Closed olljanat closed 2 years ago
@olljanat thanks for creating this issue! Yes I don't see a reason why this shouldn't work as vcluster just calls the host server's api server to create any pods.
OK. Then this is most probably issue on Kyverno side. Thanks
I trying to create Kyverno policy which overwrite resource requests for all pods running vcluster namespaces (because many of them request much more than they really need).
Issue is that this policy works for pods created from host cluster but not for pods created by syncer:
What I don't understand is that why this is the case? Afaiu syncer call host cluster kube-apiserver so Kyverno running on host cluster should see those events.