mirror of
https://github.com/falcosecurity/falco.git
synced 2025-07-01 00:52:16 +00:00
Introduce missing allowed_full_admin_users macro so its corresponding rule is disabled by default
Signed-off-by: Vicente Herrera <vicenteherrera@vicenteherrera.com>
This commit is contained in:
parent
3ce11f093f
commit
9fd08ce3e4
@ -420,6 +420,10 @@
|
|||||||
tags: [k8s]
|
tags: [k8s]
|
||||||
|
|
||||||
|
|
||||||
|
# This macro disables following rule, change to k8s_audit_never_true to enable it
|
||||||
|
- macro: allowed_full_admin_users
|
||||||
|
condition: (k8s_audit_always_true)
|
||||||
|
|
||||||
# This list includes some of the default user names for an administrator in several K8s installations
|
# This list includes some of the default user names for an administrator in several K8s installations
|
||||||
- list: full_admin_k8s_users
|
- list: full_admin_k8s_users
|
||||||
items: ["admin", "kubernetes-admin", "kubernetes-admin@kubernetes", "kubernetes-admin@cluster.local", "minikube-user"]
|
items: ["admin", "kubernetes-admin", "kubernetes-admin@kubernetes", "kubernetes-admin@cluster.local", "minikube-user"]
|
||||||
|
Loading…
Reference in New Issue
Block a user