問題文
A mutate existing rule fires but the target is never updated, and the trigger resource does change. Which cause does the documentation name first?
選択肢
- The rule must set mutateExistingOnPolicyUpdate to true, because without it the rule is never evaluated at all and the trigger therefore has no effect.
- The mutation is applied only on the next background scan interval.
- The target must be in the same namespace as the trigger, because a cross-namespace mutation is only possible through a generate rule and the target selector silently resolves to nothing otherwise.
- Custom permissions are almost always required, and Kyverno validates them when the policy is installed.