Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions util-scripts/skip-init-container-evaluation/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Skip Init Container Evaluation

Starting in ACS 5.0, policies evaluate init containers by default. This script is a **one-time post-upgrade tool** that adds `skipContainerTypes: ["INIT"]` to all existing policies that don't already have an evaluation filter, preserving the pre-5.0 behavior where init containers were not evaluated.
Starting in ACS 5.0, policies evaluate init containers by default. This script is a **one-time post-upgrade tool** that adds `skipContainerTypes: ["SKIP_INIT"]` to all existing policies that don't already have an evaluation filter, preserving the pre-5.0 behavior where init containers were not evaluated.

This script is not intended to be run repeatedly or as a long-term maintenance tool.

Expand All @@ -25,7 +25,7 @@ Each policy is presented for confirmation with options: `yes` (update this polic

1. Checks that Central is running ACS 5.0+
2. Lists all policies and prompts for confirmation before making changes
3. For each applicable policy without an existing evaluation filter, adds `skipContainerTypes: ["INIT"]`
3. For each applicable policy without an existing evaluation filter, adds `skipContainerTypes: ["SKIP_INIT"]`
4. Skips policies that already have an evaluation filter
5. Skips build-only policies (container type filters are not applicable at build time)
6. Skips declarative (CRD-managed) policies
Expand All @@ -40,5 +40,5 @@ spec:
# ... existing policy fields ...
evaluationFilter:
skipContainerTypes:
- INIT
- SKIP_INIT
```
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
#!/bin/bash
# Adds skipContainerTypes: ["INIT"] to all existing policies that don't already have it.
# Adds skipContainerTypes: ["SKIP_INIT"] to all existing policies that don't already have it.
# This is intended for customers upgrading to 5.0+ who want to preserve the pre-5.0 behavior
# where init containers were not evaluated by policies.

Expand Down Expand Up @@ -95,8 +95,8 @@ for id in $policies; do
esac
fi

# Add skipContainerTypes: ["INIT"] to the evaluation filter
updated_policy=$(echo "$policy" | jq '.evaluationFilter = {"skipContainerTypes": ["INIT"]}')
# Add skipContainerTypes: ["SKIP_INIT"] to the evaluation filter
updated_policy=$(echo "$policy" | jq '.evaluationFilter = {"skipContainerTypes": ["SKIP_INIT"]}')

result=$(curl -sk -o /dev/null -w "%{http_code}" -XPUT -H "$AUTH" -H "Content-Type: application/json" \
"$API/v1/policies/$id" --data "$updated_policy")
Expand Down
Loading