Skip to content

Commit ba02586

Browse files
committed
fix: add insecure policy
Signed-off-by: Chris Butler <chris.butler@redhat.com>
1 parent 61c1e92 commit ba02586

2 files changed

Lines changed: 39 additions & 0 deletions

File tree

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
package agent_policy
2+
3+
default AddARPNeighborsRequest := true
4+
default AddSwapRequest := true
5+
default CloseStdinRequest := true
6+
default CopyFileRequest := true
7+
default CreateContainerRequest := true
8+
default CreateSandboxRequest := true
9+
default DestroySandboxRequest := true
10+
default ExecProcessRequest := true
11+
default GetMetricsRequest := true
12+
default GetOOMEventRequest := true
13+
default GuestDetailsRequest := true
14+
default ListInterfacesRequest := true
15+
default ListRoutesRequest := true
16+
default MemHotplugByProbeRequest := true
17+
default OnlineCPUMemRequest := true
18+
default PauseContainerRequest := true
19+
default PullImageRequest := true
20+
default ReadStreamRequest := true
21+
default RemoveContainerRequest := true
22+
default RemoveStaleVirtiofsShareMountsRequest := true
23+
default ReseedRandomDevRequest := true
24+
default ResumeContainerRequest := true
25+
default SetGuestDateTimeRequest := true
26+
default SetPolicyRequest := true
27+
default SignalProcessRequest := true
28+
default StartContainerRequest := true
29+
default StartTracingRequest := true
30+
default StatsContainerRequest := true
31+
default StopTracingRequest := true
32+
default TtyWinResizeRequest := true
33+
default UpdateContainerRequest := true
34+
default UpdateEphemeralMountsRequest := true
35+
default UpdateInterfaceRequest := true
36+
default UpdateRoutesRequest := true
37+
default WaitProcessRequest := true
38+
default WriteStreamRequest := true

charts/coco-supported/kbs-access/templates/sealed-pod.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ metadata:
66
app: sealed
77
annotations:
88
peerpods: "true"
9+
io.katacontainers.config.agent.policy: '{{ tpl ( .Files.Get "insecure-policy.rego") . | b64enc }}'
910
spec:
1011
runtimeClassName: kata-remote
1112
containers:

0 commit comments

Comments
 (0)