From 552526b6ad1a7aedffca37841793c0a7eaed261a Mon Sep 17 00:00:00 2001 From: sangkenlee Date: Wed, 22 May 2024 22:25:20 +0900 Subject: [PATCH] policy guard rule audit bugfix --- internal/policy-template/tksguard-rego.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/internal/policy-template/tksguard-rego.go b/internal/policy-template/tksguard-rego.go index e19a94bc..89830dbc 100644 --- a/internal/policy-template/tksguard-rego.go +++ b/internal/policy-template/tksguard-rego.go @@ -23,7 +23,7 @@ const tks_guard_rego_rulename = ` # Do not delete following line, added by TKS const tks_guard_rego_rulelogic = ` # Do not delete or edit following rule, managed by TKS ___not_tks_triggered_request___ { - not input.review.userInfo + not input.review.userInfo.username } { tks_users := {"kubernetes-admin","system:serviceaccount:kube-system:argocd-manager"} tks_groups := {"system:masters"}