Skip to content

Commit 1390e6b

Browse files
committed
Add a ValidatingAdmissionPolicy blocking v1.multus-cni.io/default-network updates
It is not allowed to modify the v1.multus-cni.io/default-network once the pod was created. The added ValidatingAdmissionPolicy applies to environments with PreconfiguredUDNAddresses featuregate enabled. Signed-off-by: Patryk Diak <[email protected]>
1 parent 6fa9546 commit 1390e6b

File tree

1 file changed

+31
-0
lines changed

1 file changed

+31
-0
lines changed
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{{if .OVN_PRE_CONF_UDN_ADDR_ENABLE}}
2+
apiVersion: admissionregistration.k8s.io/v1
3+
kind: ValidatingAdmissionPolicy
4+
metadata:
5+
name: default-network-annotation
6+
spec:
7+
matchConstraints:
8+
resourceRules:
9+
- apiGroups: [""]
10+
apiVersions: ["v1"]
11+
operations: ["UPDATE"]
12+
resources: ["pods"]
13+
failurePolicy: Fail
14+
validations:
15+
- expression: "('v1.multus-cni.io/default-network' in oldObject.metadata.annotations) == ('v1.multus-cni.io/default-network' in object.metadata.annotations)"
16+
message: "The 'v1.multus-cni.io/default-network' annotation cannot be changed after the pod was created"
17+
---
18+
apiVersion: admissionregistration.k8s.io/v1
19+
kind: ValidatingAdmissionPolicyBinding
20+
metadata:
21+
name: default-network-annotation-binding
22+
spec:
23+
policyName: default-network-annotation
24+
validationActions: [Deny]
25+
matchResources:
26+
resourceRules:
27+
- apiGroups: [""]
28+
apiVersions: ["v1"]
29+
operations: ["UPDATE"]
30+
resources: ["pods"]
31+
{{end}}

0 commit comments

Comments
 (0)