kh: improve mount on /var/lib/kubelet rule (#509)

This commit is contained in:
Kaizhe Huang
2019-01-30 14:13:19 -08:00
committed by Mark Stemm
parent 9e0e3da617
commit 50c6515da5

View File

@@ -1428,7 +1428,8 @@
- macro: sensitive_mount
condition: (container.mount.dest[/proc*] != "N/A" or
container.mount.dest[/var/run/docker.sock] != "N/A" or
container.mount.dest[/var/lib/kubelet*] != "N/A" or
container.mount.dest[/var/lib/kubelet] != "N/A" or
container.mount.dest[/var/lib/kubelet/pki] != "N/A" or
container.mount.dest[/] != "N/A" or
container.mount.dest[/etc] != "N/A" or
container.mount.dest[/root*] != "N/A")