Skip to content

ACS runtime custom policies update#116

Merged
minmzzhang merged 3 commits into
validatedpatterns:mainfrom
p-rog:acs-runtime-custom-policies-update
Apr 1, 2026
Merged

ACS runtime custom policies update#116
minmzzhang merged 3 commits into
validatedpatterns:mainfrom
p-rog:acs-runtime-custom-policies-update

Conversation

@p-rog
Copy link
Copy Markdown
Collaborator

@p-rog p-rog commented Apr 1, 2026

I've updated the ACS runtime policies to targeted approach, where in scope there is only our test qtodo application namespace. These custom policies are not global like before.

Additionally I found one more issue with ACS normalization SecurityPolicy resources after ArgoCD creates them. I fixed it as well. It's already tested in a fresh cluster.

Ready for review and merge.

Przemyslaw Roguski added 2 commits April 1, 2026 21:41
…them. It strips all zero-value booleans from the spec which can lead to OutOfSync status in ArgoCD.
Copy link
Copy Markdown
Collaborator

@minmzzhang minmzzhang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm other than the suspicious execute command list, shall we review again that part?

Comment thread charts/acs-policies/templates/stop-suspicious-exec.yaml Outdated
…sed too broadly in many system components or init scripts
Copy link
Copy Markdown
Collaborator

@minmzzhang minmzzhang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm!

@minmzzhang minmzzhang merged commit 0ee2b13 into validatedpatterns:main Apr 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants