StarlingX System Configuration Management
Go to file
Jerry Sun aa93e03b10 Add pod security admission controller labels
Pod security admission controller labels on namespaces are needed
for pod security admission controller to know how restrictive each
namespace is. This commit adds labels for pod security admission
controller to our namespaces. Pod security admission controller
is enabled by default on kubernetes 1.23. These labels do nothing
harmful or beneficial on the lower versions of kubernetes.

Test Plan:
PASS: Bootstrap system and ensure the pod security admission
      controller labels are present on our namespaces (kube-system,
      armada, deployment, and any namespaces created by applications
      such as cert-manager)
PASS: Upgrade an old system and ensure the labels are added after
      the upgrade is finished
PASS: Try to bring up privileged pods in a baseline namespace,
      ensure it fails. This was done on a developer iso, since
      we do not have kubernetes 1.23 ready yet. The same labels
      were applied to the developer iso's namespaces.
PASS: Deploy a privileged pod in a baseline namespace in the
      current kubernetes version. Ensure it is NOT rejected

Change-Id: Ib909eaacb6bba3b5c3327e2f9998a5ecdcb70e9b
Story: 2009833
Task: 44764
Signed-off-by: Jerry Sun <jerry.sun@windriver.com>
2022-03-25 16:43:21 -04:00
api-ref/source Merge "Remove force option for k8s rootca update complete/abort" 2021-11-25 17:32:40 +00:00
config-gate Add debian package for config-gate 2021-10-05 03:58:30 -04:00
controllerconfig Add pod security admission controller labels 2022-03-25 16:43:21 -04:00
devstack Remove host hardware sysinv profile 2021-10-18 18:01:40 -03:00
doc Switch to newer openstackdocstheme and reno versions 2020-06-04 14:13:51 +02:00
releasenotes Remove host hardware sysinv profile 2021-10-18 18:01:40 -03:00
storageconfig Add debian packaging directory for storageconfig 2021-10-18 10:05:38 -03:00
sysinv Add pod security admission controller labels 2022-03-25 16:43:21 -04:00
tmp/patch-scripts/EXAMPLE_SYSINV/scripts StarlingX open source release updates 2018-05-31 07:35:52 -07:00
tools/docker/images Enable kubernetes SCTPSupport feature 2019-09-03 19:23:05 +00:00
tsconfig Merge "debian: Install tsconfig in the right place" 2021-12-08 15:27:08 +00:00
workerconfig Add debian packaging directory for workerconfig 2021-09-28 09:51:54 -04:00
.gitignore Minor zuul and tox file cleanup after manifest re-org 2019-09-06 15:40:37 -05:00
.gitreview OpenDev Migration Patch 2019-04-19 19:52:42 +00:00
.yamllint clear yamllint errors under stx-config 2018-09-12 21:11:57 +08:00
.zuul.yaml Removing py36 gates from zuul for config 2021-10-05 16:29:11 +00:00
CONTRIBUTORS.wrs StarlingX open source release updates 2018-05-31 07:35:52 -07:00
LICENSE StarlingX open source release updates 2018-05-31 07:35:52 -07:00
README.rst StarlingX open source release updates 2018-05-31 07:35:52 -07:00
bindep.txt py3: Add py39 gate for sysinv 2021-08-27 08:39:06 -04:00
centos_build_layer.cfg Build layering, add layer build config file 2019-10-15 12:29:05 +08:00
centos_dev_wheels.inc Config file changes to add 'tsconfig' after relocation from 'update' 2019-09-05 11:51:05 -04:00
centos_helm.inc Infrastructure and Cluster Monitoring 2019-08-21 17:19:54 -04:00
centos_iso_image.inc Add cert-alarm service 2021-07-22 08:29:23 -04:00
centos_pkg_dirs Add cert-alarm service 2021-07-22 08:29:23 -04:00
centos_pkg_dirs_containers Config file changes for packages relocated to repo 'openstack-armada-app' 2019-09-05 10:42:00 -04:00
centos_stable_wheels.inc Config file changes to add 'tsconfig' after relocation from 'update' 2019-09-05 11:51:05 -04:00
debian_build_layer.cfg Add debian_build_layer.cfg file 2021-10-05 14:50:08 -04:00
debian_iso_image.inc Add debian_iso_image.inc file 2021-11-04 09:07:23 -04:00
debian_pkg_dirs Add missing packages that have debian directories. 2021-11-01 19:20:40 -04:00
test-requirements.txt Calling an additional shell lint command from zuul 2021-06-03 17:35:50 -05:00
tox.ini Calling an additional shell lint command from zuul 2021-06-03 17:35:50 -05:00

README.rst

stx-config

StarlingX Configuration Management