华为云UCS-k8sdisallowedtags:策略实例示例

时间:2024-01-05 16:50:39

策略实例示例

以下策略实例展示了策略定义生效的资源类型,pararmeters中表示不允许容器镜像tag为latest。

apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sDisallowedTags
metadata:
  name: container-image-must-not-have-latest-tag
spec:
  match:
    kinds:
      - apiGroups: [""]
        kinds: ["Pod"]
    namespaces:
      - "default"
  parameters:
    tags: ["latest"]
    exemptImages: ["openpolicyagent/opa-exp:latest", "openpolicyagent/opa-exp2:latest"] 
support.huaweicloud.com/usermanual-ucs/ucs_01_0238.html