This repository has been archived by the owner on Jun 29, 2022. It is now read-only.
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
psp: Make the restrictive policy as the first on the list
The policy order of PSP has two methods of selecting a PSP for applications: 1. If a PSP allows the pod specification as is without a mutation, then that PSP is used. 2. If the above condition fails, then the fist PSP is chosen from an allowed-PSP list, and the pod is mutated accordingly. In Lokomotive's case the general cluster-wide PSP for apps that don't ship PSP is the minimal restrictive PSP. So we need to ensure that it is on top of the list for selection not bottom. Signed-off-by: Suraj Deshmukh <suraj@kinvolk.io>
- Loading branch information