华为云UCS-k8sdisallowanonymous:策略实例示例

时间:2025-02-12 15:05:17

策略实例示例

示例展示了ClusterRole和Role资源仅能关联到allowedRoles中定义的Role。

apiVersion: constraints.gatekeeper.sh/v1beta1kind: K8sDisallowAnonymousmetadata:  name: no-anonymousspec:  match:    kinds:      - apiGroups: ["rbac.authorization.k8s.io"]        kinds: ["ClusterRoleBinding"]      - apiGroups: ["rbac.authorization.k8s.io"]        kinds: ["RoleBinding"]  parameters:    allowedRoles:       - cluster-role-1
support.huaweicloud.com/usermanual-ucs/ucs_01_0239.html