Skip to content

Instantly share code, notes, and snippets.

@bharatmicrosystems
Created October 30, 2020 08:22
Show Gist options
  • Save bharatmicrosystems/cc15a1d5c2a98573bca439d661aafc0d to your computer and use it in GitHub Desktop.
Save bharatmicrosystems/cc15a1d5c2a98573bca439d661aafc0d to your computer and use it in GitHub Desktop.
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: "default"
spec:
rules:
- name: "default-deny"
match:
resources:
kinds:
- Namespace
name: "*"
exclude:
namespaces:
- "kube-system"
- "default"
- "kube-public"
- "kyverno"
generate:
kind: NetworkPolicy
name: default-deny-all-traffic
namespace: "{{request.object.metadata.namespace}}"
data:
spec:
podSelector: {}
policyTypes:
- Ingress
- Egress
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment