-
Task
-
Resolution: Done
-
Undefined
-
None
-
None
-
None
-
3
-
False
-
None
-
False
-
-
-
GRC Sprint 2023-01, GRC Sprint 2023-02, GRC Sprint 2023-03
-
No
Create a new controller that relays Gatekeeper constraint audit events to Policy status events. This is described in this section of the design document:
https://github.com/open-cluster-management-io/enhancements/tree/main/enhancements/sig-policy/85-gatekeeper-policy-integration#new-controller
See the status messages that should be sent here:
https://github.com/open-cluster-management-io/enhancements/tree/main/enhancements/sig-policy/85-gatekeeper-policy-integration#status-reporting
Note that if an enforcementAction of deny is set on a Gatekeeper constraint and the Gatekeeper validating webhook is disabled, a non-compliant message indicating that the webhook is disabled and any Gatekeeper audit failures should be included.
- is triggered by
-
ACM-3322 Native Gatekeeper constraint support in policies
- Closed