Skip to content

Commit 8aa4e29

Browse files
committed
set default namespace values
1 parent 74e811f commit 8aa4e29

File tree

2 files changed

+5
-1
lines changed

2 files changed

+5
-1
lines changed

deploy/chart/templates/0000_50_olm_00-namespace.yaml

+4
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@ metadata:
66
{{- if .Values.namespace_psa }}
77
pod-security.kubernetes.io/enforce: {{ .Values.namespace_psa.enforceLevel }}
88
pod-security.kubernetes.io/enforce-version: {{ .Values.namespace_psa.enforceVersion }}
9+
pod-security.kubernetes.io/audit: restricted
10+
pod-security.kubernetes.io/warn: restricted
911
{{- end }}
1012

1113
---
@@ -17,4 +19,6 @@ metadata:
1719
{{- if .Values.operator_namespace_psa }}
1820
pod-security.kubernetes.io/enforce: {{ .Values.operator_namespace_psa.enforceLevel }}
1921
pod-security.kubernetes.io/enforce-version: {{ .Values.operator_namespace_psa.enforceVersion }}
22+
pod-security.kubernetes.io/audit: restricted
23+
pod-security.kubernetes.io/warn: restricted
2024
{{- end }}

deploy/chart/values.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ rbacApiVersion: rbac.authorization.k8s.io
22
namespace: operator-lifecycle-manager
33
# see https://kubernetes.io/docs/concepts/security/pod-security-admission/ for more details
44
namespace_psa:
5-
enforceLevel: restricted
5+
enforceLevel: baseline
66
enforceVersion: latest
77
catalog_namespace: operator-lifecycle-manager
88
operator_namespace: operators

0 commit comments

Comments
 (0)