Comments (20)
@ritazh I think only one chart is needed (but I'm ok with having two).
On the versioning maybe we could use the max as chart version, and bump all policies to this same version?
Alternatively, the chart version can be independant, and bumped according to semantic versioning.
from gatekeeper-library.
Not stale, and related to #47 .
from gatekeeper-library.
Yeah.
Maybe a chart that includes all the ConstraintTemplate's and then maybe some default disabled but easily enable-able default restricted buckets like those? That way its easy to load the library of ConstraintTemplates and enable them as you need them with some sane defaults?
from gatekeeper-library.
@kfox1111 Would appreciate your feedback on PR #356
from gatekeeper-library.
Maybe related to #47
from gatekeeper-library.
Are you looking for helm chart for PSPs? In the past, we discussed aligning them into default, restricted buckets that's detailed under https://kubernetes.io/docs/concepts/security/pod-security-standards/. Is this close to what you are looking for?
from gatekeeper-library.
Maybe useful to https://github.com/kubernetes/community/tree/master/wg-multitenancy as well.
from gatekeeper-library.
This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.
from gatekeeper-library.
This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.
from gatekeeper-library.
not stale.
Having an helm chart would help installation.
from gatekeeper-library.
@kfox1111 @sathieu are you looking for specific groups of policies that can be part of a helm chart? Currently for validating policies, we have psp and general. are you looking for 1 helm chart for all psps (maybe filtered by PSS profile level) and 1 for all general policies or just a single helm chart for all?
Another concern: because each policy has its own version, it would be hard to determine how to update the chart's version whenever one of the policies bumps the version.
from gatekeeper-library.
I agree with the chart version being independent. Usually the Helm chart version is not tied to the application/library version. In a Chart.yaml
file, you will typically find the arguments version
and appVersion
.
from gatekeeper-library.
This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.
from gatekeeper-library.
another approach we discussed in the past was a CLI (similar to krew
or brew
), where users can add/remove/sync policies.
from gatekeeper-library.
CLI's are harder to integrate into CI/CD systems.
from gatekeeper-library.
@kfox1111 would you elaborate more in your concerns? isn't helm a cli?
from gatekeeper-library.
It isn't when your using a tool such as https://fluxcd.io/ (like: https://fluxcd.io/flux/guides/helmreleases/) or argocd (like: https://argo-cd.readthedocs.io/en/stable/user-guide/helm/)
Kubernetes objects are how you are causing deployment of the charts.
from gatekeeper-library.
Or in my case, using the Helm Terraform provider, the policies can be codified and on VCS push, a Terraform run is triggered in Terraform Cloud.
from gatekeeper-library.
This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.
from gatekeeper-library.
/repoen
/notcompleted
from gatekeeper-library.
Related Issues (20)
- Migrate require-sync CI to future gatekeeper 3.13 requires-sync-data unmarshal function
- Apply constraints for immutable fields only to CREATE operations HOT 10
- enforcementAction: deny is not respected when creating/changing to an incorrect PDB HOT 1
- Update Privileged Container Policy HOT 3
- Host networking constraint template does not respect exempt images HOT 2
- Refresh the content in Artifact-hub whenever any of the files within the policy are modified HOT 2
- docs: explicitly call out samples are provided as an example
- add cel-based policies HOT 4
- Match everything in a constraint HOT 2
- Docs exclude kind: AdmissionReview
- Problem with creating a mutation for deployments HOT 4
- replicalimits unit tests do not include checks for Scale resources HOT 4
- Consider validating pod generic ephemerals in K8sStorageClass HOT 2
- Consolidating Kubernetes PSP-related ConstraintTemplates into a Single Template for Streamlined Migration HOT 1
- bump mutate assign api version from alpha to v1
- Website generator appears to only retain the final mutation sample per directory HOT 2
- Any interest in policies/constraints that apply to custom resources? HOT 3
- Workflow Upload artifacts: overwrites the matrixed job logs HOT 1
- k8spsphostnetworkingports exemptImages does not allow hostNetwork HOT 4
- automount-serviceaccount-token ConstraintTemplate does not reflect ServiceAccount settings HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from gatekeeper-library.