apiVersion: constraints.gatekeeper.sh/v1beta1 kind: K8sDepRoleNs metadata: name: deployment-allowed-role-ns spec: match: kinds: - apiGroups: ["*"] kinds: ["Deployment"] namespaces: - "opa-test" parameters: allowedOps: ["CREATE","UPDATE"] errMsg: "INVALID_DEPLOYMENT_ROLE"