Skip to content

Commit

Permalink
Added example manifest
Browse files Browse the repository at this point in the history
Signed-off-by: Sanskarzz <[email protected]>
  • Loading branch information
Sanskarzz authored and eddycharly committed Apr 22, 2024
1 parent 14d1e43 commit 6c5437b
Show file tree
Hide file tree
Showing 2 changed files with 51 additions and 0 deletions.
24 changes: 24 additions & 0 deletions sidecar-injector/example-manifest/exampledeploy.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: nginx
namespace: default
labels:
app.kubernetes.io/name: nginx
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: nginx
template:
metadata:
labels:
kyverno-envoy-sidecar/injection: enabled
app.kubernetes.io/name: nginx
spec:
containers:
- name: nginx
image: nginx:1.20.2
ports:
- containerPort: 80

27 changes: 27 additions & 0 deletions sidecar-injector/example-manifest/policyfile-configmap.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: policy-files
namespace: default
data:
policy.yaml: |
apiVersion: json.kyverno.io/v1alpha1
kind: ValidatingPolicy
metadata:
name: check-dockerfile
spec:
rules:
- name: deny-external-calls
assert:
all:
- message: "HTTP calls are not allowed"
check:
request:
http:
method: GET
headers:
authorization:
(base64_decode(split(@, ' ')[1])):
(split(@, ':')[0]): alice
path: /foo

0 comments on commit 6c5437b

Please sign in to comment.