-
Notifications
You must be signed in to change notification settings - Fork 509
Commit
updated k8s policy set and documentation
- Loading branch information
There are no files selected for viewing
Large diffs are not rendered by default.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,16 @@ | ||
{ | ||
"name": "defaultNamespaceUsed", | ||
"file": "defaultNamespaceUsed.rego", | ||
"template_args": { | ||
"generate_name": "generate_name", | ||
"name": "defaultNamespaceUsed", | ||
"prefix": "", | ||
"resource_type": "kubernetes_pod", | ||
"suffix": "" | ||
}, | ||
"severity": "LOW", | ||
"description": "The default namespace should not be used", | ||
"reference_id": "accurics.kubernetes.OPS.460", | ||
"category": "Operational Efficiency", | ||
"version": 1 | ||
} |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,16 @@ | ||
{ | ||
"name": "defaultNamespaceUsed2", | ||
"file": "defaultNamespaceUsed.rego", | ||
"template_args": { | ||
"generate_name": "generate_name", | ||
"name": "defaultNamespaceUsed2", | ||
"prefix": "", | ||
"resource_type": "kubernetes_deployment", | ||
"suffix": "" | ||
}, | ||
"severity": "LOW", | ||
"description": "The default namespace should not be used", | ||
"reference_id": "accurics.kubernetes.OPS.461", | ||
"category": "Operational Efficiency", | ||
"version": 1 | ||
} |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,16 @@ | ||
{ | ||
"name": "defaultNamespaceUsed4", | ||
"file": "defaultNamespaceUsed.rego", | ||
"template_args": { | ||
"generate_name": "generate_name", | ||
"name": "defaultNamespaceUsed4", | ||
"prefix": "", | ||
"resource_type": "kubernetes_job", | ||
"suffix": "" | ||
}, | ||
"severity": "LOW", | ||
"description": "The default namespace should not be used", | ||
"reference_id": "accurics.kubernetes.OPS.462", | ||
"category": "Operational Efficiency", | ||
"version": 1 | ||
} |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,32 @@ | ||
package accurics | ||
|
||
{{.prefix}}{{.name}}{{.suffix}}[api.id] | ||
{ | ||
api := input.{{.resource_type}}[_] | ||
metadata := api.config.metadata | ||
metadata.namespace == "default" | ||
} | ||
|
||
{{.prefix}}{{.name}}{{.suffix}}[api.id] | ||
{ | ||
api := input.{{.resource_type}}[_] | ||
metadata := api.config.metadata | ||
metadata.namespace == "" | ||
} | ||
|
||
{{.prefix}}{{.name}}{{.suffix}}[api.id] | ||
{ | ||
api := input.{{.resource_type}}[_] | ||
metadata := api.config.metadata | ||
not metadata.namespace | ||
not metadata.{{.generate_name}} | ||
} | ||
|
||
{{.prefix}}{{.name}}{{.suffix}}[api.id] | ||
{ | ||
api := input.{{.resource_type}}[_] | ||
metadata := api.config.metadata | ||
not metadata.namespace | ||
metadata.{{.generate_name}} == false | ||
} | ||
|