Skip to content

Commit

Permalink
Add a ValidatingAdmissionPolicy blocking ServiceCIDR changes
Browse files Browse the repository at this point in the history
OCP does not yet support changing the service CIDRs at runtime.
  • Loading branch information
danwinship committed Dec 13, 2024
1 parent de93ea6 commit b62995a
Showing 1 changed file with 14 additions and 0 deletions.
14 changes: 14 additions & 0 deletions bindata/cluster-network-operator/servicecidr-vap.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: "servicecidrs.openshift.io"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups: ["networking"]
apiVersions: ["v1"]
operations: ["CREATE", "UPDATE"]
resources: ["servicecidr"]
validations:
- expression: "object.name != 'kubernetes'"

0 comments on commit b62995a

Please sign in to comment.