2revisionHistoryLimit: 10
4metricsBackends: ["prometheus"]
5auditMatchKindOnly: false
6constraintViolationsLimit: 20
10disableValidatingWebhook: false
11validatingWebhookName: gatekeeper-validating-webhook-configuration
12validatingWebhookTimeoutSeconds: 3
13validatingWebhookFailurePolicy: Ignore
14validatingWebhookAnnotations: {}
15validatingWebhookExemptNamespacesLabels: {}
16validatingWebhookObjectSelector: {}
17validatingWebhookMatchConditions: []
18validatingWebhookCheckIgnoreFailurePolicy: Fail
19validatingWebhookCustomRules: {}
20validatingWebhookSubResources: ['pods/ephemeralcontainers', 'pods/exec', 'pods/log', 'pods/eviction', 'pods/portforward', 'pods/proxy', 'pods/attach', 'pods/binding', 'pods/resize', 'deployments/scale', 'replicasets/scale', 'statefulsets/scale', 'replicationcontrollers/scale', 'services/proxy', 'nodes/proxy', 'services/status']
21validatingWebhookURL: null
22validatingWebhookScope: '*'
23enableDeleteOperations: false
24enableConnectOperations: false
25enableExternalData: true
26enableGeneratorResourceExpansion: true
27enableTLSHealthcheck: false
29mutatingWebhookName: gatekeeper-mutating-webhook-configuration
30mutatingWebhookFailurePolicy: Ignore
31mutatingWebhookReinvocationPolicy: Never
32mutatingWebhookAnnotations: {}
33mutatingWebhookExemptNamespacesLabels: {}
34mutatingWebhookObjectSelector: {}
35mutatingWebhookMatchConditions: []
36mutatingWebhookTimeoutSeconds: 1
37mutatingWebhookCustomRules: {}
38mutatingWebhookSubResources: ['pods/ephemeralcontainers', 'pods/exec', 'pods/log', 'pods/eviction', 'pods/portforward', 'pods/proxy', 'pods/attach', 'pods/binding', 'deployments/scale', 'replicasets/scale', 'statefulsets/scale', 'replicationcontrollers/scale', 'services/proxy', 'nodes/proxy', 'services/status']
39mutatingWebhookURL: null
40mutatingWebhookScope: '*'
41mutationAnnotations: false
46admissionEventsInvolvedNamespace: false
47auditEventsInvolvedNamespace: false
49externaldataProviderResponseCacheTTL: 3m
50enableK8sNativeValidation: true
55 repository: chainreg.biz/chainguard-private/gatekeeper
56 crdRepository: chainreg.biz/chainguard-private/gatekeeper-crds
57 release: latest@sha256:2c46d34eb60c04b64994eeb2cc187a4ae5d4882ed2e44972327eb5f24336f684
58 pullPolicy: IfNotPresent
63 repository: chainreg.biz/chainguard-private/gatekeeper-crds
64 tag: latest@sha256:b29180c2350d08d33674d1d0385e8455c9420308742f8d05f6623e1b5c0e9449
68 name: gatekeeper-update-namespace-label-post-upgrade
72 repository: chainreg.biz/chainguard-private/gatekeeper-crds
73 tag: latest@sha256:b29180c2350d08d33674d1d0385e8455c9420308742f8d05f6623e1b5c0e9449
74 pullPolicy: IfNotPresent
77 podSecurity: ["pod-security.kubernetes.io/audit=restricted", "pod-security.kubernetes.io/audit-version=latest", "pod-security.kubernetes.io/warn=restricted", "pod-security.kubernetes.io/warn-version=latest", "pod-security.kubernetes.io/enforce=restricted", "pod-security.kubernetes.io/enforce-version=v1.24"]
82 nodeSelector: {kubernetes.io/os: linux}
85 allowPrivilegeEscalation: false
89 readOnlyRootFilesystem: true
96 name: gatekeeper-update-namespace-label
101 repository: chainreg.biz/chainguard-private/gatekeeper-crds
102 tag: latest@sha256:b29180c2350d08d33674d1d0385e8455c9420308742f8d05f6623e1b5c0e9449
103 pullPolicy: IfNotPresent
106 podSecurity: ["pod-security.kubernetes.io/audit=restricted", "pod-security.kubernetes.io/audit-version=latest", "pod-security.kubernetes.io/warn=restricted", "pod-security.kubernetes.io/warn-version=latest", "pod-security.kubernetes.io/enforce=restricted", "pod-security.kubernetes.io/enforce-version=v1.24"]
108 priorityClassName: ""
112 repository: chainreg.biz/chainguard-private/curl
113 tag: latest@sha256:1e6c47ebb394b4ef0b21044516909679aabfe03b80c1164b19835e177b20f474
114 pullPolicy: IfNotPresent
119 priorityClassName: ""
122 nodeSelector: {kubernetes.io/os: linux}
124 allowPrivilegeEscalation: false
128 readOnlyRootFilesystem: true
133 deleteWebhookConfigurations:
135 name: gatekeeper-delete-webhook-configs
140 repository: chainreg.biz/chainguard-private/gatekeeper-crds
141 tag: latest@sha256:b29180c2350d08d33674d1d0385e8455c9420308742f8d05f6623e1b5c0e9449
142 pullPolicy: IfNotPresent
144 priorityClassName: ""
147 nodeSelector: {kubernetes.io/os: linux}
150 allowPrivilegeEscalation: false
154 readOnlyRootFilesystem: true
159auditPodAnnotations: {}
163enableRuntimeDefaultSeccompProfile: true
166 name: gatekeeper-admin
167 automountServiceAccountToken: true
168 containerName: manager
170 exemptNamespacePrefixes: []
172 dnsPolicy: ClusterFirst
178 priorityClassName: system-cluster-critical
179 disableCertRotation: false
182 strategyType: RollingUpdate
183 strategyRollingUpdate: {}
187 preferredDuringSchedulingIgnoredDuringExecution:
191 - key: gatekeeper.sh/operation
195 topologyKey: kubernetes.io/hostname
197 topologySpreadConstraints: []
199 nodeSelector: {kubernetes.io/os: linux}
207 allowPrivilegeEscalation: false
211 readOnlyRootFilesystem: true
226 disableWebhookOperation: false
227 disableGenerateOperation: true
231 path: /tmp/violations/topics
234 path: /tmp/violations
240 image: chainreg.biz/chainguard-private/gatekeeper:latest@sha256:2c46d34eb60c04b64994eeb2cc187a4ae5d4882ed2e44972327eb5f24336f684
241 imagePullPolicy: Always
243 allowPrivilegeEscalation: false
247 readOnlyRootFilesystem: true
254 - mountPath: /tmp/violations
257 name: gatekeeper-admin
258 automountServiceAccountToken: true
259 containerName: manager
261 dnsPolicy: ClusterFirst
266 priorityClassName: system-cluster-critical
267 disableCertRotation: false
271 nodeSelector: {kubernetes.io/os: linux}
279 allowPrivilegeEscalation: false
283 readOnlyRootFilesystem: true
291 writeToRAMDisk: false
293 disableGenerateOperation: false
294 disableAuditOperation: false
295 disableStatusOperation: false
299 nodeSelector: {kubernetes.io/os: linux}
302 allowPrivilegeEscalation: false
306 readOnlyRootFilesystem: true
314disabledBuiltins: ["{http.send}"]
318 name: gatekeeper-admin-upgrade-crds
321 priorityClassName: ""
324externalCertInjection:
326 secretName: gatekeeper-webhook-server-cert