From 3bcab69a9152970876487a780e15ae9da11e99bd Mon Sep 17 00:00:00 2001 From: Denise Schannon Date: Tue, 17 Jul 2018 10:16:28 -0700 Subject: [PATCH] moving psp stuff to editing clusters --- .../options/pod-security-policies/_index.md | 67 ------------------- 1 file changed, 67 deletions(-) diff --git a/content/rancher/v2.x/en/clusters/rke-clusters/options/pod-security-policies/_index.md b/content/rancher/v2.x/en/clusters/rke-clusters/options/pod-security-policies/_index.md index ac539555eab..c7484956135 100644 --- a/content/rancher/v2.x/en/clusters/rke-clusters/options/pod-security-policies/_index.md +++ b/content/rancher/v2.x/en/clusters/rke-clusters/options/pod-security-policies/_index.md @@ -17,70 +17,3 @@ When you create a new cluster, you can configure it to apply a PSP immediately. To enable a default Pod Security Policy, set the **Pod Security Policy Support** option to **Enabled**, and then make a selection from the **Default Pod Security Policy** drop-down. When the cluster finishes provisioning, the PSP you selected is applied to all projects within the cluster. - -For detailed instruction about assigning a PSP to a new cluster, see [Creating a Cluster]({{< baseurl >}}/rancher/v2.x/en/tasks/clusters/creating-a-cluster/). - -## Existing Cluster: Adding a Pod Security Policy - -If you don't apply a PSP as you create your cluster, you can always add one later. - ->**Prerequisite:** ->Create a Pod Security Policy within Rancher. Before you can assign a default PSP to an existing cluster, you must have a PSP available for assignment. For instruction, see [Creating Pod Security Policies]({{< baseurl >}}/rancher/v2.x/en/admin-settings/pod-security-policies/). - -1. From the **Global** view, find the cluster that you want to apply your PSP to. Select **Vertical Ellipsis (...) > Edit** for the cluster you want to enable PSPs for. - -2. Expand the **Cluster Options** accordion. - -3. From **Pod Security Policy Support**, select **Enabled**. - - >**Note:** Not all cluster providers support PSPs, so this option may not be available. - - **Step Result:** The **Default Pod Security Policy** drop-down activates. - -4. From **Default Pod Security Policy**, select the PSP you want to apply to the cluster. - -5. Click **Save**. - -**Result:** The PSP is applied to the cluster and any projects within the cluster. - ->**Note:** Any workloads that are already running in a cluster or project before a PSP is assigned will not be checked if it complies with the PSP. Workloads would need to be cloned or upgraded to see if they pass the PSP. - -## Project Creation: Adding a Pod Security Policy - -When you create a new project, you can assign a PSP directly to the project. Assigning a PSP to a project will: - -- Override the cluster's default PSP. -- Apply the PSP to the project. -- Apply the PSP to any namespaces you add to the project later. - ->**Prerequisites:** -> -> - Create a Pod Security Policy within Rancher. Before you can assign a default PSP to a new project, you must have a PSP available for assignment. For instruction, see [Creating Pod Security Policies]({{< baseurl >}}/rancher/v2.x/en/admin-settings/pod-security-policies/). -> - Assign a default Pod Security Policy to the project's cluster. You can't assign a PSP to a project until one is already applied to the cluster. For more information, see [Existing Cluster: Adding a Pod Security Policy](#existing-cluster--adding-a-pod-security-policy). - -As you create the project, make a selection from the **Pod Security Policy** drop-down to assign a PSP. - - - -## Existing Project: Adding a Pod Security Policy - -You can always assign a PSP to an existing project if you didn't assign one during creation. - ->**Prerequisites:** -> -> - Create a Pod Security Policy within Rancher. Before you can assign a default PSP to an existing project, you must have a PSP available for assignment. For instruction, see [Creating Pod Security Policies]({{< baseurl >}}/rancher/v2.x/en/admin-settings/pod-security-policies/). -> - Assign a default Pod Security Policy to the project's cluster. You can't assign a PSP to a project until one is already applied to the cluster. For more information, see [Existing Cluster: Adding a Pod Security Policy](#existing-cluster--adding-a-pod-security-policy). - -1. From the **Global** view, find the cluster containing the project you want to apply a PSP to. - -1. From the main menu, select **Projects/Namespaces**. - -3. Find the project that you want to add a PSP to. From that project, select **Vertical Ellipsis (...) > Edit**. - -4. From the **Pod Security Policy** drop-down, select the PSP you want to apply to the project. - -5. Click **Save**. - -**Result:** The PSP is applied to the project and any namespaces added to the project. - ->**Note:** Any workloads that are already running in a cluster or project before a PSP is assigned will not be checked if it complies with the PSP. Workloads would need to be cloned or upgraded to see if they pass the PSP.