Giter Club home page Giter Club logo

Comments (20)

sathieu avatar sathieu commented on May 30, 2024 3

@ritazh I think only one chart is needed (but I'm ok with having two).

On the versioning maybe we could use the max as chart version, and bump all policies to this same version?

Alternatively, the chart version can be independant, and bumped according to semantic versioning.

from gatekeeper-library.

sathieu avatar sathieu commented on May 30, 2024 2

Not stale, and related to #47 .

from gatekeeper-library.

kfox1111 avatar kfox1111 commented on May 30, 2024 1

Yeah.

Maybe a chart that includes all the ConstraintTemplate's and then maybe some default disabled but easily enable-able default restricted buckets like those? That way its easy to load the library of ConstraintTemplates and enable them as you need them with some sane defaults?

from gatekeeper-library.

starlightromero avatar starlightromero commented on May 30, 2024 1

@kfox1111 Would appreciate your feedback on PR #356

from gatekeeper-library.

kfox1111 avatar kfox1111 commented on May 30, 2024

Maybe related to #47

from gatekeeper-library.

sozercan avatar sozercan commented on May 30, 2024

Are you looking for helm chart for PSPs? In the past, we discussed aligning them into default, restricted buckets that's detailed under https://kubernetes.io/docs/concepts/security/pod-security-standards/. Is this close to what you are looking for?

from gatekeeper-library.

kfox1111 avatar kfox1111 commented on May 30, 2024

Maybe useful to https://github.com/kubernetes/community/tree/master/wg-multitenancy as well.

from gatekeeper-library.

stale avatar stale commented on May 30, 2024

This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

from gatekeeper-library.

stale avatar stale commented on May 30, 2024

This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

from gatekeeper-library.

sathieu avatar sathieu commented on May 30, 2024

not stale.

Having an helm chart would help installation.

from gatekeeper-library.

ritazh avatar ritazh commented on May 30, 2024

@kfox1111 @sathieu are you looking for specific groups of policies that can be part of a helm chart? Currently for validating policies, we have psp and general. are you looking for 1 helm chart for all psps (maybe filtered by PSS profile level) and 1 for all general policies or just a single helm chart for all?

Another concern: because each policy has its own version, it would be hard to determine how to update the chart's version whenever one of the policies bumps the version.

from gatekeeper-library.

starlightromero avatar starlightromero commented on May 30, 2024

I agree with the chart version being independent. Usually the Helm chart version is not tied to the application/library version. In a Chart.yaml file, you will typically find the arguments version and appVersion.

from gatekeeper-library.

stale avatar stale commented on May 30, 2024

This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

from gatekeeper-library.

sozercan avatar sozercan commented on May 30, 2024

another approach we discussed in the past was a CLI (similar to krew or brew), where users can add/remove/sync policies.

from gatekeeper-library.

kfox1111 avatar kfox1111 commented on May 30, 2024

CLI's are harder to integrate into CI/CD systems.

from gatekeeper-library.

sozercan avatar sozercan commented on May 30, 2024

@kfox1111 would you elaborate more in your concerns? isn't helm a cli?

from gatekeeper-library.

kfox1111 avatar kfox1111 commented on May 30, 2024

It isn't when your using a tool such as https://fluxcd.io/ (like: https://fluxcd.io/flux/guides/helmreleases/) or argocd (like: https://argo-cd.readthedocs.io/en/stable/user-guide/helm/)

Kubernetes objects are how you are causing deployment of the charts.

from gatekeeper-library.

starlightromero avatar starlightromero commented on May 30, 2024

Or in my case, using the Helm Terraform provider, the policies can be codified and on VCS push, a Terraform run is triggered in Terraform Cloud.

from gatekeeper-library.

stale avatar stale commented on May 30, 2024

This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

from gatekeeper-library.

kfox1111 avatar kfox1111 commented on May 30, 2024

/repoen
/notcompleted

from gatekeeper-library.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.