rule(macro user_known_k8s_ns_kube_system_images): add new macro image name inside kube-system namespace

Signed-off-by: DingGGu <ggu@dunamu.com>
This commit is contained in:
DingGGu
2020-11-11 13:35:04 +09:00
committed by poiana
parent 0b516b7d42
commit ec5b42074e

View File

@@ -2872,20 +2872,17 @@
- list: k8s_client_binaries
items: [docker, kubectl, crictl]
- macro: user_known_k8s_ns_kube_system_images
condition: >
(
container.image.repository=k8s.gcr.io/fluentd-gcp-scaler or
container.image.repository=k8s.gcr.io/node-problem-detector/node-problem-detector
)
- list: user_known_k8s_ns_kube_system_images
items: [
k8s.gcr.io/fluentd-gcp-scaler,
k8s.gcr.io/node-problem-detector/node-problem-detector
]
# Whitelist for known docker client binaries run inside container
# - k8s.gcr.io/fluentd-gcp-scaler in GCP/GKE
- macro: user_known_k8s_client_container
condition: >
(k8s.ns.name="kube-system" and user_known_k8s_ns_kube_system_images) or
container.image.repository=mcr.microsoft.com/aks/hcp/hcp-tunnel-front
(k8s.ns.name="kube-system" and container.image.repository in (user_known_k8s_ns_kube_system_images)) or container.image.repository=mcr.microsoft.com/aks/hcp/hcp-tunnel-front
- macro: user_known_k8s_client_container_parens
condition: (user_known_k8s_client_container)