2revisionHistoryLimit: 10
4metricsBackends: ["prometheus"]
5auditMatchKindOnly: false
6constraintViolationsLimit: 20
10disableValidatingWebhook: false
11validatingWebhookName: gatekeeper-validating-webhook-configuration
12validatingWebhookTimeoutSeconds: 3
13validatingWebhookFailurePolicy: Ignore
14validatingWebhookAnnotations: {}
15validatingWebhookExemptNamespacesLabels: {}
16validatingWebhookObjectSelector: {}
17validatingWebhookMatchConditions: []
18validatingWebhookCheckIgnoreFailurePolicy: Fail
19validatingWebhookCustomRules: {}
20validatingWebhookSubResources: ["pods/ephemeralcontainers", "pods/exec", "pods/log", "pods/eviction", "pods/portforward", "pods/proxy", "pods/attach", "pods/binding", "pods/resize", "deployments/scale", "replicasets/scale", "statefulsets/scale", "replicationcontrollers/scale", "services/proxy", "nodes/proxy", "services/status"]
21validatingWebhookURL: null
22validatingWebhookScope: "*"
23enableDeleteOperations: false
24enableConnectOperations: false
25enableExternalData: true
26enableGeneratorResourceExpansion: true
27enableTLSHealthcheck: false
29mutatingWebhookName: gatekeeper-mutating-webhook-configuration
30mutatingWebhookFailurePolicy: Ignore
31mutatingWebhookReinvocationPolicy: Never
32mutatingWebhookAnnotations: {}
33mutatingWebhookExemptNamespacesLabels: {}
34mutatingWebhookObjectSelector: {}
35mutatingWebhookMatchConditions: []
36mutatingWebhookTimeoutSeconds: 1
37mutatingWebhookCustomRules: {}
38mutatingWebhookSubResources: ["pods/ephemeralcontainers", "pods/exec", "pods/log", "pods/eviction", "pods/portforward", "pods/proxy", "pods/attach", "pods/binding", "deployments/scale", "replicasets/scale", "statefulsets/scale", "replicationcontrollers/scale", "services/proxy", "nodes/proxy", "services/status"]
39mutatingWebhookURL: null
40mutatingWebhookScope: "*"
41mutationAnnotations: false
46admissionEventsInvolvedNamespace: false
47auditEventsInvolvedNamespace: false
49externaldataProviderResponseCacheTTL: 3m
50enableK8sNativeValidation: true
55 repository: chainreg.biz/scratch-images/test-tmp/gatekeeper
56 crdRepository: openpolicyagent/gatekeeper-crds
57 release: 3.22.2-r0@sha256:161b0d9aac1dd472cfd5421a600fb691aa2d4d0cfde8c6285c9c0367611327cd
58 pullPolicy: IfNotPresent
63 repository: chainreg.biz/scratch-images/test-tmp/gatekeeper-crds
64 tag: 3.22.2-r0@sha256:342d71b7f1546a6707a4601133e1462b74beb07ca0f63fd0bd8e5029e6ffabdb
68 name: gatekeeper-update-namespace-label-post-upgrade
72 repository: chainreg.biz/scratch-images/test-tmp/gatekeeper-crds
73 tag: 3.22.2-r0@sha256:342d71b7f1546a6707a4601133e1462b74beb07ca0f63fd0bd8e5029e6ffabdb
74 pullPolicy: IfNotPresent
77 podSecurity: ["pod-security.kubernetes.io/audit=restricted", "pod-security.kubernetes.io/audit-version=latest", "pod-security.kubernetes.io/warn=restricted", "pod-security.kubernetes.io/warn-version=latest", "pod-security.kubernetes.io/enforce=restricted", "pod-security.kubernetes.io/enforce-version=v1.24"]
82 nodeSelector: {kubernetes.io/os: linux}
85 allowPrivilegeEscalation: false
89 readOnlyRootFilesystem: true
96 name: gatekeeper-update-namespace-label
101 repository: chainreg.biz/scratch-images/test-tmp/gatekeeper-crds
102 tag: 3.22.2-r0@sha256:342d71b7f1546a6707a4601133e1462b74beb07ca0f63fd0bd8e5029e6ffabdb
103 pullPolicy: IfNotPresent
106 podSecurity: ["pod-security.kubernetes.io/audit=restricted", "pod-security.kubernetes.io/audit-version=latest", "pod-security.kubernetes.io/warn=restricted", "pod-security.kubernetes.io/warn-version=latest", "pod-security.kubernetes.io/enforce=restricted", "pod-security.kubernetes.io/enforce-version=v1.24"]
108 priorityClassName: ""
112 repository: chainreg.biz/scratch-images/test-tmp/curl
113 tag: 8.20.0-r0@sha256:9bc8ec03edb695cd3206a41c4402adc1518c12c6999594cfe8f2ff175dbc826b
114 pullPolicy: IfNotPresent
119 priorityClassName: ""
122 nodeSelector: {kubernetes.io/os: linux}
124 allowPrivilegeEscalation: false
128 readOnlyRootFilesystem: true
133 deleteWebhookConfigurations:
135 name: gatekeeper-delete-webhook-configs
140 repository: chainreg.biz/scratch-images/test-tmp/gatekeeper-crds
141 tag: 3.22.2-r0@sha256:342d71b7f1546a6707a4601133e1462b74beb07ca0f63fd0bd8e5029e6ffabdb
142 pullPolicy: IfNotPresent
144 priorityClassName: ""
147 nodeSelector: {kubernetes.io/os: linux}
150 allowPrivilegeEscalation: false
154 readOnlyRootFilesystem: true
159auditPodAnnotations: {}
163enableRuntimeDefaultSeccompProfile: true
166 name: gatekeeper-admin
167 automountServiceAccountToken: true
168 containerName: manager
170 exemptNamespacePrefixes: []
172 dnsPolicy: ClusterFirst
178 priorityClassName: system-cluster-critical
179 disableCertRotation: false
182 strategyType: RollingUpdate
183 strategyRollingUpdate: {}
187 preferredDuringSchedulingIgnoredDuringExecution:
191 - key: gatekeeper.sh/operation
195 topologyKey: kubernetes.io/hostname
197 topologySpreadConstraints: []
199 nodeSelector: {kubernetes.io/os: linux}
207 allowPrivilegeEscalation: false
211 readOnlyRootFilesystem: true
226 disableWebhookOperation: false
227 disableGenerateOperation: true
231 path: /tmp/violations/topics
234 path: /tmp/violations
240 image: chainreg.biz/scratch-images/test-tmp/open-policy-agent-fake-reader:3.22.2-r0@sha256:c307facac401d3ee82b542cea0eea3528ae322fa273dc9f63706419c0242d04b
241 imagePullPolicy: Always
243 allowPrivilegeEscalation: false
247 readOnlyRootFilesystem: true
254 - mountPath: /tmp/violations
257 name: gatekeeper-admin
258 automountServiceAccountToken: true
259 containerName: manager
261 dnsPolicy: ClusterFirst
266 priorityClassName: system-cluster-critical
267 disableCertRotation: false
271 nodeSelector: {kubernetes.io/os: linux}
279 allowPrivilegeEscalation: false
283 readOnlyRootFilesystem: true
291 writeToRAMDisk: false
293 disableGenerateOperation: false
294 disableAuditOperation: false
295 disableAuditSidecar: false
296 disableStatusOperation: false
300 nodeSelector: {kubernetes.io/os: linux}
303 allowPrivilegeEscalation: false
307 readOnlyRootFilesystem: true
315disabledBuiltins: ["{http.send}"]
319 name: gatekeeper-admin-upgrade-crds
322 priorityClassName: ""
325externalCertInjection:
327 secretName: gatekeeper-webhook-server-cert