diff --git a/deploy/chart/values.yaml b/deploy/chart/values.yaml index ffb5891842..14e67d01df 100644 --- a/deploy/chart/values.yaml +++ b/deploy/chart/values.yaml @@ -2,7 +2,7 @@ rbacApiVersion: rbac.authorization.k8s.io namespace: operator-lifecycle-manager # see https://kubernetes.io/docs/concepts/security/pod-security-admission/ for more details namespace_psa: - enforceLevel: baseline + enforceLevel: restricted enforceVersion: latest auditLevel: restricted auditVersion: latest @@ -12,7 +12,7 @@ catalog_namespace: operator-lifecycle-manager operator_namespace: operators # see https://kubernetes.io/docs/concepts/security/pod-security-admission/ for more details operator_namespace_psa: - enforceLevel: baseline + enforceLevel: restricted enforceVersion: latest minKubeVersion: 1.11.0 writeStatusName: '""' diff --git a/deploy/upstream/values.yaml b/deploy/upstream/values.yaml index dbe19f2296..a7cf2e043b 100644 --- a/deploy/upstream/values.yaml +++ b/deploy/upstream/values.yaml @@ -9,7 +9,7 @@ catalog_namespace: olm operator_namespace: operators # see https://kubernetes.io/docs/concepts/security/pod-security-admission/ for more details operator_namespace_psa: - enforceLevel: baseline + enforceLevel: restricted enforceVersion: latest imagestream: false writeStatusName: '""' diff --git a/test/e2e/catalog_e2e_test.go b/test/e2e/catalog_e2e_test.go index 39fa0497d7..0ea9663522 100644 --- a/test/e2e/catalog_e2e_test.go +++ b/test/e2e/catalog_e2e_test.go @@ -1538,7 +1538,7 @@ var _ = Describe("Starting CatalogSource e2e tests", Label("CatalogSource"), fun }) }) }) - When("The namespace is labled as Pod Security Admission policy enforce:baseline", func() { + When("The namespace is labled as Pod Security Admission policy enforce:restricted", func() { BeforeEach(func() { var err error testNS := &corev1.Namespace{} @@ -1551,7 +1551,7 @@ var _ = Describe("Starting CatalogSource e2e tests", Label("CatalogSource"), fun }).Should(BeNil()) testNS.ObjectMeta.Labels = map[string]string{ - "pod-security.kubernetes.io/enforce": "baseline", + "pod-security.kubernetes.io/enforce": "restricted", "pod-security.kubernetes.io/enforce-version": "latest", }