document default namespace policy scope
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m12s
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m12s
This commit is contained in:
@@ -20,6 +20,13 @@ existing objects.
|
||||
| `disallow-default-namespace` | Supplemental | Blocks common application resources from being created in `default`, which makes namespace ownership explicit. |
|
||||
| `disallow-host-network` | 5.2.3 and 5.2.5 | Rejects host PID, host network, and host IPC access. |
|
||||
|
||||
The default-namespace policy intentionally excludes ConfigMaps and Secrets.
|
||||
Those objects are supporting data, not application entrypoints, and blocking
|
||||
them alone would not prevent a workload from being installed. Keeping them out
|
||||
also avoids adding broad read permissions for Secret data to Kyverno's reports
|
||||
controller. Applications should create these objects in the same explicitly
|
||||
named namespace as the workloads that consume them.
|
||||
|
||||
The CIS benchmark includes manual checks and platform-specific exceptions.
|
||||
The mapping above describes the control objective each policy supports, not a
|
||||
claim that one Kyverno rule implements the entire benchmark control.
|
||||
|
||||
Reference in New Issue
Block a user