document default namespace policy scope
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m12s
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m12s
This commit is contained in:
@@ -20,6 +20,13 @@ existing objects.
|
|||||||
| `disallow-default-namespace` | Supplemental | Blocks common application resources from being created in `default`, which makes namespace ownership explicit. |
|
| `disallow-default-namespace` | Supplemental | Blocks common application resources from being created in `default`, which makes namespace ownership explicit. |
|
||||||
| `disallow-host-network` | 5.2.3 and 5.2.5 | Rejects host PID, host network, and host IPC access. |
|
| `disallow-host-network` | 5.2.3 and 5.2.5 | Rejects host PID, host network, and host IPC access. |
|
||||||
|
|
||||||
|
The default-namespace policy intentionally excludes ConfigMaps and Secrets.
|
||||||
|
Those objects are supporting data, not application entrypoints, and blocking
|
||||||
|
them alone would not prevent a workload from being installed. Keeping them out
|
||||||
|
also avoids adding broad read permissions for Secret data to Kyverno's reports
|
||||||
|
controller. Applications should create these objects in the same explicitly
|
||||||
|
named namespace as the workloads that consume them.
|
||||||
|
|
||||||
The CIS benchmark includes manual checks and platform-specific exceptions.
|
The CIS benchmark includes manual checks and platform-specific exceptions.
|
||||||
The mapping above describes the control objective each policy supports, not a
|
The mapping above describes the control objective each policy supports, not a
|
||||||
claim that one Kyverno rule implements the entire benchmark control.
|
claim that one Kyverno rule implements the entire benchmark control.
|
||||||
|
|||||||
@@ -8,6 +8,9 @@ metadata:
|
|||||||
policies.kyverno.io/severity: medium
|
policies.kyverno.io/severity: medium
|
||||||
# Supplemental namespace-isolation control. This is not a one-to-one CIS control.
|
# Supplemental namespace-isolation control. This is not a one-to-one CIS control.
|
||||||
policies.kyverno.io/cis-control: "supplemental"
|
policies.kyverno.io/cis-control: "supplemental"
|
||||||
|
# ConfigMaps and Secrets are intentionally excluded. They are supporting
|
||||||
|
# data rather than application entrypoints, and matching Secrets would also
|
||||||
|
# require broader Kyverno reports-controller read permissions.
|
||||||
spec:
|
spec:
|
||||||
validationFailureAction: Enforce
|
validationFailureAction: Enforce
|
||||||
background: false
|
background: false
|
||||||
|
|||||||
Reference in New Issue
Block a user