問題文
A verifyImages rule must read a pull secret that lives in the namespace of the Pod being evaluated. Which capability of Kyverno 1.18 does this rely on, and what does it require?
選択肢
- The registryCredentialHelpers flag, which resolves the credentials from the cloud provider.
- The imageRegistryCredentials secrets list, which has always accepted a namespace prefix.
- Kyverno automatically uses the pod's imagePullSecrets, and the admission and background controllers need get access to secrets in those namespaces.
- The allowInsecureRegistry flag, because reading a secret from another namespace needs a certificate.