华为云UCS-k8spspvolumetypes:策略实例示例

时间:2024-09-12 15:06:02

策略实例示例

以下策略实例展示了策略定义生效的资源类型,parameters的volumes字段定义了允许的类型列表。

apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sPSPVolumeTypes
metadata:
  name: psp-volume-types
spec:
  match:
    kinds:
      - apiGroups: [""]
        kinds: ["Pod"]
  parameters:
    volumes:
    # - "*" # * may be used to allow all volume types
    - configMap
    - emptyDir
    - projected
    - secret
    - downwardAPI
    - persistentVolumeClaim
    #- hostPath #required for allowedHostPaths
    - flexVolume #required for allowedFlexVolumes
support.huaweicloud.com/usermanual-ucs/ucs_01_0215.html