From c3281696ebcb6b3899b3071742d9679dfab937c3 Mon Sep 17 00:00:00 2001 From: aledbf Date: Tue, 11 Aug 2020 15:24:27 +0000 Subject: [PATCH] Deploy GitHub Pages --- examples/psp/psp.yaml | 79 ++++++++++++++-------------------- sitemap.xml | 98 +++++++++++++++++++++--------------------- sitemap.xml.gz | Bin 678 -> 678 bytes 3 files changed, 81 insertions(+), 96 deletions(-) diff --git a/examples/psp/psp.yaml b/examples/psp/psp.yaml index f840103bd..2d57d8d27 100644 --- a/examples/psp/psp.yaml +++ b/examples/psp/psp.yaml @@ -8,49 +8,37 @@ metadata: apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata: - annotations: - # Assumes apparmor available - apparmor.security.beta.kubernetes.io/allowedProfileNames: 'runtime/default' - apparmor.security.beta.kubernetes.io/defaultProfileName: 'runtime/default' - seccomp.security.alpha.kubernetes.io/allowedProfileNames: 'docker/default' - seccomp.security.alpha.kubernetes.io/defaultProfileName: 'docker/default' name: ingress-nginx + namespace: ingress-nginx spec: allowedCapabilities: - - NET_BIND_SERVICE - allowPrivilegeEscalation: true - fsGroup: - rule: 'MustRunAs' - ranges: - - min: 1 - max: 65535 - hostIPC: false - hostNetwork: false - hostPID: false - hostPorts: - - min: 80 - max: 65535 + - NET_BIND_SERVICE privileged: false - readOnlyRootFilesystem: false - runAsUser: - rule: 'MustRunAsNonRoot' - ranges: - - min: 101 - max: 65535 - seLinux: - rule: 'RunAsAny' - supplementalGroups: - rule: 'MustRunAs' - ranges: - # Forbid adding the root group. - - min: 1 - max: 65535 + allowPrivilegeEscalation: true + # Allow core volume types. volumes: - - 'configMap' - - 'downwardAPI' - - 'emptyDir' - - 'projected' - - 'secret' + - configMap + - secret + hostIPC: false + hostPID: false + runAsUser: + # Require the container to run without root privileges. + rule: MustRunAsNonRoot + supplementalGroups: + rule: MustRunAs + ranges: + # Forbid adding the root group. + - min: 1 + max: 65535 + fsGroup: + rule: MustRunAs + ranges: + # Forbid adding the root group. + - min: 1 + max: 65535 + readOnlyRootFilesystem: false + seLinux: + rule: RunAsAny --- @@ -60,14 +48,10 @@ metadata: name: ingress-nginx-psp namespace: ingress-nginx rules: -- apiGroups: - - policy - resourceNames: - - ingress-nginx - resources: - - podsecuritypolicies - verbs: - - use +- apiGroups: [policy] + resources: [podsecuritypolicies] + verbs: [use] + resourceNames: [ingress-nginx] --- @@ -84,4 +68,5 @@ subjects: - kind: ServiceAccount name: default - kind: ServiceAccount - name: nginx-ingress-serviceaccount + name: ingress-nginx + namespace: ingress-nginx diff --git a/sitemap.xml b/sitemap.xml index e5026aed6..eef15d8d3 100644 --- a/sitemap.xml +++ b/sitemap.xml @@ -1,199 +1,199 @@ https://kubernetes.github.io/ingress-nginx/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/how-it-works/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/troubleshooting/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/kubectl-plugin/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/development/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/deploy/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/deploy/baremetal/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/deploy/rbac/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/deploy/upgrade/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/nginx-configuration/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/basic-usage/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/nginx-configuration/annotations/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/nginx-configuration/configmap/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/nginx-configuration/custom-template/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/nginx-configuration/log-format/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/cli-arguments/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/custom-errors/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/default-backend/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/exposing-tcp-udp-services/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/fcgi-services/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/ingress-path-matching/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/external-articles/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/miscellaneous/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/monitoring/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/multiple-ingress/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/tls/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/third-party-addons/modsecurity/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/user-guide/third-party-addons/opentracing/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/PREREQUISITES/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/affinity/cookie/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/auth/basic/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/auth/client-certs/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/auth/external-auth/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/auth/oauth-external-auth/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/customization/configuration-snippets/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/customization/custom-configuration/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/customization/custom-errors/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/customization/custom-headers/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/customization/external-auth-headers/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/customization/ssl-dh-param/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/customization/sysctl/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/docker-registry/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/grpc/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/multi-tls/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/rewrite/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/static-ip/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/tls-termination/ - 2020-08-10 + 2020-08-11 daily https://kubernetes.github.io/ingress-nginx/examples/psp/ - 2020-08-10 + 2020-08-11 daily \ No newline at end of file diff --git a/sitemap.xml.gz b/sitemap.xml.gz index 9513e91e1f5fc9d7a8681e0dbb19a10e9342a26c..3e535d6c17819cd9b49651e750a45543d1714209 100644 GIT binary patch delta 619 zcmV-x0+jux1*QcDABzYGDY!C`2QLC$Ns%}me?amn-pnr-%lQnVN!CYqGk<>irmp9= z{l%(aAmCXIj&w60nDf`J+wFD>@(iQSv`FYWGD96ucb@E)i!bxO<@Oh|_E?2v`j$*J zdt26k5g2IUJP&2P@TseBi$J8J^Ksv;x|Z;otBJ>C`>W;EQZ295P zq&z}onRq#*gJ80?Mi_y05X^{cZ3N?$>`+^fNLUC^x#BC`aYC6CH{KQ0Tn`c9#A{97 zs6yIJac^~uiI0~wLHg6E34;l;7veOkf2wP8&^*Q33CXEV!cntucoV$R=t?_&rI-1+ zEC4Z~bXE%+T>`6m@NFSl;k2;NiR!9ilU1=<)uk72K>99kjPp}reO<_!2UQz`8H8Gf z4|TycT8G*q*qb1Jk4H}iLeLRX5zm^U=Y;Z$V61)2=K$&)Asm;3c*4P>t$hIbf1tFr zOSMh+_2rXsU>#8GV_O3U!?+%K(@8!?lQc?6dgYY8x>jRve zoA}?ZKF619JU{0iKwFp;_=g*HRf7CPLD`|HBt1?E`#^?+XkeSnwrWuX=ZWzkn$=;J ztvim+P6;(kZWgFxO=^D>80E8Q%KA;K+E_;)<)6Tr{@-3+9A5~y{|z}njVY5M F005lOGZO#+ delta 619 zcmV-x0+jux1*QcDABzYGn9MPe2QLC#OOZGof5_x9-pnr-%lQnVLF=QtnLj^$Q`hs` z{$f>fAmCXIj&w60nA6v;+wFD>@(iO+w7~2-GD96ucb@E)i!bxO<@Oh|_E-fpeM_dA zy)A3V5g2IUJP&2P@YvP2%|N80^Ksv;x|Z;otBFUn{nhensg~F3a#@$pbLS8<=;&aR zf8l3uwGW3?_ipAGv+5enKOhabQ=Zih^Ohv?amKO^Km#Jz6^V!~#Bfk4lscA3XyF9{ zrV%2`#7hAWg2~o8!w9T{V8*=GMlfDUE^7-C2@641uJ}rKoKObi#=DX=*F!`&@miBN zs*rY5+*=(Z^6`=;NPikNVK71VLX4xTf4U|G%~PzMfKF{NkD7(Uo8XnsuC(JPIoz=odm%yqXd|QZCI4$fGQe9PSk}5W-y7b}=NZ;j+aegYSuM0`@plV|rh(+dlSU(@#x7w2s#25@vImc6AnJx+6OWpf0VYi z>C4JOU`qCUm>xW)Dju>nLQ5I;y6Q-oz3Ywb`@`MC-H+${$NQ(dN71Buv+=RjsX^R& zkj+|nIJr>ym{p0_+ejJ6O!8^}D1$ZyD$dQ$h{X8)b%F^+mFUCbd5bjPgk|W&NgAZLFh@@=xGI|8FlZjxPk<{{~-y27Z$v F005=hH6#E4