Added eks_allowed_k8s_users list to whitelist EKS users

Signed-off-by: darryk10 <stefano.chierici@sysdig.com>
Co-authored-by: Alberto Pellitteri <alberto.pellitteri@sysdig.com>
This commit is contained in:
Stefano 2022-03-25 10:34:47 +01:00 committed by poiana
parent 1988f3b0be
commit bcff88922a

View File

@ -51,13 +51,24 @@
cluster-autoscaler, cluster-autoscaler,
"system:addon-manager", "system:addon-manager",
"cloud-controller-manager", "cloud-controller-manager",
"eks:node-manager",
"system:kube-controller-manager" "system:kube-controller-manager"
] ]
- list: eks_allowed_k8s_users
items: [
"eks:node-manager",
"eks:certificate-controller",
"eks:fargate-scheduler",
"eks:k8s-metrics",
"eks:authenticator",
"eks:cluster-event-watcher",
"eks:nodewatcher",
"eks:pod-identity-mutating-webhook"
]
-
- rule: Disallowed K8s User - rule: Disallowed K8s User
desc: Detect any k8s operation by users outside of an allowed set of users. desc: Detect any k8s operation by users outside of an allowed set of users.
condition: kevt and non_system_user and not ka.user.name in (allowed_k8s_users) condition: kevt and non_system_user and not ka.user.name in (allowed_k8s_users) and not ka.user.name in (eks_allowed_k8s_users)
output: K8s Operation performed by user not in allowed list of users (user=%ka.user.name target=%ka.target.name/%ka.target.resource verb=%ka.verb uri=%ka.uri resp=%ka.response.code) output: K8s Operation performed by user not in allowed list of users (user=%ka.user.name target=%ka.target.name/%ka.target.resource verb=%ka.verb uri=%ka.uri resp=%ka.response.code)
priority: WARNING priority: WARNING
source: k8s_audit source: k8s_audit