Files
container.training/k8s/kyverno-pod-color-1.yaml
Jérôme Petazzoni 785d704726 🏭️ Rework Kyverno chapter
2025-05-11 18:34:11 +02:00

23 lines
515 B
YAML

apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: pod-color-policy-1
spec:
rules:
- name: ensure-pod-color-is-valid
match:
resources:
kinds:
- Pod
selector:
matchExpressions:
- key: color
operator: Exists
- key: color
operator: NotIn
values: [ red, green, blue ]
validate:
failureAction: Enforce
message: "If it exists, the label color must be red, green, or blue."
deny: {}