PyConChina2022-北京-用Python给Kubernetes写个自定义控制器-张晋涛dmFsdWUiOiAzfV0=" ## 其他方案 • OPA/Gatekeeper • Kyverno • Kubernetes v1.26 ValidatingAdmissionPolicy 新特性 ## OPA/Gatekeeper ## apiVersion: templates.gatekeeper.sh/v1beta1 kind: ConstraintTemplate Deploy 副本数小于等于 2 失败 ## ●●● apiVersion: admissionregistration.k8s.io/v1alpha1 2 kind: ValidatingAdmissionPolicy 3 metadata: 4 name: "demo-policy.moelove.info" 5 Spec: 6 failurePolicy: Fail 和维护成本; • OPA/Gatekeeper:简单,需要学习 Rego; • Kyverno:简单,通过 YAML 即可使用; • Kubernetes v1.26 ValidatingAdmissionPolicy 新特性:默认未开启,尚不稳定,仅能进行Validating。但属于原生特性,无需其他组件; Python 












