{"repo":"plexsystems/konstraint","free":true,"listed":false,"github":"https://github.com/plexsystems/konstraint","clone":"git clone https://github.com/plexsystems/konstraint.git","description":"A policy management tool for interacting with Gatekeeper","language":"Go","stars":393,"topics":["gatekeeper","policy","conftest","opa","kubernetes","rego","open-policy-agent"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"Konstraint Konstraint is a CLI tool to assist with the creation and management of templates and constraints when using Gatekeeper. Installation A docker image is also provided for each release: Usage To create the Gatekeeper resources, use konstraint create . To generate the accompanying documentation, use konstraint doc . Both commands support the --output flag to specify where to save the output. For more detailed usage documentation, see the CLI Documentation. Why this tool exists Automatically copy Rego to the ConstraintTemplate When writing policies for Gatekeeper, the Rego must be added to ConstraintTemplates in order for Gatekeeper to enforce the policy. This creates a scenario in which the Rego is written in a .rego file, and then copied into the ConstraintTemplate. When a change is needed to be made to the Rego, both instances must be updated. Automatically update all ConstraintTemplates with library changes Gatekeeper supports importing libraries into ConstraintTemplates with the libs field. If a change is required to the imported library, every template must be updated to include this new change. Enable writing the same policies for Conftest and Gatekeeper With Gatekeeper, policies are evaluated in the context of an AdmissionReview. This means that policies are typically written with a prefix of input.review.object . With Conftest, policies are written against yaml files. This creates a scenario where the policy needs to be written differently depending upon the co","default_branch":null,"files":null,"tree":[],"storefront":"/r/plexsystems","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/plexsystems/konstraint/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}