k8s: podsecuritypolicy via OPA
garethahealy opened this issue · 4 comments
garethahealy commented
Can we OPA'erize:
This would probably need to be tested on vanilla k8s or on OCP with SCCs least enforcing, just to stop them interfering - needs a quick check.
ckavili commented
(just came to like 'OPA'erize' 🙈)
garethahealy commented
@truncj ; hey, saw you mentioned you might pick this up on the CoP call agenda. Any progress / luck in getting time?
truncj commented
@garethahealy yup! took another look at it today and made some progress. I'll push up the changes and ask for some feedback tomorrow.
garethahealy commented
stale, didn't get any time/traction.