mirror of
https://github.com/falcosecurity/falco.git
synced 2025-09-25 20:30:47 +00:00
rule(macro user_known_k8s_client_container): add node-problem-detector pattern to avoid false positive
Signed-off-by: DingGGu <ggu@dunamu.com>
This commit is contained in:
@@ -2876,7 +2876,10 @@
|
|||||||
# - k8s.gcr.io/fluentd-gcp-scaler in GCP/GKE
|
# - k8s.gcr.io/fluentd-gcp-scaler in GCP/GKE
|
||||||
- macro: user_known_k8s_client_container
|
- macro: user_known_k8s_client_container
|
||||||
condition: >
|
condition: >
|
||||||
(k8s.ns.name="kube-system" and container.image.repository=k8s.gcr.io/fluentd-gcp-scaler) or
|
(k8s.ns.name="kube-system" and (
|
||||||
|
container.image.repository=k8s.gcr.io/fluentd-gcp-scaler or
|
||||||
|
container.image.repository=k8s.gcr.io/node-problem-detector/node-problem-detector
|
||||||
|
)) or
|
||||||
container.image.repository=mcr.microsoft.com/aks/hcp/hcp-tunnel-front
|
container.image.repository=mcr.microsoft.com/aks/hcp/hcp-tunnel-front
|
||||||
|
|
||||||
- macro: user_known_k8s_client_container_parens
|
- macro: user_known_k8s_client_container_parens
|
||||||
|
Reference in New Issue
Block a user