1# -- Policy kind (`ClusterPolicy`, `Policy`)
2# Set to `Policy` if you need namespaced policies and not cluster policies.
3# Only used when `policyType` is `ClusterPolicy` (the legacy kyverno.io types);
4# with the default `policyType: ValidatingPolicy` cluster-wide CEL policies are installed.
5policyKind: ClusterPolicy
7# -- Policy engine type (`ClusterPolicy`, `ValidatingPolicy`)
8# `ValidatingPolicy` installs CEL-based policies (policies.kyverno.io, requires Kyverno 1.17+).
9# Set to `ClusterPolicy` to keep installing the legacy kyverno.io policy types,
10# which are deprecated and will be removed in a future release
11# (see https://kyverno.io/docs/guides/migration-to-cel/).
12policyType: ValidatingPolicy
14# -- Pod Security Standard profile (`baseline`, `restricted`, `privileged`, `custom`).
15# For more info https://kyverno.io/policies/pod-security.
16podSecurityStandard: baseline
18# -- Pod Security Standard severity (`low`, `medium`, `high`).
19podSecuritySeverity: medium
21# -- Define podSecuritySeverity overrides for specific policies.
22# Override the global `podSecuritySeverity` with an individual severity for individual policies.
23# An empty string per-policy entry suppresses the annotation entirely.
24podSecuritySeverityByPolicy: {}
25# disallow-host-path: high
26# disallow-privileged-containers: high
28# -- Policies to include when `podSecurityStandard` is `custom`.
29podSecurityPolicies: []
31# -- Additional policies to include from `other`.
32includeOtherPolicies: []
33# - require-non-root-groups
35# -- Additional policies to include from `restricted`.
36includeRestrictedPolicies: []
37# - require-run-as-non-root-user
39# -- Additional custom policies to include.
41# - apiVersion: kyverno.io/v1
46# -- API server behavior if the webhook fails to respond ('Ignore', 'Fail')
47# For more info: https://kyverno.io/docs/policy-types/cluster-policy/policy-settings/
50# -- Validation failure action (`Audit`, `Enforce`).
51# For more info https://kyverno.io/docs/policy-types/cluster-policy/validate.
52validationFailureAction: Audit
54# -- Define validationFailureActionByPolicy for specific policies.
55# Override the defined `validationFailureAction` with a individual validationFailureAction for individual Policies.
56validationFailureActionByPolicy: {}
57# disallow-capabilities-strict: Enforce
58# disallow-host-path: Enforce
59# disallow-host-ports: Enforce
61# -- Define validationFailureActionOverrides for specific policies.
62# The overrides for `all` will apply to all policies.
63validationFailureActionOverrides:
74# -- Default audit annotations applied to all ValidatingPolicy policies (policyType: ValidatingPolicy only).
75# Map of annotation key to CEL valueExpression. Audit annotations are recorded in the API server audit log.
76# For more info https://kyverno.io/docs/policy-types/validating-policy/#using-auditannotations-to-add-custom-data
78 # policy-evaluated-by: "'kyverno-policies-helm'"
80# -- Define audit annotations for specific ValidatingPolicy policies (policyType: ValidatingPolicy only).
81# Per-policy entries override defaults when they share the same key.
82auditAnnotationsByPolicy: {}
84 # violation-details: >-
85 # has(object.spec.volumes) ? 'hostPath volumes found: ' + object.spec.volumes.filter(v, has(v.hostPath)).map(v, v.name).join(', ') : 'no volumes'
87# -- Validate already existing resources.
88# For more info https://kyverno.io/docs/policy-types/.
89validationAllowExistingViolations: true
91# -- Exclude resources from individual policies (policyType: ClusterPolicy only).
92# Policies with multiple rules can have individual rules excluded by using the name of the rule as the key in the `policyExclude` map.
93# NOTE: This setting only applies when policyType is set to ClusterPolicy. For ValidatingPolicy, use vpolExclude/vpolExcludeByPolicy instead.
95 # # Exclude resources from individual policies
103 # # Policies with multiple rules can have individual rules excluded
104 # adding-capabilities-strict:
112# -- Default excludes applied to ALL ValidatingPolicy policies (policyType: ValidatingPolicy only).
113# NOTE: This setting only applies when policyType is set to ValidatingPolicy. For ClusterPolicy, use policyExclude instead.
114# Supports the following optional keys:
115# excludeResourceRules: list of Kubernetes NamedRuleWithOperations (native VAP excludes)
116# excludeNamespaces: list of namespace names to exclude (generates CEL matchCondition)
117# excludeSubjects: list of subjects to exclude (generates CEL matchCondition)
118# matchConditions: list of CEL matchConditions for advanced filtering (passthrough of custom condition)
119# Per-policy overrides via vpolExcludeByPolicy replace these defaults entirely for that policy.
125 # name: system:masters
127# -- Per-policy excludes for individual ValidatingPolicy policies (policyType: ValidatingPolicy only).
128# When set for a policy, it completely replaces the global vpolExclude defaults for that policy.
129# NOTE: This setting only applies when policyType is set to ValidatingPolicy. For ClusterPolicy, use policyExclude instead.
130# Each policy name maps to an object with the same keys as vpolExclude.
131vpolExcludeByPolicy: {}
132 # disallow-host-path:
133 # excludeResourceRules:
143 # # optional - exact resource names to exclude
145 # - specific-pod-name
151 # name: system:masters
153 # name: admin@example.com
154 # - kind: ServiceAccount
155 # namespace: kube-system
158 # - name: exclude-custom
159 # expression: "!object.metadata.name.startsWith('temp-')"
161# -- Add preconditions to individual policies.
162# Policies with multiple rules can have individual rules excluded by using the name of the rule as the key in the `policyPreconditions` map.
163policyPreconditions: {}
164 # # Exclude resources from individual policies
165 # require-run-as-non-root-user:
167 # - key: "{{ request.object.metadata.name }}"
168 # operator: NotEquals
169 # value: "dcgm-exporter*"
170 # # Policies with multiple rules can have individual rules excluded
173 # - key: "{{ request.object.metadata.name }}"
174 # operator: NotEquals
175 # value: "dcgm-exporter*"
176 # adding-capabilities-strict:
178 # - key: "{{ request.object.metadata.name }}"
179 # operator: NotEquals
180 # value: "dcgm-exporter*"
182# -- Customize the target Pod controllers for the auto-generated rules. (Eg. `none`, `Deployment`, `DaemonSet,Deployment,StatefulSet`)
183# For more info https://kyverno.io/docs/policy-types/cluster-policy/autogen/.
184autogenControllers: ""
189# -- Additional Annotations.
192# -- Define custom annotations for specific policies.
193# Per-policy entries override defaults when they share the same key.
194customAnnotationsByPolicy: {}
196# my-custom-annotation: "some-value"
198# -- Additional labels.
201# -- Policies background mode
204# -- (bool) SkipBackgroundRequests bypasses admission requests that are sent by the background controller
205skipBackgroundRequests: ~
208# The default of "autodetect" will try to determine the currently installed version from the deployment
209kyvernoVersion: autodetect
211# -- Kubernetes version override
212# Override default value of kubeVersion set by release team taken from Chart.yaml with custom value. Ideally range of versions no more than two prior (ex., 1.28-1.31), must be enclosed in quotes.