华为云UCS-k8sdisallowedtags:策略实例示例

时间:2025-01-26 10:49:46

策略实例示例

以下策略实例展示了策略定义生效的资源类型,pararmeters中表示不允许容器镜像tag为latest。

apiVersion: constraints.gatekeeper.sh/v1beta1kind: K8sDisallowedTagsmetadata:  name: container-image-must-not-have-latest-tagspec:  match:    kinds:      - apiGroups: [""]        kinds: ["Pod"]    namespaces:      - "default"  parameters:    tags: ["latest"]    exemptImages: ["openpolicyagent/opa-exp:latest", "openpolicyagent/opa-exp2:latest"] 
support.huaweicloud.com/usermanual-ucs/ucs_01_0238.html