Skip to content

Support ConfigMaps as paramKind for ValidatingAdmissionPolicy to avoid failure during discovery delays with CRDs #4166

@chobostar

Description

@chobostar

(AI generated)

Describe the solution you'd like

To avoid dependency on CRD discovery for parameters, allow ConfigMaps (or possibly Secrets) to be used as paramKind for ValidatingAdmissionPolicy.

ConfigMaps (or Secrets) are native core API resources, always available without discovery delays.

Anything else you would like to add:

Currently, ValidatingAdmissionPolicy (VAP) relies on CRDs as paramKind to provide dynamic parameters. However, this approach has some drawbacks:
kubernetes/kubernetes#124237
kubernetes/kubernetes#122658

Image

Environment:

  • Gatekeeper version:
  • Kubernetes version: (use kubectl version):

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions