diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index 4b0ad5fc..e5a11001 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -1838,8 +1838,8 @@ container.mount.dest[/] != "N/A" or container.mount.dest[/home/admin] != "N/A" or container.mount.dest[/etc] != "N/A" or - container.mount.dest[/etc/kubernetes] != "N/A" or # static pod path - container.mount.dest[/etc/kubernetes/manifests] != "N/A" or # static pod path + container.mount.dest[/etc/kubernetes] != "N/A" or + container.mount.dest[/etc/kubernetes/manifests] != "N/A" or container.mount.dest[/root*] != "N/A") # The steps libcontainer performs to set up the root program for a container are: diff --git a/rules/k8s_audit_rules.yaml b/rules/k8s_audit_rules.yaml index 82a0b585..c7f8acea 100644 --- a/rules/k8s_audit_rules.yaml +++ b/rules/k8s_audit_rules.yaml @@ -1,3 +1,4 @@ +# # Copyright (C) 2019 The Falco Authors. # #