Issues
- 12
policy for blocking ingress if user doesn't specify tls
#1193 opened by saiben10 - 12
policy for blocking externlaIps
#1192 opened by saiben10 - 2
[Feature] To add Karpenter Do Not Disrupt policy for Karpenter 1.x version
#1191 opened by jkannan-talend - 3
[Bug] Update CEL expression to support CAP_NET_RAW and NET_RAW drop capabilities
#1186 opened by epasham - 0
Publish policies as OCI Artifact
#1185 opened by devantler - 5
[Bug] Security Capabilites must omit the CAP prefix which is required by Kyverno policies
#1166 opened by StraysWonderland - 1
[Sample] Prevent `kubectl cp` command
#1169 opened by JimBugwadia - 9
- 1
Add Pod Anti-Affinity
#1171 opened by gssjl2008 - 2
[Bug]: Kyverno-policies helm chart has hardcoded Kubernetes version annotations
#1165 opened by sergey198828 - 1
[Sample] disallow-privilege-escalation: Simplify CEL expressions using optional
#1144 opened by epasham - 0
[Enhancement]: Update generateExistingOnPolicyUpdate (deprecated) with new format
#1162 opened by husnialhamdani - 2
Verify CycloneDX SBOM (Keyless)
#1132 opened by BBS-Testcenter - 8
[Question] How to match PATCH requests?
#1138 opened by Da-Juan - 1
- 3
- 6
[Enhancement] Update CEL policies to make use of optionals and variables to remove redundant expressions
#1058 opened by Chandan-DK - 0
disallow-selinux: simplify CEL expressions
#1098 opened by JimBugwadia - 6
restrict-seccomp: simplify CEL expressions
#1099 opened by JimBugwadia - 3
restrict-sysctls: simplify CEL expressions
#1100 opened by JimBugwadia - 4
disallow-host-namespaces: simplify CEL expressions
#1091 opened by JimBugwadia - 4
disallow-host-path: simplify CEL expressions
#1092 opened by JimBugwadia - 3
disallow-host-ports-range: simplify CEL expressions
#1094 opened by JimBugwadia - 2
disallow-capabilities: simplify CEL expressions
#1090 opened by JimBugwadia - 4
- 3
disallow-proc-mount: simplify CEL expressions
#1097 opened by JimBugwadia - 8
[Bug] Generating network policy for existing namespace fails. As well as data template synchronization.
#1123 opened by antonvigo - 0
Add Pod Disruption Budget
#1133 opened by abuechler - 4
- 4
Refresh Environment Variables in Pods
#1124 opened by Kamalesh-Seervi - 2
Custom message not working in podSecurity subrule policy
#1120 opened by F-Fx - 0
disallow-host-process: simplify CEL expressions
#1095 opened by JimBugwadia - 2
All tested images to be stored in Kyverno org
#1102 opened by chipzoller - 0
disallow-host-ports: simplify CEL expressions
#1093 opened by JimBugwadia - 1
[Sample] Mount volumes for ephemeral containers
#1088 opened by realshuting - 0
Block Large Images
#1083 opened by davvyin - 0
- 1
[Enhancement]: Replace enforce/audit (deprecated) with Enforce/Audit on sample policies
#1061 opened by mohamedawnallah - 1
[Enhancement]: Replace enforce/audit (deprecated) with Enforce/Audit on sample policies
#1060 opened by mohamedawnallah - 4
[Bug] Sync Secrets failing to keep secrets in sync
#1056 opened by eitah - 1
Extend chainsaw tests for additional container types
#1012 opened by JimBugwadia - 2
- 2
- 0
- 0
Question: exclusions to PodSecurity sub-rule
#1040 opened by sachintiptur - 1
[Bug] Generate rule on pod creation triggers twice
#1034 opened by marevers - 4
PolicyException for a pod with multiple violations
#1017 opened by erkerb4 - 1
[Chainsaw Tests] Test generated VAPs of pod security cel policies with Chainsaw
#1003 opened by Chandan-DK - 0
Block Stale Images
#986 opened by challakiran334 - 7