Skip to content

Commands

Run Authz Server

Start the Kyverno Authz Server

kyverno-authz serve envoy authz-server [flags]

Options

      --allow-insecure-registry              Allow insecure registry
      --events-enabled                       Enable k8s events on authz, if not running in k8s this flag won't take effect
      --external-policy-source stringArray   External policy sources
      --grpc-address string                  Address to listen on (default ":9081")
      --grpc-network string                  Network to listen on (default "tcp")
  -h, --help                                 help for authz-server
      --image-pull-secret stringArray        Image pull secrets
      --kube-as string                       Username to impersonate for the operation
      --kube-as-group stringArray            Group to impersonate for the operation, this flag can be repeated to specify multiple groups.
      --kube-as-uid string                   UID to impersonate for the operation
      --kube-certificate-authority string    Path to a cert file for the certificate authority
      --kube-client-certificate string       Path to a client certificate file for TLS
      --kube-client-key string               Path to a client key file for TLS
      --kube-cluster string                  The name of the kubeconfig cluster to use
      --kube-context string                  The name of the kubeconfig context to use
      --kube-disable-compression             If true, opt-out of response compression for all requests to the server
      --kube-insecure-skip-tls-verify        If true, the server's certificate will not be checked for validity. This will make your HTTPS connections insecure
  -n, --kube-namespace string                If present, the namespace scope for this CLI request
      --kube-password string                 Password for basic authentication to the API server
      --kube-policy-source                   Enable in-cluster kubernetes policy source (default true)
      --kube-proxy-url string                If provided, this URL will be used to connect via proxy
      --kube-request-timeout string          The length of time to wait before giving up on a single server request. Non-zero values should contain a corresponding time unit (e.g. 1s, 2m, 3h). A value of zero means don't timeout requests. (default "0")
      --kube-server string                   The address and port of the Kubernetes API server
      --kube-tls-server-name string          If provided, this name will be used to validate server certificate. If this is not provided, hostname used to contact the server is used.
      --kube-token string                    Bearer token for authentication to the API server
      --kube-user string                     The name of the kubeconfig user to use
      --kube-username string                 Username for basic authentication to the API server
      --log-msg-format string                The format in which request logs would be shown in stdout (default "[%s] envoy: request %s, response: %s\n")
      --metrics-address string               Address to listen on for metrics (default ":9082")
      --openreports-enabled                  Enable reporting in the openreports format, if not running in k8s or the openreports CRD is not installed this flag won't take effect
      --probes-address string                Address to listen on for health checks
      --report-flush-interval string         how often do results get flushed into the openreports report (if active)
      --result-buffer-size int               Event buffer size for openreports, note that if the total exceeded the 1MB etcd limit, report flushing will error (default 500)

Run Validation Webhook

Start the validation webhook

kyverno-authz serve envoy validation-webhook [flags]

Options

  -h, --help                                help for validation-webhook
      --internal-cert-management            Enable Kyverno internal certificate management (default true)
      --kube-as string                      Username to impersonate for the operation
      --kube-as-group stringArray           Group to impersonate for the operation, this flag can be repeated to specify multiple groups.
      --kube-as-uid string                  UID to impersonate for the operation
      --kube-certificate-authority string   Path to a cert file for the certificate authority
      --kube-client-certificate string      Path to a client certificate file for TLS
      --kube-client-key string              Path to a client key file for TLS
      --kube-cluster string                 The name of the kubeconfig cluster to use
      --kube-context string                 The name of the kubeconfig context to use
      --kube-disable-compression            If true, opt-out of response compression for all requests to the server
      --kube-insecure-skip-tls-verify       If true, the server's certificate will not be checked for validity. This will make your HTTPS connections insecure
  -n, --kube-namespace string               If present, the namespace scope for this CLI request
      --kube-password string                Password for basic authentication to the API server
      --kube-proxy-url string               If provided, this URL will be used to connect via proxy
      --kube-request-timeout string         The length of time to wait before giving up on a single server request. Non-zero values should contain a corresponding time unit (e.g. 1s, 2m, 3h). A value of zero means don't timeout requests. (default "0")
      --kube-server string                  The address and port of the Kubernetes API server
      --kube-tls-server-name string         If provided, this name will be used to validate server certificate. If this is not provided, hostname used to contact the server is used.
      --kube-token string                   Bearer token for authentication to the API server
      --kube-user string                    The name of the kubeconfig user to use
      --kube-username string                Username for basic authentication to the API server
      --metrics-address string              Address to listen on for metrics (default ":9082")
      --probes-address string               Address to listen on for health checks (default ":9080")
      --webhook-configuration-name string   ValidatingWebhookConfiguration name to patch with generated CA bundle
      --webhook-namespace string            Namespace where webhook service and secrets are created (default "kyverno")
      --webhook-service-name string         Webhook service name used for TLS certificate generation (default "kyverno-authz-server-validation")