Extra SPO Smoke Policy
The example policy is:
examples/policy-spo-selinux-smoke-extra.yaml
It is not deployed by default.
Enable the Example
Copy it into the active base:
cp examples/policy-spo-selinux-smoke-extra.yaml policies/base/
Add it to policies/base/kustomization.yaml:
resources:
- policy-blastwall-v2-profile-usage.yaml
- policy-blastwall-v2-raw-profiles.yaml
- policy-blastwall-v2-runtime-bindings.yaml
- policy-install-spo-operator.yaml
- policy-prevent-copy-fail-cve-ds.yaml
- policy-spo-selinux-smoke-extra.yaml
- policyset-blastwall.yaml
- policyset-spo.yaml
Add it to policies/base/policyset-spo.yaml:
spec:
policies:
- policy-install-spo-operator
- policy-prevent-copy-fail-cve-ds
- policy-spo-selinux-smoke-extra
Validate:
validation/validate-render.sh policies/overlays/test-spo-cluster-scoped
Push the change when the render passes.