Skip to content

Commit 8917b26

Browse files
committed
PodSecurity: switch restricted volume check to positive check
1 parent b599a32 commit 8917b26

File tree

1 file changed

+12
-24
lines changed

1 file changed

+12
-24
lines changed

content/en/docs/concepts/security/pod-security-standards.md

Lines changed: 12 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -305,34 +305,22 @@ fail validation.
305305
<tr>
306306
<td style="white-space: nowrap">Volume Types</td>
307307
<td>
308-
<p>In addition to restricting HostPath volumes, the restricted policy limits usage of non-core volume types to those defined through PersistentVolumes.</p>
308+
<p>The restricted policy only permits the following volume types.</p>
309309
<p><strong>Restricted Fields</strong></p>
310310
<ul>
311-
<li><code>spec.volumes[*].hostPath</code></li>
312-
<li><code>spec.volumes[*].gcePersistentDisk</code></li>
313-
<li><code>spec.volumes[*].awsElasticBlockStore</code></li>
314-
<li><code>spec.volumes[*].gitRepo</code></li>
315-
<li><code>spec.volumes[*].nfs</code></li>
316-
<li><code>spec.volumes[*].iscsi</code></li>
317-
<li><code>spec.volumes[*].glusterfs</code></li>
318-
<li><code>spec.volumes[*].rbd</code></li>
319-
<li><code>spec.volumes[*].flexVolume</code></li>
320-
<li><code>spec.volumes[*].cinder</code></li>
321-
<li><code>spec.volumes[*].cephfs</code></li>
322-
<li><code>spec.volumes[*].flocker</code></li>
323-
<li><code>spec.volumes[*].fc</code></li>
324-
<li><code>spec.volumes[*].azureFile</code></li>
325-
<li><code>spec.volumes[*].vsphereVolume</code></li>
326-
<li><code>spec.volumes[*].quobyte</code></li>
327-
<li><code>spec.volumes[*].azureDisk</code></li>
328-
<li><code>spec.volumes[*].portworxVolume</code></li>
329-
<li><code>spec.volumes[*].scaleIO</code></li>
330-
<li><code>spec.volumes[*].storageos</code></li>
331-
<li><code>spec.volumes[*].photonPersistentDisk</code></li>
311+
<li><code>spec.volumes[*]</code></li>
332312
</ul>
333313
<p><strong>Allowed Values</strong></p>
334-
<ul>
335-
<li>Undefined/nil</li>
314+
Every item in the <code>spec.volumes[*]</code> list must set one of the following fields to a non-null value:
315+
<ul>
316+
<li><code>spec.volumes[*].configMap</code></li>
317+
<li><code>spec.volumes[*].csi</code></li>
318+
<li><code>spec.volumes[*].downwardAPI</code></li>
319+
<li><code>spec.volumes[*].emptyDir</code></li>
320+
<li><code>spec.volumes[*].ephemeral</code></li>
321+
<li><code>spec.volumes[*].persistentVolumeClaim</code></li>
322+
<li><code>spec.volumes[*].projected</code></li>
323+
<li><code>spec.volumes[*].secret</code></li>
336324
</ul>
337325
</td>
338326
</tr>

0 commit comments

Comments
 (0)