policy-api

command module
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: Apache-2.0 Imports: 13 Imported by: 0

README

Policy API

PolicyException status

kyverno-policy-operator writes the status of a PolicyException (gspolex):

  • observedGeneration: the metadata.generation the status describes.
  • conditions:
    • Ready: whether every Kyverno PolicyException generated for it is applied, stale ones are removed, and every target is translated. It does not check that the listed policies exist; see PoliciesResolved (the Policies column). Reasons: Reconciled, InvalidNamespace, NameTaken, LookupFailed, ApplyFailed, DeleteFailed (stale generated exceptions could not be removed), UnsupportedKind. When several checks fail, Ready takes the first failing reason in that order, and its message lists all of them.
    • PoliciesResolved: whether every listed policy matches a CEL policy. It is informational and does not affect Ready, so health checks on Ready (Flux wait, kstatus) are not blocked by policies still being migrated. Reasons:
      • Resolved: every listed policy matches a CEL policy.
      • NotMigrated: a listed policy matches only a legacy ClusterPolicy. The legacy exception covers it, and the CEL exception takes over once the policy is migrated. This is expected during the migration.
      • PolicyNotFound: a listed policy matches no policy at all, for example a typo, a removed policy, or a policy not installed yet. It wins over NotMigrated, and the message names the policies for each.
    • TargetsTranslated: whether every target can be expressed in a CEL exception. Reasons: Translated, UnsupportedKind.
  • generatedExceptions: the apiVersion, namespace and name of each Kyverno PolicyException generated for it.
  • unresolvedPolicies: listed policies that match no CEL policy, whether they match only a legacy ClusterPolicy or no policy at all.
  • unsupportedTargetKinds: target kinds left out of the CEL exception, such as Pod/exec.

kubectl get gspolex shows the Ready condition's status and reason, and the PoliciesResolved condition's status as Policies.

Documentation

Overview

Package main provides the entry point for the policy-api controller

Directories

Path Synopsis
api
v1alpha1
Package v1alpha1 contains API Schema definitions for the policy v1alpha1 API group +kubebuilder:object:generate=true +groupName=policy.giantswarm.io
Package v1alpha1 contains API Schema definitions for the policy v1alpha1 API group +kubebuilder:object:generate=true +groupName=policy.giantswarm.io
cmd
modelschema command
Package main provides the entry point for the policy-api controller
Package main provides the entry point for the policy-api controller
pkg
client/clientset/versioned/fake
This package has the automatically generated fake clientset.
This package has the automatically generated fake clientset.
client/clientset/versioned/scheme
This package contains the scheme of the automatically generated clientset.
This package contains the scheme of the automatically generated clientset.
client/clientset/versioned/typed/core/v1alpha1
This package has the automatically generated typed clients.
This package has the automatically generated typed clients.
client/clientset/versioned/typed/core/v1alpha1/fake
Package fake has the automatically generated clients.
Package fake has the automatically generated clients.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL