kubernetes/pkg/apis
Kubernetes Submit Queue f73101066a
Merge pull request #58647 from oracle/for/upstream/master/hostpath-psp-readonly
Automatic merge from submit-queue (batch tested with PRs 64344, 64709, 64717, 63631, 58647). If you want to cherry-pick this change to another branch, please follow the instructions <a href="https://github.com/kubernetes/community/blob/master/contributors/devel/cherry-picks.md">here</a>.

Add support for enforcing read only host paths in PSPs. 

**What this PR does / why we need it**:

This PR adds support for the PSP to enforce that host paths are readonly. 

**Which issue(s) this PR fixes** *(optional, in `fixes #<issue number>(, fixes #<issue_number>, ...)` format, will close the issue(s) when PR gets merged)*:
Fixes #57371
xref https://github.com/kubernetes/features/issues/5

**Special notes for your reviewer**:

**Release note**:

```release-note
PodSecurityPolicy now supports restricting hostPath volume mounts to be readOnly and under specific path prefixes
```

/cc @ericchiang @liggitt
2018-06-05 02:16:21 -07:00
..
abac regenerated all files and remove all YEAR fields 2018-03-08 17:52:48 +08:00
admission simplify api registration 2018-05-08 18:33:50 -04:00
admissionregistration simplify api registration 2018-05-08 18:33:50 -04:00
apps conversions: don't mutate in.ObjectMeta.Annotations 2018-06-02 09:44:45 +00:00
authentication svcacct: validate min and max expiration seconds on TokenRequest 2018-05-30 17:32:49 -07:00
authorization simplify api registration 2018-05-08 18:33:50 -04:00
autoscaling simplify api registration 2018-05-08 18:33:50 -04:00
batch apiextensions: add ObjectMeta schema validation and pruning 2018-06-01 17:43:07 +00:00
certificates simplify api registration 2018-05-08 18:33:50 -04:00
componentconfig auto generated file 2018-05-18 10:23:38 +08:00
core generated files 2018-06-05 09:44:10 +08:00
events simplify api registration 2018-05-08 18:33:50 -04:00
extensions Add support for enforcing read only host paths in PSPs. 2018-06-04 19:10:37 -04:00
imagepolicy simplify api registration 2018-05-08 18:33:50 -04:00
networking simplify api registration 2018-05-08 18:33:50 -04:00
policy Add support for enforcing read only host paths in PSPs. 2018-06-04 19:10:37 -04:00
rbac generated 2018-05-22 08:17:05 -04:00
scheduling Generated 2018-05-12 02:01:09 -04:00
settings autogenerated 2018-05-30 11:06:58 -07:00
storage generated files 2018-06-05 09:44:10 +08:00
OWNERS Remove myself (timothysc) from OWNERS files on areas that I do not 2018-02-12 18:56:41 -06:00