mirror of
https://github.com/falcosecurity/falco.git
synced 2025-06-26 14:52:20 +00:00
Added eks_allowed_k8s_users list to whitelist EKS users
Signed-off-by: darryk10 <stefano.chierici@sysdig.com> Co-authored-by: Alberto Pellitteri <alberto.pellitteri@sysdig.com>
This commit is contained in:
parent
1988f3b0be
commit
bcff88922a
@ -51,13 +51,24 @@
|
|||||||
cluster-autoscaler,
|
cluster-autoscaler,
|
||||||
"system:addon-manager",
|
"system:addon-manager",
|
||||||
"cloud-controller-manager",
|
"cloud-controller-manager",
|
||||||
"eks:node-manager",
|
|
||||||
"system:kube-controller-manager"
|
"system:kube-controller-manager"
|
||||||
]
|
]
|
||||||
|
|
||||||
|
- list: eks_allowed_k8s_users
|
||||||
|
items: [
|
||||||
|
"eks:node-manager",
|
||||||
|
"eks:certificate-controller",
|
||||||
|
"eks:fargate-scheduler",
|
||||||
|
"eks:k8s-metrics",
|
||||||
|
"eks:authenticator",
|
||||||
|
"eks:cluster-event-watcher",
|
||||||
|
"eks:nodewatcher",
|
||||||
|
"eks:pod-identity-mutating-webhook"
|
||||||
|
]
|
||||||
|
-
|
||||||
- rule: Disallowed K8s User
|
- rule: Disallowed K8s User
|
||||||
desc: Detect any k8s operation by users outside of an allowed set of users.
|
desc: Detect any k8s operation by users outside of an allowed set of users.
|
||||||
condition: kevt and non_system_user and not ka.user.name in (allowed_k8s_users)
|
condition: kevt and non_system_user and not ka.user.name in (allowed_k8s_users) and not ka.user.name in (eks_allowed_k8s_users)
|
||||||
output: K8s Operation performed by user not in allowed list of users (user=%ka.user.name target=%ka.target.name/%ka.target.resource verb=%ka.verb uri=%ka.uri resp=%ka.response.code)
|
output: K8s Operation performed by user not in allowed list of users (user=%ka.user.name target=%ka.target.name/%ka.target.resource verb=%ka.verb uri=%ka.uri resp=%ka.response.code)
|
||||||
priority: WARNING
|
priority: WARNING
|
||||||
source: k8s_audit
|
source: k8s_audit
|
||||||
|
Loading…
Reference in New Issue
Block a user