mirror of
https://github.com/kata-containers/kata-containers.git
synced 2026-07-02 07:02:16 +00:00
policy: add missin default policy rules
Add default-deny entries for MemAgentMemcgConfig and MemAgentCompactConfig to rules.rego, and the corresponding allow entries to the two reference OPA policies (allow-all.rego and allow-all-except-exec-process.rego). Generated-By: IBM Bob Signed-off-by: stevenhorsman <steven@uk.ibm.com>
This commit is contained in:
@@ -17,6 +17,8 @@ default GetOOMEventRequest := true
|
||||
default GuestDetailsRequest := true
|
||||
default ListInterfacesRequest := true
|
||||
default ListRoutesRequest := true
|
||||
default MemAgentCompactConfig := true
|
||||
default MemAgentMemcgConfig := true
|
||||
default MemHotplugByProbeRequest := true
|
||||
default OnlineCPUMemRequest := true
|
||||
default PauseContainerRequest := true
|
||||
|
||||
@@ -19,6 +19,8 @@ default GetOOMEventRequest := true
|
||||
default GuestDetailsRequest := true
|
||||
default ListInterfacesRequest := true
|
||||
default ListRoutesRequest := true
|
||||
default MemAgentCompactConfig := true
|
||||
default MemAgentMemcgConfig := true
|
||||
default MemHotplugByProbeRequest := true
|
||||
default OnlineCPUMemRequest := true
|
||||
default PauseContainerRequest := true
|
||||
|
||||
@@ -25,6 +25,8 @@ default GetOOMEventRequest := true
|
||||
default GuestDetailsRequest := true
|
||||
default ListInterfacesRequest := false
|
||||
default ListRoutesRequest := false
|
||||
default MemAgentCompactConfig := false
|
||||
default MemAgentMemcgConfig := false
|
||||
default MemHotplugByProbeRequest := false
|
||||
default OnlineCPUMemRequest := true
|
||||
default PauseContainerRequest := false
|
||||
|
||||
Reference in New Issue
Block a user