redhat-cop/rego-policies

k8s: podsecuritypolicy via OPA

garethahealy opened this issue · 4 comments

Can we OPA'erize:

This would probably need to be tested on vanilla k8s or on OCP with SCCs least enforcing, just to stop them interfering - needs a quick check.

(just came to like 'OPA'erize' 🙈)

@truncj ; hey, saw you mentioned you might pick this up on the CoP call agenda. Any progress / luck in getting time?

@garethahealy yup! took another look at it today and made some progress. I'll push up the changes and ask for some feedback tomorrow.

stale, didn't get any time/traction.