mirror of
https://github.com/falcosecurity/falco.git
synced 2025-06-30 16:42:14 +00:00
macro(trusted_pod): add new list k8s_image_list
Signed-off-by: kaizhe <derek0405@gmail.com>
This commit is contained in:
parent
0a600253ac
commit
e2bf87d207
@ -232,8 +232,12 @@
|
|||||||
- list: user_trusted_image_list
|
- list: user_trusted_image_list
|
||||||
items: []
|
items: []
|
||||||
|
|
||||||
|
- list: k8s_image_list
|
||||||
|
items: [k8s.gcr.io/kube-apiserver, kope/kube-apiserver-healthcheck]
|
||||||
|
|
||||||
- macro: trusted_pod
|
- macro: trusted_pod
|
||||||
condition: (ka.req.pod.containers.image.repository in (user_trusted_image_list))
|
condition: (ka.req.pod.containers.image.repository in (user_trusted_image_list) or
|
||||||
|
ka.req.pod.containers.image.repository in (k8s_image_list))
|
||||||
|
|
||||||
# Detect any new pod created in the kube-system namespace
|
# Detect any new pod created in the kube-system namespace
|
||||||
- rule: Pod Created in Kube Namespace
|
- rule: Pod Created in Kube Namespace
|
||||||
|
Loading…
Reference in New Issue
Block a user