From 75746eb32fc8f9dab5fe77430a0b7faf6e4d88dc Mon Sep 17 00:00:00 2001 From: Sheogorath <sheogorath@shivering-isles.com> Date: Sat, 1 Jul 2023 12:20:38 +0200 Subject: [PATCH] feat: Prepare PSS upgrade to 1.26 --- apps/base/forecastle/namespace.yaml | 4 ++-- apps/base/gitlab-runner/namespace.yaml | 4 ++-- apps/base/goharbor/namespace.yaml | 4 ++-- apps/base/hedgedoc/namespace.yaml | 4 ++-- apps/base/iot/namespace.yaml | 4 ++-- apps/base/keycloak/namespace.yaml | 4 ++-- apps/base/mail/namespace.yaml | 4 ++-- apps/base/mastodon/namespace.yaml | 4 ++-- apps/base/matrix/namespace.yaml | 4 ++-- apps/base/nextcloud/namespace.yaml | 4 ++-- apps/base/renovate/namespace.yaml | 4 ++-- apps/base/shields/namespace.yaml | 4 ++-- apps/base/uptime-kuma/namespace.yaml | 4 ++-- apps/k8s01/blog/namespace.yaml | 4 ++-- apps/k8s01/dns/namespace.yaml | 4 ++-- apps/k8s01/jellyfin/namespace.yaml | 4 ++-- apps/k8s01/nas/namespace.yaml | 4 ++-- apps/k8s01/syncthing/namespace.yaml | 4 ++-- bootstrap/calico/namespace.yaml | 4 ++-- infrastructure/cert-manager/namespace.yaml | 4 ++-- infrastructure/drivers/namespace.yaml | 4 ++-- infrastructure/k8up/namespace.yaml | 4 ++-- infrastructure/kubenav/namespace.yaml | 4 ++-- infrastructure/longhorn/namespace.yaml | 4 ++-- infrastructure/metallb/namespace.yaml | 4 ++-- infrastructure/monitoring/namespace.yaml | 4 ++-- infrastructure/nginx-system/namespace.yaml | 4 ++-- infrastructure/node-features/namespace.yaml | 4 ++-- infrastructure/postgres/namespace.yaml | 4 ++-- 29 files changed, 58 insertions(+), 58 deletions(-) diff --git a/apps/base/forecastle/namespace.yaml b/apps/base/forecastle/namespace.yaml index 63c98dc72..e64cf34a0 100644 --- a/apps/base/forecastle/namespace.yaml +++ b/apps/base/forecastle/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/gitlab-runner/namespace.yaml b/apps/base/gitlab-runner/namespace.yaml index bd3bc6e37..20956c02d 100644 --- a/apps/base/gitlab-runner/namespace.yaml +++ b/apps/base/gitlab-runner/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/goharbor/namespace.yaml b/apps/base/goharbor/namespace.yaml index 926731604..39f30e81b 100644 --- a/apps/base/goharbor/namespace.yaml +++ b/apps/base/goharbor/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/hedgedoc/namespace.yaml b/apps/base/hedgedoc/namespace.yaml index 757afa82b..c22f76295 100644 --- a/apps/base/hedgedoc/namespace.yaml +++ b/apps/base/hedgedoc/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/iot/namespace.yaml b/apps/base/iot/namespace.yaml index f0d7a626f..c22a70136 100644 --- a/apps/base/iot/namespace.yaml +++ b/apps/base/iot/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/keycloak/namespace.yaml b/apps/base/keycloak/namespace.yaml index 56ca77d0f..30e7fb6a2 100644 --- a/apps/base/keycloak/namespace.yaml +++ b/apps/base/keycloak/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/mail/namespace.yaml b/apps/base/mail/namespace.yaml index b1a5eae44..51dc2cf03 100644 --- a/apps/base/mail/namespace.yaml +++ b/apps/base/mail/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/mastodon/namespace.yaml b/apps/base/mastodon/namespace.yaml index 053b7f567..1000f77b6 100644 --- a/apps/base/mastodon/namespace.yaml +++ b/apps/base/mastodon/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/matrix/namespace.yaml b/apps/base/matrix/namespace.yaml index 796bc47fe..54780cb11 100644 --- a/apps/base/matrix/namespace.yaml +++ b/apps/base/matrix/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/nextcloud/namespace.yaml b/apps/base/nextcloud/namespace.yaml index 94b1c0065..bb80fa9d1 100644 --- a/apps/base/nextcloud/namespace.yaml +++ b/apps/base/nextcloud/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/renovate/namespace.yaml b/apps/base/renovate/namespace.yaml index a92d2dc3b..0adc8bab8 100644 --- a/apps/base/renovate/namespace.yaml +++ b/apps/base/renovate/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/shields/namespace.yaml b/apps/base/shields/namespace.yaml index e2e5d8d30..356f444e7 100644 --- a/apps/base/shields/namespace.yaml +++ b/apps/base/shields/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/base/uptime-kuma/namespace.yaml b/apps/base/uptime-kuma/namespace.yaml index 868f08fd0..bb0829864 100644 --- a/apps/base/uptime-kuma/namespace.yaml +++ b/apps/base/uptime-kuma/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/k8s01/blog/namespace.yaml b/apps/k8s01/blog/namespace.yaml index 30c8ee4f6..63397c4ce 100644 --- a/apps/k8s01/blog/namespace.yaml +++ b/apps/k8s01/blog/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/k8s01/dns/namespace.yaml b/apps/k8s01/dns/namespace.yaml index 0514af478..9f9054d72 100644 --- a/apps/k8s01/dns/namespace.yaml +++ b/apps/k8s01/dns/namespace.yaml @@ -6,6 +6,6 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 diff --git a/apps/k8s01/jellyfin/namespace.yaml b/apps/k8s01/jellyfin/namespace.yaml index 39fb12d96..1dbc13b46 100644 --- a/apps/k8s01/jellyfin/namespace.yaml +++ b/apps/k8s01/jellyfin/namespace.yaml @@ -6,9 +6,9 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 --- apiVersion: v1 kind: ServiceAccount diff --git a/apps/k8s01/nas/namespace.yaml b/apps/k8s01/nas/namespace.yaml index 6b4ae7650..84f7b4729 100644 --- a/apps/k8s01/nas/namespace.yaml +++ b/apps/k8s01/nas/namespace.yaml @@ -6,6 +6,6 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 diff --git a/apps/k8s01/syncthing/namespace.yaml b/apps/k8s01/syncthing/namespace.yaml index 416decd38..ab20cae9e 100644 --- a/apps/k8s01/syncthing/namespace.yaml +++ b/apps/k8s01/syncthing/namespace.yaml @@ -6,6 +6,6 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 diff --git a/bootstrap/calico/namespace.yaml b/bootstrap/calico/namespace.yaml index 0c174b9ed..e5d0af546 100644 --- a/bootstrap/calico/namespace.yaml +++ b/bootstrap/calico/namespace.yaml @@ -7,6 +7,6 @@ metadata: pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/audit: privileged pod-security.kubernetes.io/warn: privileged - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 diff --git a/infrastructure/cert-manager/namespace.yaml b/infrastructure/cert-manager/namespace.yaml index ada53bc70..be986f00d 100644 --- a/infrastructure/cert-manager/namespace.yaml +++ b/infrastructure/cert-manager/namespace.yaml @@ -6,7 +6,7 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 kyverno.shivering-isles.com/class: "system" diff --git a/infrastructure/drivers/namespace.yaml b/infrastructure/drivers/namespace.yaml index cb31c94fe..d74672cbe 100644 --- a/infrastructure/drivers/namespace.yaml +++ b/infrastructure/drivers/namespace.yaml @@ -6,7 +6,7 @@ metadata: pod-security.kubernetes.io/audit: privileged pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/warn: privileged - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 kyverno.shivering-isles.com/class: "system" diff --git a/infrastructure/k8up/namespace.yaml b/infrastructure/k8up/namespace.yaml index 1be682621..0dc7b5953 100644 --- a/infrastructure/k8up/namespace.yaml +++ b/infrastructure/k8up/namespace.yaml @@ -6,7 +6,7 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 kyverno.shivering-isles.com/class: "system" diff --git a/infrastructure/kubenav/namespace.yaml b/infrastructure/kubenav/namespace.yaml index 078a2f040..905d3132c 100644 --- a/infrastructure/kubenav/namespace.yaml +++ b/infrastructure/kubenav/namespace.yaml @@ -6,7 +6,7 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: restricted pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 kyverno.shivering-isles.com/class: "system" diff --git a/infrastructure/longhorn/namespace.yaml b/infrastructure/longhorn/namespace.yaml index 608df4c46..5bb9da6b0 100644 --- a/infrastructure/longhorn/namespace.yaml +++ b/infrastructure/longhorn/namespace.yaml @@ -9,6 +9,6 @@ metadata: pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/audit: privileged pod-security.kubernetes.io/warn: privileged - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 diff --git a/infrastructure/metallb/namespace.yaml b/infrastructure/metallb/namespace.yaml index 142008a08..59eeac4a4 100644 --- a/infrastructure/metallb/namespace.yaml +++ b/infrastructure/metallb/namespace.yaml @@ -8,6 +8,6 @@ metadata: pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/audit: privileged pod-security.kubernetes.io/warn: privileged - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 diff --git a/infrastructure/monitoring/namespace.yaml b/infrastructure/monitoring/namespace.yaml index f54e7ffae..112c91933 100644 --- a/infrastructure/monitoring/namespace.yaml +++ b/infrastructure/monitoring/namespace.yaml @@ -9,6 +9,6 @@ metadata: pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/audit: privileged pod-security.kubernetes.io/warn: privileged - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 diff --git a/infrastructure/nginx-system/namespace.yaml b/infrastructure/nginx-system/namespace.yaml index a8136ba4f..c11fd961f 100644 --- a/infrastructure/nginx-system/namespace.yaml +++ b/infrastructure/nginx-system/namespace.yaml @@ -6,8 +6,8 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 kyverno.shivering-isles.com/class: "system" ingress.shivering-isles.com/network-access-required: "true" diff --git a/infrastructure/node-features/namespace.yaml b/infrastructure/node-features/namespace.yaml index b63cc38e3..fd79543ef 100644 --- a/infrastructure/node-features/namespace.yaml +++ b/infrastructure/node-features/namespace.yaml @@ -8,6 +8,6 @@ metadata: pod-security.kubernetes.io/enforce: privileged pod-security.kubernetes.io/audit: privileged pod-security.kubernetes.io/warn: privileged - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 diff --git a/infrastructure/postgres/namespace.yaml b/infrastructure/postgres/namespace.yaml index dcebd7d90..c6134dfa1 100644 --- a/infrastructure/postgres/namespace.yaml +++ b/infrastructure/postgres/namespace.yaml @@ -6,8 +6,8 @@ metadata: pod-security.kubernetes.io/audit: restricted pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/audit-version: v1.23 + pod-security.kubernetes.io/audit-version: v1.26 pod-security.kubernetes.io/enforce-version: v1.23 - pod-security.kubernetes.io/warn-version: v1.23 + pod-security.kubernetes.io/warn-version: v1.26 kyverno.shivering-isles.com/class: "system" database.shivering-isles.com/network-access-required: "true" -- GitLab