From 1fac741a245752900bf5d9807a2458cee9ad1e4c Mon Sep 17 00:00:00 2001 From: Khushboo Sancheti Date: Thu, 1 Oct 2026 15:17:55 -0700 Subject: [PATCH] Updates to script and README for new proto value Co-authored-by: Cursor --- util-scripts/skip-init-container-evaluation/README.md | 6 +++--- .../skip-init-container-evaluation.sh | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/util-scripts/skip-init-container-evaluation/README.md b/util-scripts/skip-init-container-evaluation/README.md index 32953cd..97d25c7 100644 --- a/util-scripts/skip-init-container-evaluation/README.md +++ b/util-scripts/skip-init-container-evaluation/README.md @@ -1,6 +1,6 @@ # Skip Init Container Evaluation -Starting in ACS 5.0, policies evaluate init containers by default. This script is a **one-time post-upgrade tool** that adds `skipContainerTypes: ["INIT"]` to all existing policies that don't already have an evaluation filter, preserving the pre-5.0 behavior where init containers were not evaluated. +Starting in ACS 5.0, policies evaluate init containers by default. This script is a **one-time post-upgrade tool** that adds `skipContainerTypes: ["SKIP_INIT"]` to all existing policies that don't already have an evaluation filter, preserving the pre-5.0 behavior where init containers were not evaluated. This script is not intended to be run repeatedly or as a long-term maintenance tool. @@ -25,7 +25,7 @@ Each policy is presented for confirmation with options: `yes` (update this polic 1. Checks that Central is running ACS 5.0+ 2. Lists all policies and prompts for confirmation before making changes -3. For each applicable policy without an existing evaluation filter, adds `skipContainerTypes: ["INIT"]` +3. For each applicable policy without an existing evaluation filter, adds `skipContainerTypes: ["SKIP_INIT"]` 4. Skips policies that already have an evaluation filter 5. Skips build-only policies (container type filters are not applicable at build time) 6. Skips declarative (CRD-managed) policies @@ -40,5 +40,5 @@ spec: # ... existing policy fields ... evaluationFilter: skipContainerTypes: - - INIT + - SKIP_INIT ``` diff --git a/util-scripts/skip-init-container-evaluation/skip-init-container-evaluation.sh b/util-scripts/skip-init-container-evaluation/skip-init-container-evaluation.sh index d5a797a..33a7385 100755 --- a/util-scripts/skip-init-container-evaluation/skip-init-container-evaluation.sh +++ b/util-scripts/skip-init-container-evaluation/skip-init-container-evaluation.sh @@ -1,5 +1,5 @@ #!/bin/bash -# Adds skipContainerTypes: ["INIT"] to all existing policies that don't already have it. +# Adds skipContainerTypes: ["SKIP_INIT"] to all existing policies that don't already have it. # This is intended for customers upgrading to 5.0+ who want to preserve the pre-5.0 behavior # where init containers were not evaluated by policies. @@ -95,8 +95,8 @@ for id in $policies; do esac fi - # Add skipContainerTypes: ["INIT"] to the evaluation filter - updated_policy=$(echo "$policy" | jq '.evaluationFilter = {"skipContainerTypes": ["INIT"]}') + # Add skipContainerTypes: ["SKIP_INIT"] to the evaluation filter + updated_policy=$(echo "$policy" | jq '.evaluationFilter = {"skipContainerTypes": ["SKIP_INIT"]}') result=$(curl -sk -o /dev/null -w "%{http_code}" -XPUT -H "$AUTH" -H "Content-Type: application/json" \ "$API/v1/policies/$id" --data "$updated_policy")