Skip to main content

Extra SPO Smoke Policy

The example policy is:

examples/policy-spo-selinux-smoke-extra.yaml

It is not deployed by default.

Enable the Example​

Copy it into the active base:

cp examples/policy-spo-selinux-smoke-extra.yaml policies/base/

Add it to policies/base/kustomization.yaml:

resources:
- policy-blastwall-v2-profile-usage.yaml
- policy-blastwall-v2-raw-profiles.yaml
- policy-blastwall-v2-runtime-bindings.yaml
- policy-install-spo-operator.yaml
- policy-prevent-copy-fail-cve-ds.yaml
- policy-spo-selinux-smoke-extra.yaml
- policyset-blastwall.yaml
- policyset-spo.yaml

Add it to policies/base/policyset-spo.yaml:

spec:
policies:
- policy-install-spo-operator
- policy-prevent-copy-fail-cve-ds
- policy-spo-selinux-smoke-extra

Validate:

validation/validate-render.sh policies/overlays/test-spo-cluster-scoped

Push the change when the render passes.