{"repo":"open-policy-agent/gatekeeper-library","free":true,"listed":false,"github":"https://github.com/open-policy-agent/gatekeeper-library","clone":"git clone https://github.com/open-policy-agent/gatekeeper-library.git","description":"📚 The OPA Gatekeeper policy library","language":"Open Policy Agent","stars":700,"topics":["gatekeeper","opa","policy","cncf","kubernetes","policy-library","hacktoberfest"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"OPA Gatekeeper Library A community-owned library of policies for the OPA Gatekeeper project. Validation and Mutation The library consists of two main components: Validation and Mutation . - Validation: Gatekeeper can validate resources in the cluster against Gatekeeper validation policies, such as these defined in the library. The policies are defined as ConstraintTemplates and Constraints . ConstraintTemplates can be applied directly to a cluster and then Constraints can be applied to customize policy to fit your specific needs. - Mutation: Gatekeeper can mutate resources in the cluster against the Gatekeeper mutation policies, such as these defined in the library. Mutation policies are only examples, they should be customized to meet your needs before being applied. Usage kustomize You can use kustomize to install some or all of the templates alongside your own constraints. First, create a kustomization.yaml file: Then define your constraints in a file called constraints.yaml in the same directory. Example constraints can be found in the \"samples\" folders. You can install everything with kustomize build . kubectl apply -f - . More information can be found in the kustomization documentation. kubectl Instead of using kustomize, you can directly apply the template.yaml and constraint.yaml provided in each directory under library/ For example Testing The suite.yaml files define test cases for each ConstraintTemplate in the library. Changes to gatekeeper-library ConstraintTempla","default_branch":null,"files":null,"tree":[],"storefront":"/r/open-policy-agent","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/open-policy-agent/gatekeeper-library/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}