built-in-references/Kubernetes/service-allowed-ports/constraint.yaml (12 lines of code) (raw):
apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sAzureServiceAllowedPorts
metadata:
name: service-allowed-ports
spec:
match:
excludedNamespaces: {{ .Values.excludedNamespaces }}
kinds:
- apiGroups: [""]
kinds: ["Service"]
parameters:
allowedPorts: {{ .Values.allowedServicePorts }}