From 63119c924878b8a10229687f852f3a4be0b4c78e Mon Sep 17 00:00:00 2001 From: Pradeep Lakshmi Narasimha Date: Thu, 12 Sep 2024 10:58:22 +0530 Subject: [PATCH] Replaced deprecated generateExistingOnPolicyUpdate with generateExisting Signed-off-by: Pradeep Lakshmi Narasimha --- content/en/docs/writing-policies/generate.md | 6 +++--- .../argo-cluster-generation-from-rancher-capi.md | 4 ++-- .../config-syncer-secret-generation-from-rancher-capi.md | 2 +- .../generate-networkpolicy-existing.md | 2 +- 4 files changed, 7 insertions(+), 7 deletions(-) diff --git a/content/en/docs/writing-policies/generate.md b/content/en/docs/writing-policies/generate.md index 805c14834..1b6c6bd73 100644 --- a/content/en/docs/writing-policies/generate.md +++ b/content/en/docs/writing-policies/generate.md @@ -116,7 +116,7 @@ spec: apiVersion: networking.k8s.io/v1 name: deny-all-traffic namespace: "{{request.object.metadata.name}}" - data: + data: spec: # select all pods in the namespace podSelector: {} @@ -128,7 +128,7 @@ spec: For other examples of generate rules, see the [policy library](/policies/?policytypes=generate). {{% alert title="Note" color="info" %}} -The field `spec.generateExistingOnPolicyUpdate` is no longer required for "classic" generate rules, is deprecated, and will be removed in an upcoming version. +The field `spec.generateExisting` is no longer required for "classic" generate rules, is deprecated, and will be removed in an upcoming version. {{% /alert %}} ## Clone Source @@ -267,7 +267,7 @@ spec: apiVersion: rbac.authorization.k8s.io/v1 name: steven-rolebinding namespace: "{{request.object.metadata.name}}" - data: + data: subjects: - kind: User name: steven diff --git a/content/en/policies/argo/argo-cluster-generation-from-rancher-capi/argo-cluster-generation-from-rancher-capi.md b/content/en/policies/argo/argo-cluster-generation-from-rancher-capi/argo-cluster-generation-from-rancher-capi.md index 25993b84d..3998d7e43 100644 --- a/content/en/policies/argo/argo-cluster-generation-from-rancher-capi/argo-cluster-generation-from-rancher-capi.md +++ b/content/en/policies/argo/argo-cluster-generation-from-rancher-capi/argo-cluster-generation-from-rancher-capi.md @@ -25,7 +25,7 @@ metadata: policies.kyverno.io/minversion: 1.7.0 kyverno.io/kubernetes-version: "1.23" policies.kyverno.io/description: >- - This policy generates and synchronizes Argo CD cluster secrets from Rancher + This policy generates and synchronizes Argo CD cluster secrets from Rancher managed cluster.provisioning.cattle.io/v1 resources and their corresponding CAPI secrets. In this solution, Argo CD integrates with Rancher managed clusters via the central Rancher authentication proxy which shares the network endpoint of the Rancher API/GUI. @@ -33,7 +33,7 @@ metadata: "Cluster-API cluster auto-registration" and Rancher issue https://github.com/rancher/rancher/issues/38053 "Fix type and labels Rancher v2 provisioner specifies when creating CAPI Cluster Secret". spec: - generateExistingOnPolicyUpdate: true + generateExisting: true rules: - name: source-rancher-non-local-cluster-and-capi-secret match: diff --git a/content/en/policies/kubeops/config-syncer-secret-generation-from-rancher-capi/config-syncer-secret-generation-from-rancher-capi.md b/content/en/policies/kubeops/config-syncer-secret-generation-from-rancher-capi/config-syncer-secret-generation-from-rancher-capi.md index e203b5245..15e3d342a 100644 --- a/content/en/policies/kubeops/config-syncer-secret-generation-from-rancher-capi/config-syncer-secret-generation-from-rancher-capi.md +++ b/content/en/policies/kubeops/config-syncer-secret-generation-from-rancher-capi/config-syncer-secret-generation-from-rancher-capi.md @@ -30,7 +30,7 @@ metadata: required by the Kubeops Config Syncer for it to sync ConfigMaps/Secrets from the Rancher management cluster to downstream clusters. spec: - generateExistingOnPolicyUpdate: true + generateExisting: true rules: - name: source-rancher-non-local-cluster-and-capi-secret match: diff --git a/content/en/policies/other/generate-networkpolicy-existing/generate-networkpolicy-existing.md b/content/en/policies/other/generate-networkpolicy-existing/generate-networkpolicy-existing.md index 87e1eadd9..8410ea4a2 100644 --- a/content/en/policies/other/generate-networkpolicy-existing/generate-networkpolicy-existing.md +++ b/content/en/policies/other/generate-networkpolicy-existing/generate-networkpolicy-existing.md @@ -31,7 +31,7 @@ metadata: is additional overhead. This policy creates a new NetworkPolicy for existing Namespaces which results in a default deny behavior and labels it with created-by=kyverno. spec: - generateExistingOnPolicyUpdate: true + generateExisting: true rules: - name: generate-existing-networkpolicy match: