Commands¶
Run Authz Server¶
Start the Kyverno Authz Server
Options¶
--allow-insecure-registry Allow insecure registry
--events-enabled Enable k8s events on authz, if not running in k8s this flag won't take effect
--external-policy-source stringArray External policy sources
--grpc-address string Address to listen on (default ":9081")
--grpc-network string Network to listen on (default "tcp")
-h, --help help for authz-server
--image-pull-secret stringArray Image pull secrets
--kube-as string Username to impersonate for the operation
--kube-as-group stringArray Group to impersonate for the operation, this flag can be repeated to specify multiple groups.
--kube-as-uid string UID to impersonate for the operation
--kube-certificate-authority string Path to a cert file for the certificate authority
--kube-client-certificate string Path to a client certificate file for TLS
--kube-client-key string Path to a client key file for TLS
--kube-cluster string The name of the kubeconfig cluster to use
--kube-context string The name of the kubeconfig context to use
--kube-disable-compression If true, opt-out of response compression for all requests to the server
--kube-insecure-skip-tls-verify If true, the server's certificate will not be checked for validity. This will make your HTTPS connections insecure
-n, --kube-namespace string If present, the namespace scope for this CLI request
--kube-password string Password for basic authentication to the API server
--kube-policy-source Enable in-cluster kubernetes policy source (default true)
--kube-proxy-url string If provided, this URL will be used to connect via proxy
--kube-request-timeout string The length of time to wait before giving up on a single server request. Non-zero values should contain a corresponding time unit (e.g. 1s, 2m, 3h). A value of zero means don't timeout requests. (default "0")
--kube-server string The address and port of the Kubernetes API server
--kube-tls-server-name string If provided, this name will be used to validate server certificate. If this is not provided, hostname used to contact the server is used.
--kube-token string Bearer token for authentication to the API server
--kube-user string The name of the kubeconfig user to use
--kube-username string Username for basic authentication to the API server
--log-msg-format string The format in which request logs would be shown in stdout (default "[%s] envoy: request %s, response: %s\n")
--metrics-address string Address to listen on for metrics (default ":9082")
--openreports-enabled Enable reporting in the openreports format, if not running in k8s or the openreports CRD is not installed this flag won't take effect
--probes-address string Address to listen on for health checks
--report-flush-interval string how often do results get flushed into the openreports report (if active)
--result-buffer-size int Event buffer size for openreports, note that if the total exceeded the 1MB etcd limit, report flushing will error (default 500)
Run Validation Webhook¶
Start the validation webhook
Options¶
-h, --help help for validation-webhook
--internal-cert-management Enable Kyverno internal certificate management (default true)
--kube-as string Username to impersonate for the operation
--kube-as-group stringArray Group to impersonate for the operation, this flag can be repeated to specify multiple groups.
--kube-as-uid string UID to impersonate for the operation
--kube-certificate-authority string Path to a cert file for the certificate authority
--kube-client-certificate string Path to a client certificate file for TLS
--kube-client-key string Path to a client key file for TLS
--kube-cluster string The name of the kubeconfig cluster to use
--kube-context string The name of the kubeconfig context to use
--kube-disable-compression If true, opt-out of response compression for all requests to the server
--kube-insecure-skip-tls-verify If true, the server's certificate will not be checked for validity. This will make your HTTPS connections insecure
-n, --kube-namespace string If present, the namespace scope for this CLI request
--kube-password string Password for basic authentication to the API server
--kube-proxy-url string If provided, this URL will be used to connect via proxy
--kube-request-timeout string The length of time to wait before giving up on a single server request. Non-zero values should contain a corresponding time unit (e.g. 1s, 2m, 3h). A value of zero means don't timeout requests. (default "0")
--kube-server string The address and port of the Kubernetes API server
--kube-tls-server-name string If provided, this name will be used to validate server certificate. If this is not provided, hostname used to contact the server is used.
--kube-token string Bearer token for authentication to the API server
--kube-user string The name of the kubeconfig user to use
--kube-username string Username for basic authentication to the API server
--metrics-address string Address to listen on for metrics (default ":9082")
--probes-address string Address to listen on for health checks (default ":9080")
--webhook-configuration-name string ValidatingWebhookConfiguration name to patch with generated CA bundle
--webhook-namespace string Namespace where webhook service and secrets are created (default "kyverno")
--webhook-service-name string Webhook service name used for TLS certificate generation (default "kyverno-authz-server-validation")