Skip to content

Commit 9cfa781

Browse files
joelanfordci-robot
authored andcommitted
UPSTREAM: <carry>: namespace: use privileged PSA for audit and warn levels
Signed-off-by: Joe Lanford <[email protected]>
1 parent e9e41bc commit 9cfa781

File tree

2 files changed

+9
-0
lines changed

2 files changed

+9
-0
lines changed

openshift/kustomize/overlays/openshift/olmv1-ns/patches/manager_namespace_privileged.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,4 +3,9 @@ kind: Namespace
33
metadata:
44
name: system
55
labels:
6+
pod-security.kubernetes.io/audit: privileged
7+
pod-security.kubernetes.io/audit-version: latest
8+
pod-security.kubernetes.io/warn: privileged
9+
pod-security.kubernetes.io/warn-version: latest
610
pod-security.kubernetes.io/enforce: privileged
11+
pod-security.kubernetes.io/enforce-version: latest

openshift/manifests/00-namespace-openshift-operator-controller.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,12 @@ apiVersion: v1
22
kind: Namespace
33
metadata:
44
labels:
5+
pod-security.kubernetes.io/audit: privileged
6+
pod-security.kubernetes.io/audit-version: latest
57
pod-security.kubernetes.io/enforce: privileged
68
pod-security.kubernetes.io/enforce-version: latest
9+
pod-security.kubernetes.io/warn: privileged
10+
pod-security.kubernetes.io/warn-version: latest
711
name: openshift-operator-controller
812
annotations:
913
workload.openshift.io/allowed: management

0 commit comments

Comments
 (0)