diff --git a/karpenter/add-karpenter-daemonset-priority-class/kyverno-test.yaml b/karpenter/add-karpenter-daemonset-priority-class/kyverno-test.yaml index 0c324ae39..2fa368a49 100644 --- a/karpenter/add-karpenter-daemonset-priority-class/kyverno-test.yaml +++ b/karpenter/add-karpenter-daemonset-priority-class/kyverno-test.yaml @@ -9,8 +9,8 @@ resources: results: - kind: DaemonSet patchedResource: daemonset-patched.yaml - policy: test/add-karpenter-daemonset-priority-class + policy: add-karpenter-daemonset-priority-class resources: - - test + - test/test result: pass rule: add-karpenter-daemonset-priority-class diff --git a/karpenter/set-karpenter-non-cpu-limits/kyverno-test.yaml b/karpenter/set-karpenter-non-cpu-limits/kyverno-test.yaml index 8a4b4c55a..ea9df80b3 100644 --- a/karpenter/set-karpenter-non-cpu-limits/kyverno-test.yaml +++ b/karpenter/set-karpenter-non-cpu-limits/kyverno-test.yaml @@ -9,57 +9,57 @@ resources: results: - kind: Pod patchedResource: pod-ephemeral-storage-patched1.yaml - policy: test/set-karpenter-non-cpu-limits + policy: set-karpenter-non-cpu-limits resources: - - test1 + - test/test1 result: pass rule: set-ephemeral-storage - kind: Pod patchedResource: pod-ephemeral-storage-patched2.yaml - policy: test/set-karpenter-non-cpu-limits + policy: set-karpenter-non-cpu-limits resources: - - test2 + - test/test2 result: pass rule: set-ephemeral-storage - kind: Pod patchedResource: pod-ephemeral-storage-patched3.yaml - policy: test/set-karpenter-non-cpu-limits + policy: set-karpenter-non-cpu-limits resources: - - test3 + - test/test3 result: pass rule: set-ephemeral-storage - kind: Pod patchedResource: pod-ephemeral-storage-patched4.yaml - policy: test/set-karpenter-non-cpu-limits + policy: set-karpenter-non-cpu-limits resources: - - test4 + - test/test4 result: pass rule: set-ephemeral-storage - kind: Pod patchedResource: pod-memory-patched1.yaml - policy: test/set-karpenter-non-cpu-limits + policy: set-karpenter-non-cpu-limits resources: - - test1 + - test/test1 result: pass rule: set-memory - kind: Pod patchedResource: pod-memory-patched2.yaml - policy: test/set-karpenter-non-cpu-limits + policy: set-karpenter-non-cpu-limits resources: - - test2 + - test/test2 result: pass rule: set-memory - kind: Pod patchedResource: pod-memory-patched3.yaml - policy: test/set-karpenter-non-cpu-limits + policy: set-karpenter-non-cpu-limits resources: - - test3 + - test/test3 result: pass rule: set-memory - kind: Pod patchedResource: pod-memory-patched4.yaml - policy: test/set-karpenter-non-cpu-limits + policy: set-karpenter-non-cpu-limits resources: - - test4 + - test/test4 result: skip rule: set-memory diff --git a/other/a/add-labels/kyverno-test.yaml b/other/a/add-labels/kyverno-test.yaml index 05fcd30fb..9b5cc1b7f 100644 --- a/other/a/add-labels/kyverno-test.yaml +++ b/other/a/add-labels/kyverno-test.yaml @@ -9,15 +9,15 @@ resources: results: - kind: Pod patchedResource: patchedResource.yaml - policy: default/add-labels + policy: add-labels resources: - - myapp-pod + - default/myapp-pod result: pass rule: add-labels - kind: Service patchedResource: patchedResource1.yaml - policy: default/add-labels + policy: add-labels resources: - - my-service + - default/my-service result: pass rule: add-labels diff --git a/other/a/add-ndots/kyverno-test.yaml b/other/a/add-ndots/kyverno-test.yaml index 51266cb92..b118c9b82 100644 --- a/other/a/add-ndots/kyverno-test.yaml +++ b/other/a/add-ndots/kyverno-test.yaml @@ -9,8 +9,8 @@ resources: results: - kind: Pod patchedResource: patchedResource.yaml - policy: default/add-ndots + policy: add-ndots resources: - - myapp-pod + - default/myapp-pod result: pass rule: add-ndots diff --git a/other/a/add-nodeSelector/kyverno-test.yaml b/other/a/add-nodeSelector/kyverno-test.yaml index 45e90d4a4..e1fd36df6 100644 --- a/other/a/add-nodeSelector/kyverno-test.yaml +++ b/other/a/add-nodeSelector/kyverno-test.yaml @@ -9,8 +9,8 @@ resources: results: - kind: Pod patchedResource: patchedResource.yaml - policy: default/add-nodeselector + policy: add-nodeselector resources: - - myapp-pod + - default/myapp-pod result: pass rule: add-nodeselector diff --git a/other/a/add-pod-priorityclassname/kyverno-test.yaml b/other/a/add-pod-priorityclassname/kyverno-test.yaml index c61ddbd85..03947e356 100644 --- a/other/a/add-pod-priorityclassname/kyverno-test.yaml +++ b/other/a/add-pod-priorityclassname/kyverno-test.yaml @@ -9,9 +9,9 @@ resources: results: - kind: Pod patchedResource: patchedResource.yaml - policy: foo/add-pod-priorityclassname + policy: add-pod-priorityclassname resources: - - blank + - foo/blank result: pass rule: add-priorityclass-pods variables: values.yaml diff --git a/other/b-d/create-default-pdb/kyverno-test.yaml b/other/b-d/create-default-pdb/kyverno-test.yaml index aeea8301f..0c6746c24 100644 --- a/other/b-d/create-default-pdb/kyverno-test.yaml +++ b/other/b-d/create-default-pdb/kyverno-test.yaml @@ -9,8 +9,8 @@ resources: results: - generatedResource: generatedResource.yaml kind: Deployment - policy: hello-world/create-default-pdb + policy: create-default-pdb resources: - - nginx-deployment + - hello-world/nginx-deployment result: pass rule: create-default-pdb diff --git a/other/b-d/disallow-all-secrets/kyverno-test.yaml b/other/b-d/disallow-all-secrets/kyverno-test.yaml index 45fb20dad..696f2d92b 100644 --- a/other/b-d/disallow-all-secrets/kyverno-test.yaml +++ b/other/b-d/disallow-all-secrets/kyverno-test.yaml @@ -8,41 +8,41 @@ resources: - resource.yaml results: - kind: Pod - policy: default/no-secrets + policy: no-secrets resources: - - secret-env-pod + - default/secret-env-pod result: fail rule: secrets-not-from-env - kind: Pod - policy: default/no-secrets + policy: no-secrets resources: - - secret-ref-pod - - secret-vol-pod + - default/secret-ref-pod + - default/secret-vol-pod result: pass rule: secrets-not-from-env - kind: Pod - policy: default/no-secrets + policy: no-secrets resources: - - secret-ref-pod + - default/secret-ref-pod result: fail rule: secrets-not-from-envfrom - kind: Pod - policy: default/no-secrets + policy: no-secrets resources: - - secret-env-pod - - secret-vol-pod + - default/secret-env-pod + - default/secret-vol-pod result: pass rule: secrets-not-from-envfrom - kind: Pod - policy: default/no-secrets + policy: no-secrets resources: - - secret-vol-pod + - default/secret-vol-pod result: fail rule: secrets-not-from-volumes - kind: Pod - policy: default/no-secrets + policy: no-secrets resources: - - secret-env-pod - - secret-ref-pod + - default/secret-env-pod + - default/secret-ref-pod result: pass rule: secrets-not-from-volumes diff --git a/other/b-d/disallow-secrets-from-env-vars/kyverno-test.yaml b/other/b-d/disallow-secrets-from-env-vars/kyverno-test.yaml index 0a898c045..d100ddf4f 100644 --- a/other/b-d/disallow-secrets-from-env-vars/kyverno-test.yaml +++ b/other/b-d/disallow-secrets-from-env-vars/kyverno-test.yaml @@ -8,26 +8,26 @@ resources: - resource.yaml results: - kind: Pod - policy: default/secrets-not-from-env-vars + policy: secrets-not-from-env-vars resources: - - secret-env-pod + - default/secret-env-pod result: fail rule: secrets-not-from-env-vars - kind: Pod - policy: default/secrets-not-from-env-vars + policy: secrets-not-from-env-vars resources: - - secret-ref-pod + - default/secret-ref-pod result: pass rule: secrets-not-from-env-vars - kind: Pod - policy: default/secrets-not-from-env-vars + policy: secrets-not-from-env-vars resources: - - secret-ref-pod + - default/secret-ref-pod result: fail rule: secrets-not-from-envfrom - kind: Pod - policy: default/secrets-not-from-env-vars + policy: secrets-not-from-env-vars resources: - - secret-env-pod + - default/secret-env-pod result: pass rule: secrets-not-from-envfrom diff --git a/other/b-d/dns-policy-and-dns-config/kyverno-test.yaml b/other/b-d/dns-policy-and-dns-config/kyverno-test.yaml index 430bc5a39..121e1cac6 100644 --- a/other/b-d/dns-policy-and-dns-config/kyverno-test.yaml +++ b/other/b-d/dns-policy-and-dns-config/kyverno-test.yaml @@ -9,9 +9,9 @@ resources: results: - kind: Pod patchedResource: patchedResource.yaml - policy: default/change-dns-config-policy + policy: change-dns-config-policy resources: - - myapp-pod + - default/myapp-pod result: pass rule: dns-policy variables: variables.yaml diff --git a/other/m-q/pdb-maxunavailable/kyverno-test.yaml b/other/m-q/pdb-maxunavailable/kyverno-test.yaml index 29194873c..cfe58a057 100644 --- a/other/m-q/pdb-maxunavailable/kyverno-test.yaml +++ b/other/m-q/pdb-maxunavailable/kyverno-test.yaml @@ -8,16 +8,16 @@ resources: - resource.yaml results: - kind: PodDisruptionBudget - policy: kube-system/pdb-maxunavailable + policy: pdb-maxunavailable resources: - - bad-pdb-zero - - bad-pdb-negative-one + - kube-system/bad-pdb-zero + - kube-system/bad-pdb-negative-one result: fail rule: pdb-maxunavailable - kind: PodDisruptionBudget - policy: kube-system/pdb-maxunavailable + policy: pdb-maxunavailable resources: - - good-pdb - - good-pdb-none + - kube-system/good-pdb + - kube-system/good-pdb-none result: pass rule: pdb-maxunavailable diff --git a/other/m-q/pdb-minavailable/kyverno-test.yaml b/other/m-q/pdb-minavailable/kyverno-test.yaml index 1d468fe07..21ec21be3 100644 --- a/other/m-q/pdb-minavailable/kyverno-test.yaml +++ b/other/m-q/pdb-minavailable/kyverno-test.yaml @@ -8,15 +8,15 @@ resources: - resource.yaml results: - kind: StatefulSet - policy: nginx/pdb-minavailable-check + policy: pdb-minavailable-check resources: - - bad-pdb + - nginx/bad-pdb result: fail rule: pdb-minavailable - kind: StatefulSet - policy: nginx/pdb-minavailable-check + policy: pdb-minavailable-check resources: - - good-pdb + - nginx/good-pdb result: pass rule: pdb-minavailable variables: values.yaml diff --git a/other/res/restrict-controlplane-scheduling/kyverno-test.yaml b/other/res/restrict-controlplane-scheduling/kyverno-test.yaml index c451b8f48..9584ef189 100644 --- a/other/res/restrict-controlplane-scheduling/kyverno-test.yaml +++ b/other/res/restrict-controlplane-scheduling/kyverno-test.yaml @@ -8,26 +8,26 @@ resources: - resource.yaml results: - kind: Pod - policy: default/restrict-controlplane-scheduling + policy: restrict-controlplane-scheduling resources: - - myapp-pod-2 + - default/myapp-pod-2 result: fail rule: restrict-controlplane-scheduling-control-plane - kind: Pod - policy: default/restrict-controlplane-scheduling + policy: restrict-controlplane-scheduling resources: - - myapp-pod-1 + - default/myapp-pod-1 result: pass rule: restrict-controlplane-scheduling-control-plane - kind: Pod - policy: default/restrict-controlplane-scheduling + policy: restrict-controlplane-scheduling resources: - - myapp-pod-1 + - default/myapp-pod-1 result: fail rule: restrict-controlplane-scheduling-master - kind: Pod - policy: default/restrict-controlplane-scheduling + policy: restrict-controlplane-scheduling resources: - - myapp-pod-2 + - default/myapp-pod-2 result: pass rule: restrict-controlplane-scheduling-master diff --git a/other/res/restrict-deprecated-registry/kyverno-test.yaml b/other/res/restrict-deprecated-registry/kyverno-test.yaml index 23658a43d..f55b98da5 100644 --- a/other/res/restrict-deprecated-registry/kyverno-test.yaml +++ b/other/res/restrict-deprecated-registry/kyverno-test.yaml @@ -8,14 +8,14 @@ resources: - resource.yaml results: - kind: Pod - policy: policy-test/restrict-deprecated-registry + policy: restrict-deprecated-registry resources: - - test-pod-bad + - policy-test/test-pod-bad result: fail rule: restrict-deprecated-registry - kind: Pod - policy: policy-test/restrict-deprecated-registry + policy: restrict-deprecated-registry resources: - - test-pod-good + - policy-test/test-pod-good result: pass rule: restrict-deprecated-registry diff --git a/other/res/restrict-ingress-classes/kyverno-test.yaml b/other/res/restrict-ingress-classes/kyverno-test.yaml index 319a73489..882e40d88 100644 --- a/other/res/restrict-ingress-classes/kyverno-test.yaml +++ b/other/res/restrict-ingress-classes/kyverno-test.yaml @@ -8,14 +8,14 @@ resources: - resource.yaml results: - kind: Ingress - policy: default/restrict-ingress-classes + policy: restrict-ingress-classes resources: - - minimal-ingress-2 + - default/minimal-ingress-2 result: fail rule: validate-ingress - kind: Ingress - policy: default/restrict-ingress-classes + policy: restrict-ingress-classes resources: - - minimal-ingress-1 + - default/minimal-ingress-1 result: pass rule: validate-ingress diff --git a/other/res/restrict-ingress-defaultbackend/kyverno-test.yaml b/other/res/restrict-ingress-defaultbackend/kyverno-test.yaml index c9f068056..03c1dcafd 100644 --- a/other/res/restrict-ingress-defaultbackend/kyverno-test.yaml +++ b/other/res/restrict-ingress-defaultbackend/kyverno-test.yaml @@ -8,14 +8,14 @@ resources: - resource.yaml results: - kind: Ingress - policy: default/restrict-ingress-defaultbackend + policy: restrict-ingress-defaultbackend resources: - - sample-app-1 + - default/sample-app-1 result: fail rule: restrict-ingress-defaultbackend - kind: Ingress - policy: default/restrict-ingress-defaultbackend + policy: restrict-ingress-defaultbackend resources: - - sample-app-2 + - default/sample-app-2 result: pass rule: restrict-ingress-defaultbackend diff --git a/other/res/restrict-loadbalancer/kyverno-test.yaml b/other/res/restrict-loadbalancer/kyverno-test.yaml index 4ca8b9f79..13a7ea63f 100644 --- a/other/res/restrict-loadbalancer/kyverno-test.yaml +++ b/other/res/restrict-loadbalancer/kyverno-test.yaml @@ -8,14 +8,14 @@ resources: - resource.yaml results: - kind: Service - policy: default/no-loadbalancer-service + policy: no-loadbalancer-service resources: - - my-service-1 + - default/my-service-1 result: fail rule: no-LoadBalancer - kind: Service - policy: default/no-loadbalancer-service + policy: no-loadbalancer-service resources: - - my-service-2 + - default/my-service-2 result: pass rule: no-LoadBalancer diff --git a/other/res/restrict-node-selection/kyverno-test.yaml b/other/res/restrict-node-selection/kyverno-test.yaml index d3696508c..089014b65 100644 --- a/other/res/restrict-node-selection/kyverno-test.yaml +++ b/other/res/restrict-node-selection/kyverno-test.yaml @@ -8,26 +8,26 @@ resources: - resource.yaml results: - kind: Pod - policy: default/restrict-node-selection + policy: restrict-node-selection resources: - - myapp-pod-2 + - default/myapp-pod-2 result: fail rule: restrict-nodename - kind: Pod - policy: default/restrict-node-selection + policy: restrict-node-selection resources: - - myapp-pod-1 + - default/myapp-pod-1 result: pass rule: restrict-nodename - kind: Pod - policy: default/restrict-node-selection + policy: restrict-node-selection resources: - - myapp-pod-1 + - default/myapp-pod-1 result: fail rule: restrict-nodeselector - kind: Pod - policy: default/restrict-node-selection + policy: restrict-node-selection resources: - - myapp-pod-2 + - default/myapp-pod-2 result: pass rule: restrict-nodeselector diff --git a/other/res/restrict-usergroup-fsgroup-id/kyverno-test.yaml b/other/res/restrict-usergroup-fsgroup-id/kyverno-test.yaml index 6303a6082..a00641459 100644 --- a/other/res/restrict-usergroup-fsgroup-id/kyverno-test.yaml +++ b/other/res/restrict-usergroup-fsgroup-id/kyverno-test.yaml @@ -8,20 +8,20 @@ resources: - resource.yaml results: - kind: Pod - policy: default/validate-userid-groupid-fsgroup + policy: validate-userid-groupid-fsgroup resources: - - myapp-pod + - default/myapp-pod result: pass rule: validate-fsgroup - kind: Pod - policy: default/validate-userid-groupid-fsgroup + policy: validate-userid-groupid-fsgroup resources: - - myapp-pod + - default/myapp-pod result: pass rule: validate-groupid - kind: Pod - policy: default/validate-userid-groupid-fsgroup + policy: validate-userid-groupid-fsgroup resources: - - myapp-pod + - default/myapp-pod result: pass rule: validate-userid diff --git a/other/s-z/topologyspreadconstraints-policy/kyverno-test.yaml b/other/s-z/topologyspreadconstraints-policy/kyverno-test.yaml index 018c3f21b..c663237d2 100644 --- a/other/s-z/topologyspreadconstraints-policy/kyverno-test.yaml +++ b/other/s-z/topologyspreadconstraints-policy/kyverno-test.yaml @@ -12,22 +12,22 @@ resources: - resource-skip.yaml results: - kind: StatefulSet - policy: monitoring/topologyspreadconstraints-policy + policy: topologyspreadconstraints-policy resources: - - fail1 - - fail2 - - fail3 + - monitoring/fail1 + - monitoring/fail2 + - monitoring/fail3 result: fail rule: spread-pods - kind: StatefulSet - policy: monitoring/topologyspreadconstraints-policy + policy: topologyspreadconstraints-policy resources: - - pass + - monitoring/pass result: pass rule: spread-pods - kind: StatefulSet - policy: monitoring/topologyspreadconstraints-policy + policy: topologyspreadconstraints-policy resources: - - skip + - monitoring/skip result: skip rule: spread-pods