Policy Controller
E697174
Policy Controller is a Kubernetes policy management and enforcement component used in Anthos to ensure cluster configurations comply with defined security and governance rules.
Statements (50)
| Predicate | Object |
|---|---|
| instanceOf |
Anthos component
ⓘ
Kubernetes policy management component ⓘ configuration policy enforcement tool ⓘ |
| appliesTo |
Anthos clusters
NERFINISHED
ⓘ
Kubernetes clusters ⓘ |
| basedOn | Open Policy Agent Gatekeeper NERFINISHED ⓘ |
| canAudit | existing cluster resources ⓘ |
| canDeny |
non-compliant resource creations
ⓘ
non-compliant resource updates ⓘ |
| configurationLanguage | Rego NERFINISHED ⓘ |
| deployedAs | pods in the cluster ⓘ |
| developedBy | Google NERFINISHED ⓘ |
| documentationURL | https://cloud.google.com/anthos-config-management/docs/concepts/policy-controller ⓘ |
| enforces |
governance standards
ⓘ
organizational compliance requirements ⓘ policy constraints at admission time ⓘ security best practices ⓘ |
| ensures |
cluster configurations comply with defined policies
ⓘ
cluster configurations comply with governance rules ⓘ cluster configurations comply with security rules ⓘ |
| goal |
centralize policy management
ⓘ
improve security posture ⓘ reduce configuration drift ⓘ |
| integratesWith |
Anthos Config Management
NERFINISHED
ⓘ
Google Cloud console NERFINISHED ⓘ Kubernetes admission webhooks NERFINISHED ⓘ |
| monitors | Kubernetes resource configurations ⓘ |
| partOf | Anthos Config Management suite NERFINISHED ⓘ |
| platform | Google Cloud NERFINISHED ⓘ |
| runsAs | Kubernetes controllers ⓘ |
| scope |
cluster-wide policies
ⓘ
namespace-level policies ⓘ |
| supports |
audit of existing resources
ⓘ
constraint templates ⓘ constraints ⓘ custom policies ⓘ dry-run policy evaluation ⓘ hierarchical policy inheritance ⓘ multi-cluster policy management ⓘ mutating admission control ⓘ policy bundles ⓘ predefined security policies ⓘ validating admission control ⓘ |
| supportsEnvironment |
multi-cloud Kubernetes clusters
ⓘ
on-premises Kubernetes clusters ⓘ |
| usedFor |
Kubernetes policy management
ⓘ
compliance enforcement ⓘ policy enforcement ⓘ security governance enforcement ⓘ |
| usedIn | Anthos NERFINISHED ⓘ |
Referenced by (1)
Full triples — surface form annotated when it differs from this entity's canonical label.