Skip to content
This repository has been archived by the owner on Aug 28, 2024. It is now read-only.

Add kyverno exceptions for kube-system pods #653

Open
blancharda opened this issue Dec 14, 2023 · 0 comments
Open

Add kyverno exceptions for kube-system pods #653

blancharda opened this issue Dec 14, 2023 · 0 comments

Comments

@blancharda
Copy link
Contributor

RKE2 pods in the kube-system namespace violate many Kyverno policies (allowed registry, host path mounts, host network etc).
After kyverno is deployed in the cluster, adding or upgrading nodes fails.

As a temporary workaround, we are adding kube-system to the list of exempt namespaces, but longer term we should add more targeted policy exceptions.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant