Skip to content
Snippets Groups Projects
Verified Commit a60b84e2 authored by Sheogorath's avatar Sheogorath :european_castle:
Browse files

feat(infrastructure): Use Pod Security Standards for infrastructure

This patch enables explicit pod security standards on all infrastructure
namespaces.
parent d399ec16
No related branches found
No related tags found
No related merge requests found
Showing with 62 additions and 9 deletions
......@@ -7,3 +7,6 @@ metadata:
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/warn: privileged
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
......@@ -3,5 +3,10 @@ kind: Namespace
metadata:
name: cert-manager
labels:
name: cert-manager
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
kyverno.shivering-isles.com/class: "system"
......@@ -3,5 +3,10 @@ kind: Namespace
metadata:
name: drivers-system
labels:
name: drivers-system
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/warn: privileged
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
kyverno.shivering-isles.com/class: "system"
......@@ -3,5 +3,10 @@ kind: Namespace
metadata:
name: k8up-system
labels:
name: k8up-system
kyverno.shivering-isles.com/class: "system"
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
kyverno.shivering-isles.com/class: "system"
......@@ -3,5 +3,10 @@ kind: Namespace
metadata:
name: kubenav-system
labels:
name: kubenav-system
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/enforce: restricted
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
kyverno.shivering-isles.com/class: "system"
......@@ -7,3 +7,6 @@ metadata:
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/warn: privileged
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
......@@ -9,3 +9,6 @@ metadata:
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/warn: privileged
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
......@@ -8,3 +8,6 @@ metadata:
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/warn: privileged
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
......@@ -9,3 +9,6 @@ metadata:
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/warn: privileged
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
......@@ -3,6 +3,11 @@ kind: Namespace
metadata:
name: nginx-system
labels:
name: nginx-system
kyverno.shivering-isles.com/class: "system"
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
kyverno.shivering-isles.com/class: "system"
ingress.shivering-isles.com/network-access-required: "true"
......@@ -8,3 +8,6 @@ metadata:
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: privileged
pod-security.kubernetes.io/warn: privileged
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
......@@ -3,6 +3,11 @@ kind: Namespace
metadata:
name: postgres-system
labels:
name: postgres-system
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
kyverno.shivering-isles.com/class: "system"
database.shivering-isles.com/network-access-required: "true"
......@@ -3,5 +3,10 @@ kind: Namespace
metadata:
name: starboard-system
labels:
name: starboard-system
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/audit-version: 1.23
pod-security.kubernetes.io/enforce-version: 1.23
pod-security.kubernetes.io/warn-version: 1.23
kyverno.shivering-isles.com/class: "system"
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment