2revisionHistoryLimit: 10
4metricsBackends: ["prometheus"]
5auditMatchKindOnly: false
6constraintViolationsLimit: 20
10disableValidatingWebhook: false
11validatingWebhookName: gatekeeper-validating-webhook-configuration
12validatingWebhookTimeoutSeconds: 3
13validatingWebhookFailurePolicy: Ignore
14validatingWebhookAnnotations: {}
15validatingWebhookExemptNamespacesLabels: {}
16validatingWebhookObjectSelector: {}
17validatingWebhookMatchConditions: []
18validatingWebhookCheckIgnoreFailurePolicy: Fail
19validatingWebhookCustomRules: {}
20validatingWebhookSubResources: ["pods/ephemeralcontainers", "pods/exec", "pods/log", "pods/eviction", "pods/portforward", "pods/proxy", "pods/attach", "pods/binding", "pods/resize", "deployments/scale", "replicasets/scale", "statefulsets/scale", "replicationcontrollers/scale", "services/proxy", "nodes/proxy", "services/status"]
21validatingWebhookURL: null
22validatingWebhookScope: "*"
23enableDeleteOperations: false
24enableConnectOperations: false
25enableExternalData: true
26enableGeneratorResourceExpansion: true
27enableTLSHealthcheck: false
29mutatingWebhookName: gatekeeper-mutating-webhook-configuration
30mutatingWebhookFailurePolicy: Ignore
31mutatingWebhookReinvocationPolicy: Never
32mutatingWebhookAnnotations: {}
33mutatingWebhookExemptNamespacesLabels: {}
34mutatingWebhookObjectSelector: {}
35mutatingWebhookMatchConditions: []
36mutatingWebhookTimeoutSeconds: 1
37mutatingWebhookCustomRules: {}
38mutatingWebhookSubResources: ["pods/ephemeralcontainers", "pods/exec", "pods/log", "pods/eviction", "pods/portforward", "pods/proxy", "pods/attach", "pods/binding", "deployments/scale", "replicasets/scale", "statefulsets/scale", "replicationcontrollers/scale", "services/proxy", "nodes/proxy", "services/status"]
39mutatingWebhookURL: null
40mutatingWebhookScope: "*"
41mutationAnnotations: false
46admissionEventsInvolvedNamespace: false
47auditEventsInvolvedNamespace: false
49externaldataProviderResponseCacheTTL: 3m
50enableK8sNativeValidation: true
55 repository: cgr.dev/chainguard-private/gatekeeper-fips
56 crdRepository: openpolicyagent/gatekeeper-crds
57 release: latest@sha256:3048e2dc9502e6a94c841e9a96e4e1ba9496dd01e25c4284ebab94fd5fabe9d8
58 pullPolicy: IfNotPresent
63 repository: cgr.dev/chainguard-private/gatekeeper-crds-fips
64 tag: latest@sha256:851b60969315e4bd2d225fa3a33bc3659f7a1b790878367f9bc56c47e21a6510
68 name: gatekeeper-update-namespace-label-post-upgrade
72 repository: cgr.dev/chainguard-private/gatekeeper-crds-fips
73 tag: latest@sha256:851b60969315e4bd2d225fa3a33bc3659f7a1b790878367f9bc56c47e21a6510
74 pullPolicy: IfNotPresent
77 podSecurity: ["pod-security.kubernetes.io/audit=restricted", "pod-security.kubernetes.io/audit-version=latest", "pod-security.kubernetes.io/warn=restricted", "pod-security.kubernetes.io/warn-version=latest", "pod-security.kubernetes.io/enforce=restricted", "pod-security.kubernetes.io/enforce-version=v1.24"]
82 nodeSelector: {kubernetes.io/os: linux}
85 allowPrivilegeEscalation: false
89 readOnlyRootFilesystem: true
96 name: gatekeeper-update-namespace-label
101 repository: cgr.dev/chainguard-private/gatekeeper-crds-fips
102 tag: latest@sha256:851b60969315e4bd2d225fa3a33bc3659f7a1b790878367f9bc56c47e21a6510
103 pullPolicy: IfNotPresent
106 podSecurity: ["pod-security.kubernetes.io/audit=restricted", "pod-security.kubernetes.io/audit-version=latest", "pod-security.kubernetes.io/warn=restricted", "pod-security.kubernetes.io/warn-version=latest", "pod-security.kubernetes.io/enforce=restricted", "pod-security.kubernetes.io/enforce-version=v1.24"]
108 priorityClassName: ""
112 repository: cgr.dev/chainguard-private/curl-fips
113 tag: latest@sha256:fe306db47ff8e878f601e78b245c4ae03f399d730f9651b5b6cef5e3ab2a20cc
114 pullPolicy: IfNotPresent
119 priorityClassName: ""
122 nodeSelector: {kubernetes.io/os: linux}
124 allowPrivilegeEscalation: false
128 readOnlyRootFilesystem: true
133 deleteWebhookConfigurations:
135 name: gatekeeper-delete-webhook-configs
140 repository: cgr.dev/chainguard-private/gatekeeper-crds-fips
141 tag: latest@sha256:851b60969315e4bd2d225fa3a33bc3659f7a1b790878367f9bc56c47e21a6510
142 pullPolicy: IfNotPresent
144 priorityClassName: ""
147 nodeSelector: {kubernetes.io/os: linux}
150 allowPrivilegeEscalation: false
154 readOnlyRootFilesystem: true
159auditPodAnnotations: {}
163enableRuntimeDefaultSeccompProfile: true
166 name: gatekeeper-admin
167 automountServiceAccountToken: true
168 containerName: manager
170 exemptNamespacePrefixes: []
172 dnsPolicy: ClusterFirst
178 priorityClassName: system-cluster-critical
179 disableCertRotation: false
182 strategyType: RollingUpdate
183 strategyRollingUpdate: {}
187 preferredDuringSchedulingIgnoredDuringExecution:
191 - key: gatekeeper.sh/operation
195 topologyKey: kubernetes.io/hostname
197 topologySpreadConstraints: []
199 nodeSelector: {kubernetes.io/os: linux}
207 allowPrivilegeEscalation: false
211 readOnlyRootFilesystem: true
226 disableWebhookOperation: false
227 disableGenerateOperation: true
231 path: /tmp/violations/topics
234 path: /tmp/violations
240 image: cgr.dev/chainguard-private/open-policy-agent-fake-reader-fips:latest@sha256:2bcf0e577a21a83107025a12dedd7d94fb61c609912edc2d38078e602c5289b7
241 imagePullPolicy: Always
243 allowPrivilegeEscalation: false
247 readOnlyRootFilesystem: true
254 - mountPath: /tmp/violations
257 name: gatekeeper-admin
258 automountServiceAccountToken: true
259 containerName: manager
261 dnsPolicy: ClusterFirst
266 priorityClassName: system-cluster-critical
267 disableCertRotation: false
271 nodeSelector: {kubernetes.io/os: linux}
279 allowPrivilegeEscalation: false
283 readOnlyRootFilesystem: true
291 writeToRAMDisk: false
293 disableGenerateOperation: false
294 disableAuditOperation: false
295 disableAuditSidecar: false
296 disableStatusOperation: false
300 nodeSelector: {kubernetes.io/os: linux}
303 allowPrivilegeEscalation: false
307 readOnlyRootFilesystem: true
315disabledBuiltins: ["{http.send}"]
319 name: gatekeeper-admin-upgrade-crds
322 priorityClassName: ""
325externalCertInjection:
327 secretName: gatekeeper-webhook-server-cert