Update content/zh/docs/concepts/policy/pod-security-policy.md
Co-authored-by: Qiming Teng <tengqm@outlook.com>
This commit is contained in:
@@ -316,7 +316,7 @@ controller selects policies according to the following criteria:
|
|||||||
2. If the pod must be defaulted or mutated, the first PodSecurityPolicy
|
2. If the pod must be defaulted or mutated, the first PodSecurityPolicy
|
||||||
(ordered by name) to allow the pod is selected.
|
(ordered by name) to allow the pod is selected.
|
||||||
-->
|
-->
|
||||||
1. 优先考虑允许pod保持原样,不会更改Pod字段的默认值或其他配置的PodSecurityPolicy。
|
1. 优先考虑允许 Pod 保持原样,不会更改 Pod 字段默认值或其他配置的 PodSecurityPolicy。
|
||||||
这类非更改性质的 PodSecurityPolicy 对象之间的顺序无关紧要。
|
这类非更改性质的 PodSecurityPolicy 对象之间的顺序无关紧要。
|
||||||
2. 如果必须要为 Pod 设置默认值或者其他配置,(按名称顺序)选择第一个允许
|
2. 如果必须要为 Pod 设置默认值或者其他配置,(按名称顺序)选择第一个允许
|
||||||
Pod 操作的 PodSecurityPolicy 对象。
|
Pod 操作的 PodSecurityPolicy 对象。
|
||||||
@@ -1232,4 +1232,3 @@ By default, all safe sysctls are allowed.
|
|||||||
- 参阅[Pod 安全标准](/zh/docs/concepts/security/pod-security-standards/)
|
- 参阅[Pod 安全标准](/zh/docs/concepts/security/pod-security-standards/)
|
||||||
了解策略建议。
|
了解策略建议。
|
||||||
- 阅读 [Pod 安全策略参考](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#podsecuritypolicy-v1beta1-policy)了解 API 细节。
|
- 阅读 [Pod 安全策略参考](/docs/reference/generated/kubernetes-api/{{< param "version" >}}/#podsecuritypolicy-v1beta1-policy)了解 API 细节。
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user