Skip to content

policy values.yamlπŸ’£

openshiftπŸ’£

Type: bool

Default value
false

replicasπŸ’£

Type: int

Default value
3

auditIntervalπŸ’£

Type: int

Default value
300

metricsBackends[0]πŸ’£

Type: string

Default value
"prometheus"

auditMatchKindOnlyπŸ’£

Type: bool

Default value
true

constraintViolationsLimitπŸ’£

Type: int

Default value
1000

auditFromCacheπŸ’£

Type: bool

Default value
false

disableMutationπŸ’£

Type: bool

Default value
true

disableValidatingWebhookπŸ’£

Type: bool

Default value
false

validatingWebhookTimeoutSecondsπŸ’£

Type: int

Default value
15

validatingWebhookFailurePolicyπŸ’£

Type: string

Default value
"Ignore"

validatingWebhookAnnotationsπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

validatingWebhookExemptNamespacesLabelsπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

validatingWebhookObjectSelectorπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

validatingWebhookCheckIgnoreFailurePolicyπŸ’£

Type: string

Default value
"Fail"

validatingWebhookCustomRulesπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

enableDeleteOperationsπŸ’£

Type: bool

Default value
false

enableExternalDataπŸ’£

Type: bool

Default value
true

enableGeneratorResourceExpansionπŸ’£

Type: bool

Default value
false

enableTLSHealthcheckπŸ’£

Type: bool

Default value
false

maxServingThreadsπŸ’£

Type: int

Default value
-1

mutatingWebhookFailurePolicyπŸ’£

Type: string

Default value
"Ignore"

mutatingWebhookReinvocationPolicyπŸ’£

Type: string

Default value
"Never"

mutatingWebhookAnnotationsπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

mutatingWebhookExemptNamespacesLabelsπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

mutatingWebhookObjectSelectorπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

mutatingWebhookTimeoutSecondsπŸ’£

Type: int

Default value
1

mutatingWebhookCustomRulesπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

mutationAnnotationsπŸ’£

Type: bool

Default value
false

auditChunkSizeπŸ’£

Type: int

Default value
500

logLevelπŸ’£

Type: string

Default value
"INFO"

logDeniesπŸ’£

Type: bool

Default value
true

logMutationsπŸ’£

Type: bool

Default value
true

emitAdmissionEventsπŸ’£

Type: bool

Default value
false

emitAuditEventsπŸ’£

Type: bool

Default value
false

resourceQuotaπŸ’£

Type: bool

Default value
true

postUpgrade.labelNamespace.enabledπŸ’£

Type: bool

Default value
false

postUpgrade.labelNamespace.image.repositoryπŸ’£

Type: string

Default value
"registry1.dso.mil/ironbank/opensource/kubernetes/kubectl"

postUpgrade.labelNamespace.image.tagπŸ’£

Type: string

Default value
"v1.25.6"

postUpgrade.labelNamespace.image.pullPolicyπŸ’£

Type: string

Default value
"IfNotPresent"

postUpgrade.labelNamespace.image.pullSecretsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postUpgrade.labelNamespace.extraNamespacesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postUpgrade.labelNamespace.podSecurityπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postUpgrade.affinityπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

postUpgrade.tolerationsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postUpgrade.nodeSelector.”kubernetes.io/os”πŸ’£

Type: string

Default value
"linux"

postUpgrade.resourcesπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

postUpgrade.securityContext.allowPrivilegeEscalationπŸ’£

Type: bool

Default value
false

postUpgrade.securityContext.capabilities.drop[0]πŸ’£

Type: string

Default value
"ALL"

postUpgrade.securityContext.readOnlyRootFilesystemπŸ’£

Type: bool

Default value
true

postUpgrade.securityContext.runAsGroupπŸ’£

Type: int

Default value
999

postUpgrade.securityContext.runAsNonRootπŸ’£

Type: bool

Default value
true

postUpgrade.securityContext.runAsUserπŸ’£

Type: int

Default value
1000

postInstall.labelNamespace.enabledπŸ’£

Type: bool

Default value
true

postInstall.labelNamespace.extraRulesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postInstall.labelNamespace.image.repositoryπŸ’£

Type: string

Default value
"registry1.dso.mil/ironbank/opensource/kubernetes/kubectl"

postInstall.labelNamespace.image.tagπŸ’£

Type: string

Default value
"v1.25.6"

postInstall.labelNamespace.image.pullPolicyπŸ’£

Type: string

Default value
"IfNotPresent"

postInstall.labelNamespace.image.pullSecretsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postInstall.labelNamespace.extraNamespacesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postInstall.labelNamespace.podSecurityπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postInstall.probeWebhook.enabledπŸ’£

Type: bool

Default value
true

postInstall.probeWebhook.image.repositoryπŸ’£

Type: string

Default value
"registry1.dso.mil/ironbank/big-bang/base"

postInstall.probeWebhook.image.tagπŸ’£

Type: string

Default value
"2.0.0"

postInstall.probeWebhook.image.pullPolicyπŸ’£

Type: string

Default value
"IfNotPresent"

postInstall.probeWebhook.image.pullSecretsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postInstall.probeWebhook.waitTimeoutπŸ’£

Type: int

Default value
60

postInstall.probeWebhook.httpTimeoutπŸ’£

Type: int

Default value
2

postInstall.probeWebhook.insecureHTTPSπŸ’£

Type: bool

Default value
false

postInstall.affinityπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

postInstall.tolerationsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

postInstall.nodeSelector.”kubernetes.io/os”πŸ’£

Type: string

Default value
"linux"

postInstall.securityContext.allowPrivilegeEscalationπŸ’£

Type: bool

Default value
false

postInstall.securityContext.capabilities.drop[0]πŸ’£

Type: string

Default value
"ALL"

postInstall.securityContext.readOnlyRootFilesystemπŸ’£

Type: bool

Default value
true

postInstall.securityContext.runAsGroupπŸ’£

Type: int

Default value
999

postInstall.securityContext.runAsNonRootπŸ’£

Type: bool

Default value
true

postInstall.securityContext.runAsUserπŸ’£

Type: int

Default value
1000

preUninstall.deleteWebhookConfigurations.extraRulesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

preUninstall.deleteWebhookConfigurations.enabledπŸ’£

Type: bool

Default value
false

preUninstall.deleteWebhookConfigurations.image.repositoryπŸ’£

Type: string

Default value
"registry1.dso.mil/ironbank/opensource/kubernetes/kubectl"

preUninstall.deleteWebhookConfigurations.image.tagπŸ’£

Type: string

Default value
"v1.25.6"

preUninstall.deleteWebhookConfigurations.image.pullPolicyπŸ’£

Type: string

Default value
"IfNotPresent"

preUninstall.deleteWebhookConfigurations.image.pullSecretsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

preUninstall.affinityπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

preUninstall.tolerationsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

preUninstall.nodeSelector.”kubernetes.io/os”πŸ’£

Type: string

Default value
"linux"

preUninstall.resourcesπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

preUninstall.securityContext.allowPrivilegeEscalationπŸ’£

Type: bool

Default value
false

preUninstall.securityContext.capabilities.drop[0]πŸ’£

Type: string

Default value
"ALL"

preUninstall.securityContext.readOnlyRootFilesystemπŸ’£

Type: bool

Default value
true

preUninstall.securityContext.runAsGroupπŸ’£

Type: int

Default value
999

preUninstall.securityContext.runAsNonRootπŸ’£

Type: bool

Default value
true

preUninstall.securityContext.runAsUserπŸ’£

Type: int

Default value
1000

image.repositoryπŸ’£

Type: string

Default value
"registry1.dso.mil/ironbank/opensource/openpolicyagent/gatekeeper"

image.releaseπŸ’£

Type: string

Default value
"v3.11.0"

image.pullPolicyπŸ’£

Type: string

Default value
"IfNotPresent"

image.pullSecrets[0].nameπŸ’£

Type: string

Default value
"private-registry"

image.crdRepositoryπŸ’£

Type: string

Default value
"registry1.dso.mil/ironbank/opensource/kubernetes/kubectl"

image.crdReleaseπŸ’£

Type: string

Default value
"v1.25.6"

podAnnotations.”container.seccomp.security.alpha.kubernetes.io/manager”πŸ’£

Type: string

Default value
"runtime/default"

podLabelsπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

podCountLimitπŸ’£

Type: string

Default value
"100"

secretAnnotationsπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

enableRuntimeDefaultSeccompProfileπŸ’£

Type: bool

Default value
true

controllerManager.exemptNamespacesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

controllerManager.exemptNamespacePrefixesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

controllerManager.hostNetworkπŸ’£

Type: bool

Default value
false

controllerManager.dnsPolicyπŸ’£

Type: string

Default value
"ClusterFirst"

controllerManager.portπŸ’£

Type: int

Default value
8443

controllerManager.metricsPortπŸ’£

Type: int

Default value
8888

controllerManager.healthPortπŸ’£

Type: int

Default value
9090

controllerManager.readinessTimeoutπŸ’£

Type: int

Default value
1

controllerManager.livenessTimeoutπŸ’£

Type: int

Default value
1

controllerManager.priorityClassNameπŸ’£

Type: string

Default value
"system-cluster-critical"

controllerManager.disableCertRotationπŸ’£

Type: bool

Default value
false

controllerManager.tlsMinVersionπŸ’£

Type: float

Default value
1.3

controllerManager.clientCertNameπŸ’£

Type: string

Default value
""

controllerManager.affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].podAffinityTerm.labelSelector.matchExpressions[0].keyπŸ’£

Type: string

Default value
"gatekeeper.sh/operation"

controllerManager.affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].podAffinityTerm.labelSelector.matchExpressions[0].operatorπŸ’£

Type: string

Default value
"In"

controllerManager.affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].podAffinityTerm.labelSelector.matchExpressions[0].values[0]πŸ’£

Type: string

Default value
"webhook"

controllerManager.affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].podAffinityTerm.topologyKeyπŸ’£

Type: string

Default value
"kubernetes.io/hostname"

controllerManager.affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].weightπŸ’£

Type: int

Default value
100

controllerManager.topologySpreadConstraintsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

controllerManager.tolerationsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

controllerManager.nodeSelector.”kubernetes.io/os”πŸ’£

Type: string

Default value
"linux"

controllerManager.resources.limits.cpuπŸ’£

Type: string

Default value
"175m"

controllerManager.resources.limits.memoryπŸ’£

Type: string

Default value
"512Mi"

controllerManager.resources.requests.cpuπŸ’£

Type: string

Default value
"175m"

controllerManager.resources.requests.memoryπŸ’£

Type: string

Default value
"512Mi"

controllerManager.securityContext.allowPrivilegeEscalationπŸ’£

Type: bool

Default value
false

controllerManager.securityContext.capabilities.drop[0]πŸ’£

Type: string

Default value
"ALL"

controllerManager.securityContext.readOnlyRootFilesystemπŸ’£

Type: bool

Default value
true

controllerManager.securityContext.runAsGroupπŸ’£

Type: int

Default value
999

controllerManager.securityContext.runAsNonRootπŸ’£

Type: bool

Default value
true

controllerManager.securityContext.runAsUserπŸ’£

Type: int

Default value
1000

controllerManager.podSecurityContext.fsGroupπŸ’£

Type: int

Default value
999

controllerManager.podSecurityContext.supplementalGroups[0]πŸ’£

Type: int

Default value
999

controllerManager.extraRulesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

audit.hostNetworkπŸ’£

Type: bool

Default value
false

audit.dnsPolicyπŸ’£

Type: string

Default value
"ClusterFirst"

audit.metricsPortπŸ’£

Type: int

Default value
8888

audit.healthPortπŸ’£

Type: int

Default value
9090

audit.readinessTimeoutπŸ’£

Type: int

Default value
1

audit.livenessTimeoutπŸ’£

Type: int

Default value
1

audit.priorityClassNameπŸ’£

Type: string

Default value
"system-cluster-critical"

audit.disableCertRotationπŸ’£

Type: bool

Default value
true

audit.affinityπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

audit.tolerationsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

audit.nodeSelector.”kubernetes.io/os”πŸ’£

Type: string

Default value
"linux"

audit.resources.limits.cpuπŸ’£

Type: float

Default value
1.2

audit.resources.limits.memoryπŸ’£

Type: string

Default value
"768Mi"

audit.resources.requests.cpuπŸ’£

Type: float

Default value
1.2

audit.resources.requests.memoryπŸ’£

Type: string

Default value
"768Mi"

audit.securityContext.allowPrivilegeEscalationπŸ’£

Type: bool

Default value
false

audit.securityContext.capabilities.drop[0]πŸ’£

Type: string

Default value
"ALL"

audit.securityContext.readOnlyRootFilesystemπŸ’£

Type: bool

Default value
true

audit.securityContext.runAsGroupπŸ’£

Type: int

Default value
999

audit.securityContext.runAsNonRootπŸ’£

Type: bool

Default value
true

audit.securityContext.runAsUserπŸ’£

Type: int

Default value
1000

audit.podSecurityContext.fsGroupπŸ’£

Type: int

Default value
999

audit.podSecurityContext.supplementalGroups[0]πŸ’£

Type: int

Default value
999

audit.writeToRAMDiskπŸ’£

Type: bool

Default value
false

audit.extraRulesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

crds.affinityπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

crds.tolerationsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

crds.nodeSelector.”kubernetes.io/os”πŸ’£

Type: string

Default value
"linux"

crds.resourcesπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

crds.securityContext.allowPrivilegeEscalationπŸ’£

Type: bool

Default value
false

crds.securityContext.capabilities.drop[0]πŸ’£

Type: string

Default value
"ALL"

crds.securityContext.readOnlyRootFilesystemπŸ’£

Type: bool

Default value
true

crds.securityContext.runAsGroupπŸ’£

Type: int

Default value
65532

crds.securityContext.runAsNonRootπŸ’£

Type: bool

Default value
true

crds.securityContext.runAsUserπŸ’£

Type: int

Default value
65532

pdb.controllerManager.minAvailableπŸ’£

Type: int

Default value
1

serviceπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

disabledBuiltins[0]πŸ’£

Type: string

Default value
"{http.send}"

psp.enabledπŸ’£

Type: bool

Default value
false

upgradeCRDs.enabledπŸ’£

Type: bool

Default value
true

upgradeCRDs.extraRulesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

cleanupCRDs.enabledπŸ’£

Type: bool

Default value
true

rbac.createπŸ’£

Type: bool

Default value
true

externalCertInjection.enabledπŸ’£

Type: bool

Default value
false

externalCertInjection.secretNameπŸ’£

Type: string

Default value
"gatekeeper-webhook-server-cert"

violations.allowedAppArmorProfiles.enabledπŸ’£

Type: bool

Default value
false

violations.allowedAppArmorProfiles.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.allowedAppArmorProfiles.kindπŸ’£

Type: string

Default value
"K8sPSPAppArmor"

violations.allowedAppArmorProfiles.nameπŸ’£

Type: string

Default value
"allowed-app-armor-profiles"

violations.allowedAppArmorProfiles.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.allowedAppArmorProfiles.parameters.allowedProfiles[0]πŸ’£

Type: string

Default value
"runtime/default"

violations.allowedAppArmorProfiles.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedCapabilities.enabledπŸ’£

Type: bool

Default value
true

violations.allowedCapabilities.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.allowedCapabilities.kindπŸ’£

Type: string

Default value
"K8sPSPCapabilities"

violations.allowedCapabilities.nameπŸ’£

Type: string

Default value
"allowed-capabilities"

violations.allowedCapabilities.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.allowedCapabilities.parameters.allowedCapabilitiesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedCapabilities.parameters.requiredDropCapabilities[0]πŸ’£

Type: string

Default value
"all"

violations.allowedCapabilities.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedDockerRegistries.enabledπŸ’£

Type: bool

Default value
true

violations.allowedDockerRegistries.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.allowedDockerRegistries.kindπŸ’£

Type: string

Default value
"K8sAllowedRepos"

violations.allowedDockerRegistries.nameπŸ’£

Type: string

Default value
"allowed-docker-registries"

violations.allowedDockerRegistries.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.allowedDockerRegistries.parameters.repos[0]πŸ’£

Type: string

Default value
"registry1.dso.mil"

violations.allowedDockerRegistries.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedFlexVolumes.enabledπŸ’£

Type: bool

Default value
true

violations.allowedFlexVolumes.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.allowedFlexVolumes.kindπŸ’£

Type: string

Default value
"K8sPSPFlexVolumes"

violations.allowedFlexVolumes.nameπŸ’£

Type: string

Default value
"allowed-flex-volumes"

violations.allowedFlexVolumes.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.allowedFlexVolumes.parameters.allowedFlexVolumesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedFlexVolumes.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedHostFilesystem.enabledπŸ’£

Type: bool

Default value
true

violations.allowedHostFilesystem.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.allowedHostFilesystem.kindπŸ’£

Type: string

Default value
"K8sPSPHostFilesystem"

violations.allowedHostFilesystem.nameπŸ’£

Type: string

Default value
"allowed-host-filesystem"

violations.allowedHostFilesystem.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.allowedHostFilesystem.parameters.allowedHostPathsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedHostFilesystem.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedIPs.enabledπŸ’£

Type: bool

Default value
true

violations.allowedIPs.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.allowedIPs.kindπŸ’£

Type: string

Default value
"K8sExternalIPs"

violations.allowedIPs.nameπŸ’£

Type: string

Default value
"allowed-ips"

violations.allowedIPs.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.allowedIPs.parameters.allowedIPsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedIPs.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedProcMount.enabledπŸ’£

Type: bool

Default value
true

violations.allowedProcMount.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.allowedProcMount.kindπŸ’£

Type: string

Default value
"K8sPSPProcMount"

violations.allowedProcMount.nameπŸ’£

Type: string

Default value
"allowed-proc-mount"

violations.allowedProcMount.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.allowedProcMount.parameters.procMountπŸ’£

Type: string

Default value
"Default"

violations.allowedProcMount.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedSecCompProfiles.enabledπŸ’£

Type: bool

Default value
true

violations.allowedSecCompProfiles.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.allowedSecCompProfiles.kindπŸ’£

Type: string

Default value
"K8sPSPSeccomp"

violations.allowedSecCompProfiles.nameπŸ’£

Type: string

Default value
"allowed-sec-comp-profiles"

violations.allowedSecCompProfiles.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.allowedSecCompProfiles.parameters.allowedProfiles[0]πŸ’£

Type: string

Default value
"runtime/default"

violations.allowedSecCompProfiles.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.allowedUsers.enabledπŸ’£

Type: bool

Default value
true

violations.allowedUsers.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.allowedUsers.kindπŸ’£

Type: string

Default value
"K8sPSPAllowedUsers"

violations.allowedUsers.nameπŸ’£

Type: string

Default value
"allowed-users"

violations.allowedUsers.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.allowedUsers.parameters.runAsUser.ruleπŸ’£

Type: string

Default value
"MustRunAsNonRoot"

violations.allowedUsers.parameters.fsGroup.ruleπŸ’£

Type: string

Default value
"MustRunAs"

violations.allowedUsers.parameters.fsGroup.ranges[0].minπŸ’£

Type: int

Default value
1000

violations.allowedUsers.parameters.fsGroup.ranges[0].maxπŸ’£

Type: int

Default value
65535

violations.allowedUsers.parameters.runAsGroup.ruleπŸ’£

Type: string

Default value
"MustRunAs"

violations.allowedUsers.parameters.runAsGroup.ranges[0].minπŸ’£

Type: int

Default value
1000

violations.allowedUsers.parameters.runAsGroup.ranges[0].maxπŸ’£

Type: int

Default value
65535

violations.allowedUsers.parameters.supplementalGroups.ruleπŸ’£

Type: string

Default value
"MustRunAs"

violations.allowedUsers.parameters.supplementalGroups.ranges[0].minπŸ’£

Type: int

Default value
1000

violations.allowedUsers.parameters.supplementalGroups.ranges[0].maxπŸ’£

Type: int

Default value
65535

violations.allowedUsers.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.bannedImageTags.enabledπŸ’£

Type: bool

Default value
true

violations.bannedImageTags.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.bannedImageTags.kindπŸ’£

Type: string

Default value
"K8sBannedImageTags"

violations.bannedImageTags.nameπŸ’£

Type: string

Default value
"banned-image-tags"

violations.bannedImageTags.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.bannedImageTags.parameters.tags[0]πŸ’£

Type: string

Default value
"latest"

violations.bannedImageTags.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.blockNodePort.enabledπŸ’£

Type: bool

Default value
true

violations.blockNodePort.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.blockNodePort.kindπŸ’£

Type: string

Default value
"K8sBlockNodePort"

violations.blockNodePort.nameπŸ’£

Type: string

Default value
"block-node-ports"

violations.blockNodePort.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.blockNodePort.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.containerRatio.enabledπŸ’£

Type: bool

Default value
true

violations.containerRatio.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.containerRatio.kindπŸ’£

Type: string

Default value
"K8sContainerRatios"

violations.containerRatio.nameπŸ’£

Type: string

Default value
"container-ratios"

violations.containerRatio.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.containerRatio.parameters.ratioπŸ’£

Type: string

Default value
"2"

violations.containerRatio.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.hostNetworking.enabledπŸ’£

Type: bool

Default value
true

violations.hostNetworking.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.hostNetworking.kindπŸ’£

Type: string

Default value
"K8sPSPHostNetworkingPorts"

violations.hostNetworking.nameπŸ’£

Type: string

Default value
"host-networking"

violations.hostNetworking.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.hostNetworking.parameters.hostNetworkπŸ’£

Type: bool

Default value
false

violations.hostNetworking.parameters.minπŸ’£

Type: int

Default value
0

violations.hostNetworking.parameters.maxπŸ’£

Type: int

Default value
0

violations.hostNetworking.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.httpsOnly.enabledπŸ’£

Type: bool

Default value
true

violations.httpsOnly.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.httpsOnly.kindπŸ’£

Type: string

Default value
"K8sHttpsOnly2"

violations.httpsOnly.nameπŸ’£

Type: string

Default value
"https-only"

violations.httpsOnly.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.httpsOnly.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.imageDigest.enabledπŸ’£

Type: bool

Default value
true

violations.imageDigest.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.imageDigest.kindπŸ’£

Type: string

Default value
"K8sImageDigests2"

violations.imageDigest.nameπŸ’£

Type: string

Default value
"image-digest"

violations.imageDigest.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.imageDigest.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.namespacesHaveIstio.enabledπŸ’£

Type: bool

Default value
true

violations.namespacesHaveIstio.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.namespacesHaveIstio.kindπŸ’£

Type: string

Default value
"K8sRequiredLabelValues"

violations.namespacesHaveIstio.nameπŸ’£

Type: string

Default value
"namespaces-have-istio"

violations.namespacesHaveIstio.match.namespaceSelector.matchExpressions[0].keyπŸ’£

Type: string

Default value
"admission.gatekeeper.sh/ignore"

violations.namespacesHaveIstio.match.namespaceSelector.matchExpressions[0].operatorπŸ’£

Type: string

Default value
"DoesNotExist"

violations.namespacesHaveIstio.parameters.labels[0].allowedRegexπŸ’£

Type: string

Default value
"^enabled"

violations.namespacesHaveIstio.parameters.labels[0].keyπŸ’£

Type: string

Default value
"istio-injection"

violations.namespacesHaveIstio.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.noBigContainers.enabledπŸ’£

Type: bool

Default value
true

violations.noBigContainers.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.noBigContainers.kindπŸ’£

Type: string

Default value
"K8sContainerLimits"

violations.noBigContainers.nameπŸ’£

Type: string

Default value
"no-big-container"

violations.noBigContainers.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.noBigContainers.parameters.cpuπŸ’£

Type: string

Default value
"2000m"

violations.noBigContainers.parameters.memoryπŸ’£

Type: string

Default value
"4G"

violations.noBigContainers.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.noHostNamespace.enabledπŸ’£

Type: bool

Default value
true

violations.noHostNamespace.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.noHostNamespace.kindπŸ’£

Type: string

Default value
"K8sPSPHostNamespace2"

violations.noHostNamespace.nameπŸ’£

Type: string

Default value
"no-host-namespace"

violations.noHostNamespace.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.noHostNamespace.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.noPrivilegedContainers.enabledπŸ’£

Type: bool

Default value
true

violations.noPrivilegedContainers.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.noPrivilegedContainers.kindπŸ’£

Type: string

Default value
"K8sPSPPrivilegedContainer2"

violations.noPrivilegedContainers.nameπŸ’£

Type: string

Default value
"no-privileged-containers"

violations.noPrivilegedContainers.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.noPrivilegedContainers.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.noDefaultServiceAccount.enabledπŸ’£

Type: bool

Default value
true

violations.noDefaultServiceAccount.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.noDefaultServiceAccount.kindπŸ’£

Type: string

Default value
"K8sDenySADefault"

violations.noDefaultServiceAccount.nameπŸ’£

Type: string

Default value
"no-default-service-account"

violations.noDefaultServiceAccount.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.noDefaultServiceAccount.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.noPrivilegedEscalation.enabledπŸ’£

Type: bool

Default value
true

violations.noPrivilegedEscalation.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.noPrivilegedEscalation.kindπŸ’£

Type: string

Default value
"K8sPSPAllowPrivilegeEscalationContainer2"

violations.noPrivilegedEscalation.nameπŸ’£

Type: string

Default value
"no-privileged-escalation"

violations.noPrivilegedEscalation.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.noPrivilegedEscalation.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.noSysctls.enabledπŸ’£

Type: bool

Default value
true

violations.noSysctls.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.noSysctls.kindπŸ’£

Type: string

Default value
"K8sPSPForbiddenSysctls"

violations.noSysctls.nameπŸ’£

Type: string

Default value
"no-sysctls"

violations.noSysctls.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.noSysctls.parameters.forbiddenSysctls[0]πŸ’£

Type: string

Default value
"*"

violations.noSysctls.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.podsHaveIstio.enabledπŸ’£

Type: bool

Default value
true

violations.podsHaveIstio.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.podsHaveIstio.kindπŸ’£

Type: string

Default value
"K8sNoAnnotationValues"

violations.podsHaveIstio.nameπŸ’£

Type: string

Default value
"pods-have-istio"

violations.podsHaveIstio.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.podsHaveIstio.parameters.annotations[0].disallowedRegexπŸ’£

Type: string

Default value
"^false"

violations.podsHaveIstio.parameters.annotations[0].keyπŸ’£

Type: string

Default value
"sidecar.istio.io/inject"

violations.podsHaveIstio.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.readOnlyRoot.enabledπŸ’£

Type: bool

Default value
true

violations.readOnlyRoot.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.readOnlyRoot.kindπŸ’£

Type: string

Default value
"K8sPSPReadOnlyRootFilesystem2"

violations.readOnlyRoot.nameπŸ’£

Type: string

Default value
"read-only-root"

violations.readOnlyRoot.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.readOnlyRoot.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.requiredLabels.enabledπŸ’£

Type: bool

Default value
true

violations.requiredLabels.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.requiredLabels.kindπŸ’£

Type: string

Default value
"K8sRequiredLabelValues"

violations.requiredLabels.nameπŸ’£

Type: string

Default value
"required-labels"

violations.requiredLabels.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.requiredLabels.parameters.labels[0].allowedRegexπŸ’£

Type: string

Default value
""

violations.requiredLabels.parameters.labels[0].keyπŸ’£

Type: string

Default value
"app.kubernetes.io/name"

violations.requiredLabels.parameters.labels[1].allowedRegexπŸ’£

Type: string

Default value
""

violations.requiredLabels.parameters.labels[1].keyπŸ’£

Type: string

Default value
"app.kubernetes.io/instance"

violations.requiredLabels.parameters.labels[2].allowedRegexπŸ’£

Type: string

Default value
""

violations.requiredLabels.parameters.labels[2].keyπŸ’£

Type: string

Default value
"app.kubernetes.io/version"

violations.requiredLabels.parameters.labels[3].allowedRegexπŸ’£

Type: string

Default value
""

violations.requiredLabels.parameters.labels[3].keyπŸ’£

Type: string

Default value
"app.kubernetes.io/component"

violations.requiredLabels.parameters.labels[4].allowedRegexπŸ’£

Type: string

Default value
""

violations.requiredLabels.parameters.labels[4].keyπŸ’£

Type: string

Default value
"app.kubernetes.io/part-of"

violations.requiredLabels.parameters.labels[5].allowedRegexπŸ’£

Type: string

Default value
""

violations.requiredLabels.parameters.labels[5].keyπŸ’£

Type: string

Default value
"app.kubernetes.io/managed-by"

violations.requiredLabels.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.requiredProbes.enabledπŸ’£

Type: bool

Default value
true

violations.requiredProbes.enforcementActionπŸ’£

Type: string

Default value
"dryrun"

violations.requiredProbes.kindπŸ’£

Type: string

Default value
"K8sRequiredProbes"

violations.requiredProbes.nameπŸ’£

Type: string

Default value
"required-probes"

violations.requiredProbes.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.requiredProbes.parameters.probeTypes[0]πŸ’£

Type: string

Default value
"tcpSocket"

violations.requiredProbes.parameters.probeTypes[1]πŸ’£

Type: string

Default value
"httpGet"

violations.requiredProbes.parameters.probeTypes[2]πŸ’£

Type: string

Default value
"exec"

violations.requiredProbes.parameters.probes[0]πŸ’£

Type: string

Default value
"readinessProbe"

violations.requiredProbes.parameters.probes[1]πŸ’£

Type: string

Default value
"livenessProbe"

violations.requiredProbes.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.restrictedTaint.enabledπŸ’£

Type: bool

Default value
true

violations.restrictedTaint.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.restrictedTaint.kindπŸ’£

Type: string

Default value
"RestrictedTaintToleration"

violations.restrictedTaint.nameπŸ’£

Type: string

Default value
"restricted-taint"

violations.restrictedTaint.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.restrictedTaint.parameters.allowGlobalTolerationπŸ’£

Type: bool

Default value
false

violations.restrictedTaint.parameters.restrictedTaint.effectπŸ’£

Type: string

Default value
"NoSchedule"

violations.restrictedTaint.parameters.restrictedTaint.keyπŸ’£

Type: string

Default value
"privileged"

violations.restrictedTaint.parameters.restrictedTaint.valueπŸ’£

Type: string

Default value
"true"

violations.restrictedTaint.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.selinuxPolicy.enabledπŸ’£

Type: bool

Default value
true

violations.selinuxPolicy.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.selinuxPolicy.kindπŸ’£

Type: string

Default value
"K8sPSPSELinuxV2"

violations.selinuxPolicy.nameπŸ’£

Type: string

Default value
"selinux-policy"

violations.selinuxPolicy.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.selinuxPolicy.parameters.allowedSELinuxOptionsπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.selinuxPolicy.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.uniqueIngressHost.enabledπŸ’£

Type: bool

Default value
true

violations.uniqueIngressHost.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.uniqueIngressHost.kindπŸ’£

Type: string

Default value
"K8sUniqueIngressHost"

violations.uniqueIngressHost.nameπŸ’£

Type: string

Default value
"unique-ingress-hosts"

violations.uniqueIngressHost.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.uniqueIngressHost.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

violations.volumeTypes.enabledπŸ’£

Type: bool

Default value
true

violations.volumeTypes.enforcementActionπŸ’£

Type: string

Default value
"deny"

violations.volumeTypes.kindπŸ’£

Type: string

Default value
"K8sPSPVolumeTypes"

violations.volumeTypes.nameπŸ’£

Type: string

Default value
"volume-types"

violations.volumeTypes.matchπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}

violations.volumeTypes.parameters.volumes[0]πŸ’£

Type: string

Default value
"configMap"

violations.volumeTypes.parameters.volumes[1]πŸ’£

Type: string

Default value
"emptyDir"

violations.volumeTypes.parameters.volumes[2]πŸ’£

Type: string

Default value
"projected"

violations.volumeTypes.parameters.volumes[3]πŸ’£

Type: string

Default value
"secret"

violations.volumeTypes.parameters.volumes[4]πŸ’£

Type: string

Default value
"downwardAPI"

violations.volumeTypes.parameters.volumes[5]πŸ’£

Type: string

Default value
"persistentVolumeClaim"

violations.volumeTypes.parameters.excludedResourcesπŸ’£

Type: list

Default value
[]
Default value (formatted)
[]

monitoring.enabledπŸ’£

Type: bool

Default value
false

networkPolicies.enabledπŸ’£

Type: bool

Default value
false

networkPolicies.controlPlaneCidrπŸ’£

Type: string

Default value
"0.0.0.0/0"

bbtests.enabledπŸ’£

Type: bool

Default value
false

bbtests.scripts.imageπŸ’£

Type: string

Default value
"registry1.dso.mil/ironbank/opensource/kubernetes/kubectl:v1.25.6"

bbtests.scripts.additionalVolumeMounts[0].nameπŸ’£

Type: string

Default value
"{{ .Chart.Name }}-test-config"

bbtests.scripts.additionalVolumeMounts[0].mountPathπŸ’£

Type: string

Default value
"/yaml"

bbtests.scripts.additionalVolumeMounts[1].nameπŸ’£

Type: string

Default value
"{{ .Chart.Name }}-kube-cache"

bbtests.scripts.additionalVolumeMounts[1].mountPathπŸ’£

Type: string

Default value
"/.kube/cache"

bbtests.scripts.additionalVolumes[0].nameπŸ’£

Type: string

Default value
"{{ .Chart.Name }}-test-config"

bbtests.scripts.additionalVolumes[0].configMap.nameπŸ’£

Type: string

Default value
"{{ .Chart.Name }}-test-config"

bbtests.scripts.additionalVolumes[1].nameπŸ’£

Type: string

Default value
"{{ .Chart.Name }}-kube-cache"

bbtests.scripts.additionalVolumes[1].emptyDirπŸ’£

Type: object

Default value
{}
Default value (formatted)
{}