Skip to content

Commit f11d70d

Browse files
authored
Update policy-for-kubernetes.md
1 parent 825b162 commit f11d70d

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

articles/governance/policy/concepts/policy-for-kubernetes.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -608,7 +608,7 @@ Finally, to identify the AKS cluster version that you're using, follow the linke
608608

609609
#### 1.7.0
610610
Introducing expansion, a shift left feature that will let you know up front whether your workload resources (Deployments, ReplicaSets, Jobs, etc) will produce admissible pods. Expansion should not change the behavior of your policies; rather, it will just shift Gatekeeper's evaluation of pod-scoped policies to occur at workload admission time rather than pod admission time. However, to perform this evaluation it must generate and evaluate a what-if pod based on the pod spec defined in the workload, which may have incomplete metadata (for instance, it will be missing the proper owner references). Because of this small risk of policy behavior changing, we are introducing expansion as disabled by default. To enable expansion for a given policy definition, set `.policyRule.then.details.source` to `All`. Built-ins will be updated soon to enable parameterization of this field. If you test your policy definition and find that the what-if pod being generated for evaluation purposes is incomplete, you can also use a mutation with source `Generated` to mutate the what-if pods. For more information on this option, view the [Gatekeeper documentation](https://open-policy-agent.github.io/gatekeeper/website/docs/expansion#mutating-example).
611-
Update the addon to use MSAL by default, with a fallback to ADAL (full ADAL removal will occur next release).
611+
Security improvements.
612612
- Released July 2024
613613
- Kubernetes 1.27+
614614
- Gatekeeper 3.16.3

0 commit comments

Comments
 (0)