File tree Expand file tree Collapse file tree 3 files changed +6
-6
lines changed Expand file tree Collapse file tree 3 files changed +6
-6
lines changed Original file line number Diff line number Diff line change @@ -273,8 +273,8 @@ admission_control_eventratelimit_file: "admission-eventratelimit.yaml" # the fil
273
273
274
274
# ValidatingAdmissionPolicy
275
275
# NOTE: Section 5 requires Kubernetes version v1.30.0 and above
276
- vap_exclude_system_namespace_crd : " vap-exclude-system-namespace -crd.yml"
277
- vap_cis_exclude_system_namespace_params : " vap-cis-exclude-system-namespace-params .yml" # Please verify the namespaceExclusion
276
+ vap_cis_validation_parameters_crd : " vap-cis-validation-parameters -crd.yml"
277
+ vap_cis_validation_parameters : " vap-cis-validation-parameters .yml" # Please verify the excludeSystemNamespaces, allowedRegistries, maxReplicas
278
278
vap_cis_enforce_runasnonroot_policy : " vap-cis-enforce-runasnonroot-policy.yml"
279
279
vap_cis_enforce_runasnonroot_policy_binding : " vap-cis-enforce-runasnonroot-policy-binding.yml"
280
280
vap_cis_minimize_addition_of_limited_capabilities_policy : " vap-cis-minimize-addition-of-limited-capabilities-policy.yml"
Original file line number Diff line number Diff line change 8
8
until : apiserver_start_5_0_0.stdout|length > 0
9
9
retries : 120
10
10
delay : 1
11
- - name : " 5.0.0 | PRE-REQ | Apply CRD for ValidatingAdmissionPolicy {{ vap_exclude_system_namespace_crd }}"
11
+ - name : " 5.0.0 | PRE-REQ | Apply CRD for ValidatingAdmissionPolicy {{ vap_cis_validation_parameters_crd }}"
12
12
ansible.builtin.command : kubectl --kubeconfig={{ kubeconfig_path }} apply -f -
13
13
args :
14
- stdin : " {{ lookup('file', vap_exclude_system_namespace_crd ) }}"
14
+ stdin : " {{ lookup('file', vap_cis_validation_parameters_crd ) }}"
15
15
register : crd_5_0_0
16
16
changed_when : " 'created' in crd_5_0_0.stdout"
17
- - name : " 5.0.0 | PRE-REQ | Apply Paramerters for ValidatingAdmissionPolicy {{ vap_cis_exclude_system_namespace_params }}"
17
+ - name : " 5.0.0 | PRE-REQ | Apply Paramerters for ValidatingAdmissionPolicy {{ vap_cis_validation_parameters }}"
18
18
ansible.builtin.command : kubectl --kubeconfig={{ kubeconfig_path }} apply -f -
19
19
args :
20
- stdin : " {{ lookup('file', vap_cis_exclude_system_namespace_params ) }}"
20
+ stdin : " {{ lookup('file', vap_cis_validation_parameters ) }}"
21
21
register : params_5_0_0
22
22
changed_when : " 'created' in params_5_0_0.stdout"
23
23
run_once : true
You can’t perform that action at this time.
0 commit comments