fix: disable s3 secret policy

This commit is contained in:
2025-06-20 15:28:04 +02:00
parent 8b7609b99d
commit f7303521b6
@@ -1,34 +1,34 @@
{{- if .Values.clusterConfig.kyverno.enabled }}
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
annotations:
policies.clusterConfig.kyverno.io/description: 'This policy will sync the s3 secret in kube-system namespace across namespaces'
policies.clusterConfig.kyverno.io/subject: Secret
policies.clusterConfig.kyverno.io/title: Sync s3 Secrets
name: sync-s3-credentials
spec:
generateExistingOnPolicyUpdate: true
background: true
rules:
- generate:
apiVersion: v1
clone:
name: s3-credentials
namespace: kube-system
kind: Secret
name: s3-credentials
namespace: '{{`{{request.object.metadata.name}}`}}'
synchronize: true
match:
resources:
kinds:
- Namespace
names:
- "velero"
- "loki"
- "tempo"
name: sync-s3-secret
skipBackgroundRequests: true
validationFailureAction: audit
{{- end }}
# {{- if .Values.clusterConfig.kyverno.enabled }}
# apiVersion: kyverno.io/v1
# kind: ClusterPolicy
# metadata:
# annotations:
# policies.clusterConfig.kyverno.io/description: 'This policy will sync the s3 secret in kube-system namespace across namespaces'
# policies.clusterConfig.kyverno.io/subject: Secret
# policies.clusterConfig.kyverno.io/title: Sync s3 Secrets
# name: sync-s3-credentials
# spec:
# generateExistingOnPolicyUpdate: true
# background: true
# rules:
# - generate:
# apiVersion: v1
# clone:
# name: s3-credentials
# namespace: kube-system
# kind: Secret
# name: s3-credentials
# namespace: '{{`{{request.object.metadata.name}}`}}'
# synchronize: true
# match:
# resources:
# kinds:
# - Namespace
# names:
# - "velero"
# - "loki"
# - "tempo"
# name: sync-s3-secret
# skipBackgroundRequests: true
# validationFailureAction: audit
# {{- end }}