This message was deleted.
# neuvector-security
a
This message was deleted.
q
How did you install NeuVector? (Helm? example yaml files? other?)
c
Helm. I used only
neuvector-core
chart.
1
q
Maybe its crabby that you also didn’t add a namespace?
a la
Copy code
metadata:
    name: user-created.test.deny
    namespace: test-deny
The namespace needs to exist, as well
It might be easier in the long run to create the CRD rule in NeuVector and export it versus hand-spinning it. Maybe. 🙂
Copy code
apiVersion: <http://neuvector.com/v1|neuvector.com/v1>
kind: NvAdmissionControlSecurityRule
metadata:
  name: local
spec:
  config:
    client_mode: service
    enable: false
    mode: monitor
  rules:
  - action: deny
    comment: deny deployments to default ns
    criteria:
    - name: namespace
      op: containsAny
      path: namespace
      value: default
    rule_mode: protect
c
thank you Jorn! Your manifests worked, the
config
section helped.
🙌 1