tests due to chainsaw templating
Signed-off-by: Chandan-DK <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for d6ad7cd - Browse repository at this point
Copy the full SHA d6ad7cdView commit details
Commits on Jun 3, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 8ca2e18 - Browse repository at this point
Copy the full SHA 8ca2e18View commit details