diff --git a/staging/src/k8s.io/pod-security-admission/webhook/manifests/20-resourcequota.yaml b/staging/src/k8s.io/pod-security-admission/webhook/manifests/20-resourcequota.yaml new file mode 100644 index 00000000000..0c90bd22bda --- /dev/null +++ b/staging/src/k8s.io/pod-security-admission/webhook/manifests/20-resourcequota.yaml @@ -0,0 +1,14 @@ +apiVersion: v1 +kind: ResourceQuota +metadata: + name: pod-security-webhook + namespace: pod-security-webhook +spec: + hard: + pods: 3 + scopeSelector: + matchExpressions: + - operator: In + scopeName: PriorityClass + values: + - system-cluster-critical \ No newline at end of file diff --git a/staging/src/k8s.io/pod-security-admission/webhook/manifests/kustomization.yaml b/staging/src/k8s.io/pod-security-admission/webhook/manifests/kustomization.yaml index f637494436e..8320af4a6d1 100644 --- a/staging/src/k8s.io/pod-security-admission/webhook/manifests/kustomization.yaml +++ b/staging/src/k8s.io/pod-security-admission/webhook/manifests/kustomization.yaml @@ -2,6 +2,7 @@ resources: - 10-namespace.yaml - 20-configmap.yaml - 20-serviceaccount.yaml +- 20-resourcequota.yaml - 30-clusterrole.yaml - 40-clusterrolebinding.yaml - 50-deployment.yaml