diff --git a/clusters/cl01tl/services/generic-device-plugin/templates/namespace.yaml b/clusters/cl01tl/services/generic-device-plugin/templates/namespace.yaml new file mode 100644 index 000000000..f841985e1 --- /dev/null +++ b/clusters/cl01tl/services/generic-device-plugin/templates/namespace.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: generic-device-plugin + labels: + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/warn: privileged diff --git a/clusters/cl01tl/services/intel-device-plugin/templates/namespace.yaml b/clusters/cl01tl/services/intel-device-plugin/templates/namespace.yaml new file mode 100644 index 000000000..c2f50eac5 --- /dev/null +++ b/clusters/cl01tl/services/intel-device-plugin/templates/namespace.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: intel-device-plugin + labels: + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/warn: privileged diff --git a/clusters/cl01tl/services/node-feature-discovery/templates/namespace.yaml b/clusters/cl01tl/services/node-feature-discovery/templates/namespace.yaml new file mode 100644 index 000000000..84ed3cb76 --- /dev/null +++ b/clusters/cl01tl/services/node-feature-discovery/templates/namespace.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: node-feature-discovery + labels: + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/warn: privileged diff --git a/clusters/cl01tl/services/spegel/templates/namespace.yaml b/clusters/cl01tl/services/spegel/templates/namespace.yaml index 870a6b300..f0371e897 100644 --- a/clusters/cl01tl/services/spegel/templates/namespace.yaml +++ b/clusters/cl01tl/services/spegel/templates/namespace.yaml @@ -3,4 +3,6 @@ kind: Namespace metadata: name: spegel labels: + pod-security.kubernetes.io/audit: privileged pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/warn: privileged diff --git a/clusters/cl01tl/services/tailscale-operator/templates/namespace.yaml b/clusters/cl01tl/services/tailscale-operator/templates/namespace.yaml new file mode 100644 index 000000000..d8e00a849 --- /dev/null +++ b/clusters/cl01tl/services/tailscale-operator/templates/namespace.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: tailscale-operator + labels: + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/warn: privileged diff --git a/clusters/cl01tl/storage/rook-ceph/templates/namespace.yaml b/clusters/cl01tl/storage/rook-ceph/templates/namespace.yaml new file mode 100644 index 000000000..ccc9b8454 --- /dev/null +++ b/clusters/cl01tl/storage/rook-ceph/templates/namespace.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: rook-ceph + labels: + pod-security.kubernetes.io/audit: privileged + pod-security.kubernetes.io/enforce: privileged + pod-security.kubernetes.io/warn: privileged