diff --git a/staging/src/k8s.io/pod-security-admission/policy/check_dropCapabilities.go b/staging/src/k8s.io/pod-security-admission/policy/check_capabilities_restricted.go similarity index 87% rename from staging/src/k8s.io/pod-security-admission/policy/check_dropCapabilities.go rename to staging/src/k8s.io/pod-security-admission/policy/check_capabilities_restricted.go index 894cd86b4e5..383e662db7e 100644 --- a/staging/src/k8s.io/pod-security-admission/policy/check_dropCapabilities.go +++ b/staging/src/k8s.io/pod-security-admission/policy/check_capabilities_restricted.go @@ -33,25 +33,25 @@ const ( ) func init() { - addCheck(CheckDropCapabilities) + addCheck(CheckCapabilitiesRestricted) } -// CheckDropCapabilities returns a restricted level check -// that ensures all capabilities are dropped in 1.22+ -func CheckDropCapabilities() Check { +// CheckCapabilitiesRestricted returns a restricted level check +// that ensures ALL capabilities are dropped in 1.22+ +func CheckCapabilitiesRestricted() Check { return Check{ - ID: "dropCapabilities", + ID: "capabilities_restricted", Level: api.LevelRestricted, Versions: []VersionedCheck{ { MinimumVersion: api.MajorMinorVersion(1, 22), - CheckPod: dropCapabilities_1_22, + CheckPod: capabilitiesRestricted_1_22, }, }, } } -func dropCapabilities_1_22(podMetadata *metav1.ObjectMeta, podSpec *corev1.PodSpec) CheckResult { +func capabilitiesRestricted_1_22(podMetadata *metav1.ObjectMeta, podSpec *corev1.PodSpec) CheckResult { var ( containersMissingDropAll []string containersAddingForbidden []string diff --git a/staging/src/k8s.io/pod-security-admission/test/fixtures_dropCapabilities.go b/staging/src/k8s.io/pod-security-admission/test/fixtures_capabilities_restricted.go similarity index 98% rename from staging/src/k8s.io/pod-security-admission/test/fixtures_dropCapabilities.go rename to staging/src/k8s.io/pod-security-admission/test/fixtures_capabilities_restricted.go index e2e791b21f3..3cca372d851 100644 --- a/staging/src/k8s.io/pod-security-admission/test/fixtures_dropCapabilities.go +++ b/staging/src/k8s.io/pod-security-admission/test/fixtures_capabilities_restricted.go @@ -90,7 +90,7 @@ func init() { } registerFixtureGenerator( - fixtureKey{level: api.LevelRestricted, version: api.MajorMinorVersion(1, 22), check: "dropCapabilities"}, + fixtureKey{level: api.LevelRestricted, version: api.MajorMinorVersion(1, 22), check: "capabilities_restricted"}, fixtureData_1_22, ) }