diff --git a/bindata/cluster-network-operator/servicecidr-vap.yaml b/bindata/cluster-network-operator/servicecidr-vap.yaml new file mode 100644 index 0000000000..35b37a7d83 --- /dev/null +++ b/bindata/cluster-network-operator/servicecidr-vap.yaml @@ -0,0 +1,14 @@ +apiVersion: admissionregistration.k8s.io/v1 +kind: ValidatingAdmissionPolicy +metadata: + name: "servicecidrs.openshift.io" +spec: + failurePolicy: Fail + matchConstraints: + resourceRules: + - apiGroups: ["networking"] + apiVersions: ["v1"] + operations: ["CREATE", "UPDATE"] + resources: ["servicecidr"] + validations: + - expression: "object.name != 'kubernetes'"