mirror of
https://github.com/falcosecurity/falco.git
synced 2025-09-23 02:47:25 +00:00
rule(Disallowed K8s User): whitelist kube-apiserver-healthcheck
kops 1.17 adds a kube-apiserver-healthcheck user: https://github.com/kubernetes/kops/tree/master/cmd/kube-apiserver-healthcheck Logs are currently spammed with: ``` {"output":"18:02:15.466580992: Warning K8s Operation performed by user not in allowed list of users (user=kube-apiserver-healthcheck target=<NA>/<NA> verb=get uri=/healthz resp=200)","priority":"Warning","rule":"Disallowed K8s User","time":"2020-06-29T18:02:15.466580992Z", "output_fields": {"jevt.time":"18:02:15.466580992","ka.response.code":"200","ka.target.name":"<NA>","ka.target.resource":"<NA>","ka.uri":"/healthz","ka.user.name":"kube-apiserver-healthcheck","ka.verb":"get"}} ``` Signed-off-by: Antoine Deschênes <antoine.deschenes@equisoft.com>
This commit is contained in:
committed by
poiana
parent
9eb0b7fb5f
commit
a5cadbf5fa
@@ -45,7 +45,7 @@
|
||||
|
||||
- list: allowed_k8s_users
|
||||
items: [
|
||||
"minikube", "minikube-user", "kubelet", "kops", "admin", "kube", "kube-proxy",
|
||||
"minikube", "minikube-user", "kubelet", "kops", "admin", "kube", "kube-proxy", "kube-apiserver-healthcheck",
|
||||
vertical_pod_autoscaler_users,
|
||||
]
|
||||
|
||||
|
Reference in New Issue
Block a user