-
Notifications
You must be signed in to change notification settings - Fork 945
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Default Kyverno policies for OpenEBS #3385
Comments
|
Another policy engine to consider is KubeWarden . There is already a policy hub which has most PSPs implemented. Writing the policy is fairly simple too: https://docs.kubewarden.io/writing-policies/go/04-validation.html |
|
Pushing this from slack thread. Jim Bugwadia 27 minutes ago @kiranmova - thanks for asking!
The last one may be important, as its critical to allow flexibility. Jim Bugwadia 25 minutes ago |


OpenEBS cStor and Jiva projects involve managing K8s custom resources via the engine operators.
OpenEBS currently uses:
PSP is getting deprecated in the upcoming K8s releases and webhook admission controller has a number of gotchas w.r.t certificate and policy management.
This feature is to track the adoption of Kyverno for performing enforcing security and validation policies.
Kyverno also can be extended for pushing image pull secrets into the pods that are launched by OpenEBS operators.
The text was updated successfully, but these errors were encountered: