d0b3c26223
Adds three policy files under policy/ plus a pre-commit hook that
runs conftest against all staged YAML manifests (excluding chart
templates).
Policies:
no_ingress.rego
Deny Ingress resources — cluster uses Gateway API only.
gateway_api.rego
HTTPRoute/TLSRoute: require explicit group/kind on parentRefs and
group/kind/weight on backendRefs (PR #162, #165).
Gateway: require explicit group on certificateRefs (PR #153).
All fields are defaulted by the controller; omitting them causes
permanent ArgoCD OutOfSync.
resource_normalization.rego
CPU integer: deny unquoted integer cpu values (PR #163).
CPU milliCPU: deny values like 1000m/2000m that normalise to "1"/"2" (PR #164).
Memory Mi→Gi: deny 1024Mi/2048Mi etc. that normalise to 1Gi/2Gi (PR #163).
clusterIP null: deny Service with explicit null clusterIP (PR #166).
Also fixes all existing violations found by the new policies across
puppet deployments and reposync cronjobs (resource normalization).
kanidm/tlsroute.yaml and puppet/service_puppetdb.yaml are excluded
from this commit as they are addressed in PRs #165 and #166.
14 lines
406 B
Rego
14 lines
406 B
Rego
package main
|
|
|
|
# Deny all Kubernetes Ingress resources.
|
|
# This cluster uses Gateway API (HTTPRoute + Gateway) for ingress routing.
|
|
# Ingress is the legacy API and must not be added.
|
|
|
|
deny contains msg if {
|
|
input.kind == "Ingress"
|
|
msg := sprintf(
|
|
"%s/%s: Ingress resources are forbidden — use Gateway API HTTPRoute instead",
|
|
[input.metadata.namespace, input.metadata.name],
|
|
)
|
|
}
|