CKS · Question #61
3) Edit the ImagePolicyWebhook config. One of these is true on your cluster: Option 1 (most common in these tasks): ImagePolicyWebhook config is a standalone file. Option 2: ImagePolicyWebhook config
Edit the file in /etc/kubernetes/bouncer that contains kind: ImagePolicyWebhookConfiguration: grep -R "kind: ImagePolicyWebhookConfiguration" -n /etc/kubernetes/bouncer vi /etc/kubernetes/bouncer/<THE_FILE_YOU_FOUND>.yaml Set (or ensure) exactly: defaultAllow: false Option 2: Ima
Question
- Edit the ImagePolicyWebhook config. One of these is true on your cluster: Option 1 (most common in these tasks): ImagePolicyWebhook config is a standalone file. Option 2: ImagePolicyWebhook config is embedded inside AdmissionConfiguration.
Explanation
Edit the file in /etc/kubernetes/bouncer that contains kind: ImagePolicyWebhookConfiguration: grep -R "kind: ImagePolicyWebhookConfiguration" -n /etc/kubernetes/bouncer vi /etc/kubernetes/bouncer/<THE_FILE_YOU_FOUND>.yaml Set (or ensure) exactly: defaultAllow: false Option 2: ImagePolicyWebhook config is embedded inside AdmissionConfiguration Edit the AdmissionConfiguration file: vi /etc/kubernetes/bouncer/admission_configuration.yaml Find the plugin section for ImagePolicyWebhook and ensure the config includes: defaultAllow: false Save/exit: :wq
Topics
Community Discussion
No community discussion yet for this question.