pfe-adv-sep/lab-03/allow-hostpath.yaml (15 lines of code) (raw):
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sPSPHostFilesystem
metadata:
name: allow-hostpath
spec:
match:
kinds:
- apiGroups:
- ""
kinds:
- Pod
parameters:
allowedHostPaths:
- pathPrefix: /var/log
readOnly: true