2revisionHistoryLimit: 10
4metricsBackends: ["prometheus"]
5auditMatchKindOnly: false
6constraintViolationsLimit: 20
10disableValidatingWebhook: false
11validatingWebhookName: gatekeeper-validating-webhook-configuration
12validatingWebhookTimeoutSeconds: 3
13validatingWebhookFailurePolicy: Ignore
14validatingWebhookAnnotations: {}
15validatingWebhookExemptNamespacesLabels: {}
16validatingWebhookObjectSelector: {}
17validatingWebhookMatchConditions: []
18validatingWebhookCheckIgnoreFailurePolicy: Fail
19validatingWebhookCustomRules: {}
20validatingWebhookSubResources: ["pods/ephemeralcontainers", "pods/exec", "pods/log", "pods/eviction", "pods/portforward", "pods/proxy", "pods/attach", "pods/binding", "pods/resize", "deployments/scale", "replicasets/scale", "statefulsets/scale", "replicationcontrollers/scale", "services/proxy", "nodes/proxy", "services/status"]
21validatingWebhookURL: null
22validatingWebhookScope: "*"
23enableDeleteOperations: false
24enableConnectOperations: false
25enableExternalData: true
26enableGeneratorResourceExpansion: true
27enableTLSHealthcheck: false
29mutatingWebhookName: gatekeeper-mutating-webhook-configuration
30mutatingWebhookFailurePolicy: Ignore
31mutatingWebhookReinvocationPolicy: Never
32mutatingWebhookAnnotations: {}
33mutatingWebhookExemptNamespacesLabels: {}
34mutatingWebhookObjectSelector: {}
35mutatingWebhookMatchConditions: []
36mutatingWebhookTimeoutSeconds: 1
37mutatingWebhookCustomRules: {}
38mutatingWebhookSubResources: ["pods/ephemeralcontainers", "pods/exec", "pods/log", "pods/eviction", "pods/portforward", "pods/proxy", "pods/attach", "pods/binding", "deployments/scale", "replicasets/scale", "statefulsets/scale", "replicationcontrollers/scale", "services/proxy", "nodes/proxy", "services/status"]
39mutatingWebhookURL: null
40mutatingWebhookScope: "*"
41mutationAnnotations: false
46admissionEventsInvolvedNamespace: false
47auditEventsInvolvedNamespace: false
49externaldataProviderResponseCacheTTL: 3m
50enableK8sNativeValidation: true
55 repository: cgr.dev/scratch-images/test-tmp/gatekeeper
56 crdRepository: openpolicyagent/gatekeeper-crds
57 release: 3.22.2-r1@sha256:96fa608047e90e14085aafcd032d1d2d4b5e3e7c9c5dc30094fae5c65d061e2e
58 pullPolicy: IfNotPresent
63 repository: cgr.dev/scratch-images/test-tmp/gatekeeper-crds
64 tag: 3.22.2-r1@sha256:2f84512bf8b9981fdf849c09914568f3390c3f4a0b22330e6a71184e2f116cc1
68 name: gatekeeper-update-namespace-label-post-upgrade
72 repository: cgr.dev/scratch-images/test-tmp/gatekeeper-crds
73 tag: 3.22.2-r1@sha256:2f84512bf8b9981fdf849c09914568f3390c3f4a0b22330e6a71184e2f116cc1
74 pullPolicy: IfNotPresent
77 podSecurity: ["pod-security.kubernetes.io/audit=restricted", "pod-security.kubernetes.io/audit-version=latest", "pod-security.kubernetes.io/warn=restricted", "pod-security.kubernetes.io/warn-version=latest", "pod-security.kubernetes.io/enforce=restricted", "pod-security.kubernetes.io/enforce-version=v1.24"]
82 nodeSelector: {kubernetes.io/os: linux}
85 allowPrivilegeEscalation: false
89 readOnlyRootFilesystem: true
96 name: gatekeeper-update-namespace-label
101 repository: cgr.dev/scratch-images/test-tmp/gatekeeper-crds
102 tag: 3.22.2-r1@sha256:2f84512bf8b9981fdf849c09914568f3390c3f4a0b22330e6a71184e2f116cc1
103 pullPolicy: IfNotPresent
106 podSecurity: ["pod-security.kubernetes.io/audit=restricted", "pod-security.kubernetes.io/audit-version=latest", "pod-security.kubernetes.io/warn=restricted", "pod-security.kubernetes.io/warn-version=latest", "pod-security.kubernetes.io/enforce=restricted", "pod-security.kubernetes.io/enforce-version=v1.24"]
108 priorityClassName: ""
112 repository: cgr.dev/scratch-images/test-tmp/curl
113 tag: 8.20.0-r1@sha256:6dcb2f5ba2b8b0adc49427cbd73ef1348995aaaa9be1a9b5f06e2043f23ab6a7
114 pullPolicy: IfNotPresent
119 priorityClassName: ""
122 nodeSelector: {kubernetes.io/os: linux}
124 allowPrivilegeEscalation: false
128 readOnlyRootFilesystem: true
133 deleteWebhookConfigurations:
135 name: gatekeeper-delete-webhook-configs
140 repository: cgr.dev/scratch-images/test-tmp/gatekeeper-crds
141 tag: 3.22.2-r1@sha256:2f84512bf8b9981fdf849c09914568f3390c3f4a0b22330e6a71184e2f116cc1
142 pullPolicy: IfNotPresent
144 priorityClassName: ""
147 nodeSelector: {kubernetes.io/os: linux}
150 allowPrivilegeEscalation: false
154 readOnlyRootFilesystem: true
159auditPodAnnotations: {}
163enableRuntimeDefaultSeccompProfile: true
166 name: gatekeeper-admin
167 automountServiceAccountToken: true
168 containerName: manager
170 exemptNamespacePrefixes: []
172 dnsPolicy: ClusterFirst
178 priorityClassName: system-cluster-critical
179 disableCertRotation: false
182 strategyType: RollingUpdate
183 strategyRollingUpdate: {}
187 preferredDuringSchedulingIgnoredDuringExecution:
191 - key: gatekeeper.sh/operation
195 topologyKey: kubernetes.io/hostname
197 topologySpreadConstraints: []
199 nodeSelector: {kubernetes.io/os: linux}
207 allowPrivilegeEscalation: false
211 readOnlyRootFilesystem: true
226 disableWebhookOperation: false
227 disableGenerateOperation: true
231 path: /tmp/violations/topics
234 path: /tmp/violations
240 image: cgr.dev/scratch-images/test-tmp/open-policy-agent-fake-reader:3.22.2-r1@sha256:6d0ca53fe022571e7bbc8450ac97ad3facc70e4c4f3e24afff84662c0b074ad3
241 imagePullPolicy: Always
243 allowPrivilegeEscalation: false
247 readOnlyRootFilesystem: true
254 - mountPath: /tmp/violations
257 name: gatekeeper-admin
258 automountServiceAccountToken: true
259 containerName: manager
261 dnsPolicy: ClusterFirst
266 priorityClassName: system-cluster-critical
267 disableCertRotation: false
271 nodeSelector: {kubernetes.io/os: linux}
279 allowPrivilegeEscalation: false
283 readOnlyRootFilesystem: true
291 writeToRAMDisk: false
293 disableGenerateOperation: false
294 disableAuditOperation: false
295 disableAuditSidecar: false
296 disableStatusOperation: false
300 nodeSelector: {kubernetes.io/os: linux}
303 allowPrivilegeEscalation: false
307 readOnlyRootFilesystem: true
315disabledBuiltins: ["{http.send}"]
319 name: gatekeeper-admin-upgrade-crds
322 priorityClassName: ""
325externalCertInjection:
327 secretName: gatekeeper-webhook-server-cert