Skip to main content

Updates the cluster policy

Updates the cluster policy

Path Parameters
    workspace stringrequired

    Workspace to use

    name stringrequired

    The name of the cluster policy you wish or update

Query Parameters
    dryRun string

    Set to 'All' to perform a server-side dry run of updating this resource

    force string

    Set to 'true' to override read-only (has no effect unless used by Wayfinder admin)

    owner string

    Use an explicit owner for this resource - this must match the owner used on create, if set

    apply string

    Use server-side apply for this update instead of overwriting the whole object

Request Body required

The specification for the cluster policy you are updating

    apiVersion string
    kind string
    metadata

    ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.

    annotations object

    Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects. More info: http://kubernetes.io/docs/user-guide/annotations

  • property name* string
  • clusterName string
    creationTimestamp string
    deletionGracePeriodSeconds int64
    deletionTimestamp string
    finalizers string[]
    generateName string
    generation int64
    labels object

    Map of string keys and values that can be used to organize and categorize (scope and select) objects. May match selectors of replication controllers and services. More info: http://kubernetes.io/docs/user-guide/labels

  • property name* string
  • managedFields undefined[]

    ManagedFields maps workflow-id and version to the set of fields that are managed by that workflow. This is mostly for internal housekeeping, and users typically shouldn't need to set or understand this field. A workflow can be the user's name, a controller's name, or the name of a specific apply path like "ci-cd". The set of fields is always in the version that the workflow used when modifying the object.

    apiVersion string
    fieldsType string
    fieldsV1 string
    manager string
    operation string
    subresource string
    time string
    name string
    namespace string
    ownerReferences undefined[]

    List of objects depended by this object. If ALL objects in the list have been deleted, this object will be garbage collected. If this object is managed by a controller, then an entry in this list will point to this controller, with the controller field set to true. There cannot be more than one managing controller.

    apiVersion stringrequired
    blockOwnerDeletion boolean
    controller boolean
    kind stringrequired
    name stringrequired
    uid stringrequired
    resourceVersion string
    selfLink string
    uid string
    spec

    ClusterPolicySpec defines the specification of a policy in a cluster or namespace

    policy

    Policy details

    kuberbac

    KubeRBAC holds the kubernetes rbac details

    clusterScoped boolean
    clusterScopedRoleOverride boolean
    roleBindingNameOverride string
    roleNameOverride string
    roleRef

    RoleRef is a reference to the Role or ClusterRole within the target cluster - must exist if no rules are specified

    apiGroup stringrequired
    kind stringrequired
    name stringrequired
    rules undefined[]

    Rules is rules Leave blank to specify only a binding is to be created

    apiGroups string[]
    nonResourceURLs string[]
    resourceNames string[]
    resources string[]
    verbs string[]required
    subjects undefined[]

    Subjects / principles who the rules apply to - user - group - serviceaccount Note only a service account can specify the namespace

    apiGroup string
    kind stringrequired
    name stringrequired
    namespace string
    kyverno

    Kyverno holds the spec for a kyverno policy

    applyRules string
    background boolean
    failurePolicy string
    generateExistingOnPolicyUpdate boolean
    mutateExistingOnPolicyUpdate boolean
    rules undefined[]
    context undefined[]
    apiCall
    jmesPath string
    service
    caBundle stringrequired
    data undefined[] required
    key stringrequired
    value stringrequired
    requestType stringrequired
    urlPath stringrequired
    urlPath stringrequired
    configMap
    name stringrequired
    namespace string
    imageRegistry
    jmesPath string
    reference stringrequired
    name string
    variable
    default string
    jmesPath string
    value string
    exclude
    all undefined[]
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind stringrequired
    name stringrequired
    namespace string
    any undefined[]
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind stringrequired
    name stringrequired
    namespace string
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind stringrequired
    name stringrequired
    namespace string
    generate
    apiVersion string
    clone
    name string
    namespace string
    cloneList
    kinds string[]
    namespace string
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • data string
    kind string
    name string
    namespace string
    synchronize boolean
    imageExtractors object
    type
    items
    key string
    name string
    path stringrequired
    value string
    match
    all undefined[]
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind stringrequired
    name stringrequired
    namespace string
    any undefined[]
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind stringrequired
    name stringrequired
    namespace string
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind stringrequired
    name stringrequired
    namespace string
    mutate
    foreach undefined[]
    context undefined[]
    apiCall
    jmesPath string
    service
    caBundle stringrequired
    data undefined[] required
    key stringrequired
    value stringrequired
    requestType stringrequired
    urlPath stringrequired
    urlPath stringrequired
    configMap
    name stringrequired
    namespace string
    imageRegistry
    jmesPath string
    reference stringrequired
    name string
    variable
    default string
    jmesPath string
    value string
    foreach string
    list string
    patchStrategicMerge string
    patchesJson6902 string
    preconditions
    all undefined[]
    key string
    operator string
    value string
    any undefined[]
    key string
    operator string
    value string
    patchStrategicMerge string
    patchesJson6902 string
    targets undefined[]
    apiVersion string
    kind string
    name string
    namespace string
    name string
    preconditions string
    validate
    anyPattern string
    deny
    conditions string
    foreach undefined[]
    anyPattern string
    context undefined[]
    apiCall
    jmesPath string
    service
    caBundle stringrequired
    data undefined[] required
    key stringrequired
    value stringrequired
    requestType stringrequired
    urlPath stringrequired
    urlPath stringrequired
    configMap
    name stringrequired
    namespace string
    imageRegistry
    jmesPath string
    reference stringrequired
    name string
    variable
    default string
    jmesPath string
    value string
    deny
    conditions string
    elementScope boolean
    foreach string
    list string
    pattern string
    preconditions
    all undefined[]
    key string
    operator string
    value string
    any undefined[]
    key string
    operator string
    value string
    manifests
    annotationDomain string
    attestors undefined[]
    count int32
    entries undefined[]
    annotations object
  • property name* string
  • attestor string
    certificates
    cert string
    certChain string
    rekor
    url stringrequired
    keyless
    additionalExtensions object
  • property name* string
  • issuer string
    rekor
    url stringrequired
    roots string
    subject string
    keys
    kms string
    publicKeys string
    rekor
    url stringrequired
    secret
    name stringrequired
    namespace stringrequired
    signatureAlgorithm string
    repository string
    dryRun
    enable boolean
    namespace string
    ignoreFields undefined[]
    fields string[]
    objects undefined[]
    group string
    kind string
    name string
    namespace string
    version string
    repository string
    message string
    pattern string
    podSecurity
    exclude undefined[]
    controlName stringrequired
    images string[]
    level string
    version string
    verifyImages undefined[]
    additionalExtensions object
  • property name* string
  • annotations object
  • property name* string
  • attestations undefined[]
    attestors undefined[] required
    count int32
    entries undefined[]
    annotations object
  • property name* string
  • attestor string
    certificates
    cert string
    certChain string
    rekor
    url stringrequired
    keyless
    additionalExtensions object
  • property name* string
  • issuer string
    rekor
    url stringrequired
    roots string
    subject string
    keys
    kms string
    publicKeys string
    rekor
    url stringrequired
    secret
    name stringrequired
    namespace stringrequired
    signatureAlgorithm string
    repository string
    conditions undefined[]
    all undefined[]
    key string
    operator string
    value string
    any undefined[]
    key string
    operator string
    value string
    predicateType stringrequired
    attestors undefined[]
    count int32
    entries undefined[]
    annotations object
  • property name* string
  • attestor string
    certificates
    cert string
    certChain string
    rekor
    url stringrequired
    keyless
    additionalExtensions object
  • property name* string
  • issuer string
    rekor
    url stringrequired
    roots string
    subject string
    keys
    kms string
    publicKeys string
    rekor
    url stringrequired
    secret
    name stringrequired
    namespace stringrequired
    signatureAlgorithm string
    repository string
    image string
    imageReferences string[]
    issuer string
    key string
    mutateDigest booleanrequired
    repository string
    required booleanrequired
    roots string
    subject string
    verifyDigest booleanrequired
    schemaValidation boolean
    validationFailureAction string
    validationFailureActionOverrides undefined[]
    action string
    namespaces string[]
    webhookTimeoutSeconds int32
    type stringrequired
    target required

    Target contains targeting information for this cluster policy

    cluster

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespace

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key stringrequired
    operator stringrequired
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • status

    ClusterPolicyStatus defines the status of a cluster policy

    cloudResourcesCreated boolean
    conditions undefined[]
    detail string
    lastTransitionTime stringrequired
    message string
    name stringrequired
    negativePolarity boolean
    observedGeneration int64
    reason stringrequired
    status stringrequired
    type stringrequired
    detail string
    lastReconcile
    generation int64required
    time stringrequired
    lastSuccess
    generation int64required
    time stringrequired
    message string
    obsoleteResources undefined[]
    kind stringrequired
    name stringrequired
    routing undefined[]
    error string
    lastReconcile
    generation int64required
    time stringrequired
    status stringrequired
    target required
    group stringrequired
    kind stringrequired
    name stringrequired
    namespace stringrequired
    version stringrequired
    status stringrequired
    wayfinderVersion string

Responses

Contains the cluster policy definition

Schema
    apiVersion string
    kind string
    metadata

    ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.

    annotations object

    Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects. More info: http://kubernetes.io/docs/user-guide/annotations

  • property name* string
  • clusterName string
    creationTimestamp string
    deletionGracePeriodSeconds int64
    deletionTimestamp string
    finalizers string[]
    generateName string
    generation int64
    labels object

    Map of string keys and values that can be used to organize and categorize (scope and select) objects. May match selectors of replication controllers and services. More info: http://kubernetes.io/docs/user-guide/labels

  • property name* string
  • managedFields undefined[]

    ManagedFields maps workflow-id and version to the set of fields that are managed by that workflow. This is mostly for internal housekeeping, and users typically shouldn't need to set or understand this field. A workflow can be the user's name, a controller's name, or the name of a specific apply path like "ci-cd". The set of fields is always in the version that the workflow used when modifying the object.

    apiVersion string
    fieldsType string
    fieldsV1 string
    manager string
    operation string
    subresource string
    time string
    name string
    namespace string
    ownerReferences undefined[]

    List of objects depended by this object. If ALL objects in the list have been deleted, this object will be garbage collected. If this object is managed by a controller, then an entry in this list will point to this controller, with the controller field set to true. There cannot be more than one managing controller.

    apiVersion string
    blockOwnerDeletion boolean
    controller boolean
    kind string
    name string
    uid string
    resourceVersion string
    selfLink string
    uid string
    spec

    ClusterPolicySpec defines the specification of a policy in a cluster or namespace

    policy

    Policy details

    kuberbac

    KubeRBAC holds the kubernetes rbac details

    clusterScoped boolean
    clusterScopedRoleOverride boolean
    roleBindingNameOverride string
    roleNameOverride string
    roleRef

    RoleRef is a reference to the Role or ClusterRole within the target cluster - must exist if no rules are specified

    apiGroup string
    kind string
    name string
    rules undefined[]

    Rules is rules Leave blank to specify only a binding is to be created

    apiGroups string[]
    nonResourceURLs string[]
    resourceNames string[]
    resources string[]
    verbs string[]
    subjects undefined[]

    Subjects / principles who the rules apply to - user - group - serviceaccount Note only a service account can specify the namespace

    apiGroup string
    kind string
    name string
    namespace string
    kyverno

    Kyverno holds the spec for a kyverno policy

    applyRules string
    background boolean
    failurePolicy string
    generateExistingOnPolicyUpdate boolean
    mutateExistingOnPolicyUpdate boolean
    rules undefined[]
    context undefined[]
    apiCall
    jmesPath string
    service
    caBundle string
    data undefined[]
    key string
    value string
    requestType string
    urlPath string
    urlPath string
    configMap
    name string
    namespace string
    imageRegistry
    jmesPath string
    reference string
    name string
    variable
    default string
    jmesPath string
    value string
    exclude
    all undefined[]
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind string
    name string
    namespace string
    any undefined[]
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind string
    name string
    namespace string
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind string
    name string
    namespace string
    generate
    apiVersion string
    clone
    name string
    namespace string
    cloneList
    kinds string[]
    namespace string
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • data string
    kind string
    name string
    namespace string
    synchronize boolean
    imageExtractors object
    type
    items
    key string
    name string
    path string
    value string
    match
    all undefined[]
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind string
    name string
    namespace string
    any undefined[]
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind string
    name string
    namespace string
    clusterRoles string[]
    resources
    annotations object
  • property name* string
  • kinds string[]
    name string
    names string[]
    namespaceSelector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespaces string[]
    selector

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • roles string[]
    subjects undefined[]
    apiGroup string
    kind string
    name string
    namespace string
    mutate
    foreach undefined[]
    context undefined[]
    apiCall
    jmesPath string
    service
    caBundle string
    data undefined[]
    key string
    value string
    requestType string
    urlPath string
    urlPath string
    configMap
    name string
    namespace string
    imageRegistry
    jmesPath string
    reference string
    name string
    variable
    default string
    jmesPath string
    value string
    foreach string
    list string
    patchStrategicMerge string
    patchesJson6902 string
    preconditions
    all undefined[]
    key string
    operator string
    value string
    any undefined[]
    key string
    operator string
    value string
    patchStrategicMerge string
    patchesJson6902 string
    targets undefined[]
    apiVersion string
    kind string
    name string
    namespace string
    name string
    preconditions string
    validate
    anyPattern string
    deny
    conditions string
    foreach undefined[]
    anyPattern string
    context undefined[]
    apiCall
    jmesPath string
    service
    caBundle string
    data undefined[]
    key string
    value string
    requestType string
    urlPath string
    urlPath string
    configMap
    name string
    namespace string
    imageRegistry
    jmesPath string
    reference string
    name string
    variable
    default string
    jmesPath string
    value string
    deny
    conditions string
    elementScope boolean
    foreach string
    list string
    pattern string
    preconditions
    all undefined[]
    key string
    operator string
    value string
    any undefined[]
    key string
    operator string
    value string
    manifests
    annotationDomain string
    attestors undefined[]
    count int32
    entries undefined[]
    annotations object
  • property name* string
  • attestor string
    certificates
    cert string
    certChain string
    rekor
    url string
    keyless
    additionalExtensions object
  • property name* string
  • issuer string
    rekor
    url string
    roots string
    subject string
    keys
    kms string
    publicKeys string
    rekor
    url string
    secret
    name string
    namespace string
    signatureAlgorithm string
    repository string
    dryRun
    enable boolean
    namespace string
    ignoreFields undefined[]
    fields string[]
    objects undefined[]
    group string
    kind string
    name string
    namespace string
    version string
    repository string
    message string
    pattern string
    podSecurity
    exclude undefined[]
    controlName string
    images string[]
    level string
    version string
    verifyImages undefined[]
    additionalExtensions object
  • property name* string
  • annotations object
  • property name* string
  • attestations undefined[]
    attestors undefined[]
    count int32
    entries undefined[]
    annotations object
  • property name* string
  • attestor string
    certificates
    cert string
    certChain string
    rekor
    url string
    keyless
    additionalExtensions object
  • property name* string
  • issuer string
    rekor
    url string
    roots string
    subject string
    keys
    kms string
    publicKeys string
    rekor
    url string
    secret
    name string
    namespace string
    signatureAlgorithm string
    repository string
    conditions undefined[]
    all undefined[]
    key string
    operator string
    value string
    any undefined[]
    key string
    operator string
    value string
    predicateType string
    attestors undefined[]
    count int32
    entries undefined[]
    annotations object
  • property name* string
  • attestor string
    certificates
    cert string
    certChain string
    rekor
    url string
    keyless
    additionalExtensions object
  • property name* string
  • issuer string
    rekor
    url string
    roots string
    subject string
    keys
    kms string
    publicKeys string
    rekor
    url string
    secret
    name string
    namespace string
    signatureAlgorithm string
    repository string
    image string
    imageReferences string[]
    issuer string
    key string
    mutateDigest boolean
    repository string
    required boolean
    roots string
    subject string
    verifyDigest boolean
    schemaValidation boolean
    validationFailureAction string
    validationFailureActionOverrides undefined[]
    action string
    namespaces string[]
    webhookTimeoutSeconds int32
    type string
    target

    Target contains targeting information for this cluster policy

    cluster

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • namespace

    A label selector is a label query over a set of resources. The result of matchLabels and matchExpressions are ANDed. An empty label selector matches all objects. A null label selector matches no objects.

    matchExpressions undefined[]

    matchExpressions is a list of label selector requirements. The requirements are ANDed.

    key string
    operator string
    values string[]
    matchLabels object

    matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

  • property name* string
  • status

    ClusterPolicyStatus defines the status of a cluster policy

    cloudResourcesCreated boolean
    conditions undefined[]
    detail string
    lastTransitionTime string
    message string
    name string
    negativePolarity boolean
    observedGeneration int64
    reason string
    status string
    type string
    detail string
    lastReconcile
    generation int64
    time string
    lastSuccess
    generation int64
    time string
    message string
    obsoleteResources undefined[]
    kind string
    name string
    routing undefined[]
    error string
    lastReconcile
    generation int64
    time string
    status string
    target
    group string
    kind string
    name string
    namespace string
    version string
    status string
    wayfinderVersion string
Loading...