华为云UCS-k8sdisallowanonymous:策略实例示例

时间:2024-01-05 16:50:36

策略实例示例

示例展示了ClusterRole和Role资源仅能关联到allowedRoles中定义的Role。

apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sDisallowAnonymous
metadata:
  name: no-anonymous
spec:
  match:
    kinds:
      - apiGroups: ["rbac.authorization.k8s.io"]
        kinds: ["ClusterRoleBinding"]
      - apiGroups: ["rbac.authorization.k8s.io"]
        kinds: ["RoleBinding"]
  parameters:
    allowedRoles: 
      - cluster-role-1
support.huaweicloud.com/usermanual-ucs/ucs_01_0239.html