5.2. Enabling admission controller enforcement
You can enable admission controller enforcement from the Clusters view when you install Sensor or edit an existing cluster configuration.
-
When installing a cluster by using the Operator, Helm, or
roxctlCLI methods, follow the instructions in "Installing Secured Cluster services for RHACS on Red Hat OpenShift" and "Installing Secured Cluster services for RHACS on other platforms" to enable admission controller enforcement during installation. When installing a cluster by using the legacy installation method, follow these steps:
-
In the RHACS portal, select Platform Configuration
Clusters. -
Click Secure a cluster
Legacy installation method. - In the Dynamic configuration (syncs with Sensor) section, in the Admission controller enforcement behavior field, select Enforce policies.
- Select Next.
- Select Finish. RHACS automatically synchronizes the admission controller and applies the changes.
-
In the RHACS portal, select Platform Configuration
Verification
-
The
ValidatingWebhookConfigurationKubernetes resource contains information about enforcement configuration behavior. The configuration settings are available in the admission controller logs.