Documentation
| Article | Path |
|---|---|
| Review effective AppArmor protection for containers | terraform/kubernetes/missing_app_armor_config |
| Review container CPU limits | terraform/kubernetes/cpu_limits_not_set |
| Review container CPU requests | terraform/kubernetes/cpu_requests_not_set |
| Container shares the host PID namespace | terraform/kubernetes/container_host_pid_is_true |
| Review container resource requests and limits | terraform/kubernetes/container_resources_limits_undefined |
| Review added Linux capabilities in containers | terraform/kubernetes/container_with_added_capabilities |
| Review CronJob start deadlines | terraform/kubernetes/cronjob_deadline_not_configured |
| Review Deployment pod placement | terraform/kubernetes/deployment_has_no_pod_anti_affinity |
| Review the Deployment PodDisruptionBudget | terraform/kubernetes/deployment_without_pod_disruption_budget |
| Review container access to the Docker daemon socket | terraform/kubernetes/docker_daemon_socket_is_exposed_to_containers |
| Review HPA Object metric references | terraform/kubernetes/hpa_targets_invalid_object |
| Kubernetes PodSecurityPolicy permits host IPC sharing | terraform/kubernetes/psp_allows_sharing_host_ipc |
| Pod shares the host IPC namespace | terraform/kubernetes/shared_host_ipc_namespace |
| Kubernetes PodSecurityPolicy permits host network sharing | terraform/kubernetes/psp_allows_containers_to_share_the_host_network_namespace |
| Pod shares the host network namespace | terraform/kubernetes/shared_host_network_namespace |
| Review workload exposure through Kubernetes Ingress | terraform/kubernetes/ingress_controller_exposes_workload |
| Review container memory limits | terraform/kubernetes/memory_limits_not_defined |
| Review container memory requests | terraform/kubernetes/memory_requests_not_defined |
| Review removal of NET_RAW from containers | terraform/kubernetes/net_raw_capabilities_not_being_dropped |
| Review policy requirements to drop NET_RAW | terraform/kubernetes/net_raw_capabilities_disabled_for_psp |
| Review Pod and container security contexts | terraform/kubernetes/pod_or_container_without_security_context |
| Pod-creation permissions are too broad | terraform/kubernetes/permissive_access_to_create_pods |
| Review NetworkPolicy pod selection | terraform/kubernetes/network_policy_is_not_targeting_any_pod |
| Kubernetes PodSecurityPolicy permits privilege escalation | terraform/kubernetes/psp_allows_privilege_escalation |
| Privilege escalation allowed in a Kubernetes container | terraform/kubernetes/privilege_escalation_allowed |
| Kubernetes container runs in privileged mode | terraform/kubernetes/container_is_privileged |
| Kubernetes PodSecurityPolicy permits privileged execution | terraform/kubernetes/psp_set_to_privileged |
| Review container readiness probes | terraform/kubernetes/readiness_probe_is_not_configured |
| Review policies allowing containers to run as root | terraform/kubernetes/root_containers_admitted |
| SYS_ADMIN capability added to a Kubernetes container | terraform/kubernetes/containers_with_sys_admin_capabilities |
| Review container seccomp profiles | terraform/kubernetes/secoomp_profile_is_not_configured |
| Review exposure of Secrets in environment variables | terraform/kubernetes/secrets_as_environment_variables |
| RBAC Role has Secret-read permissions | terraform/kubernetes/rbac_roles_with_read_secrets_permissions |
| Review ServiceAccount sharing | terraform/kubernetes/shared_service_account |
| ServiceAccount name is not specified | terraform/kubernetes/service_account_name_undefined_or_empty |
| Review ServiceAccount token automounting | terraform/kubernetes/service_account_token_automount_not_disabled |
| Review ServiceAccount access to Secrets | terraform/kubernetes/service_account_allows_access_secrets |
| Review Kubernetes NodePort access scope | terraform/kubernetes/service_type_is_nodeport |
| Review the StatefulSet headless Service association | terraform/kubernetes/statefulset_without_service_name |
| Review the StatefulSet PodDisruptionBudget | terraform/kubernetes/statefulset_without_pod_disruption_budget |
| Review StatefulSet persistent-storage requirements | terraform/kubernetes/statefulset_requests_storage |
| Tiller (Helm v2) deployed in a Kubernetes environment | terraform/kubernetes/tiller_is_deployed |
| Kubernetes security policy permits Unmasked proc mounts | terraform/kubernetes/container_runs_unmasked |
| Kubernetes configuration permits unsafe sysctls | terraform/kubernetes/cluster_allows_unsafe_sysctls |
| Review whether workload host_port is needed | terraform/kubernetes/workload_host_port_not_specified |
| Review cluster-admin ClusterRoleBinding permissions | terraform/kubernetes/cluster_admin_role_binding_with_super_user_permissions |
| Review the need for container liveness probes | terraform/kubernetes/liveness_probe_is_not_defined |
| Review use of the Kubernetes default namespace | terraform/kubernetes/using_default_namespace |
| Review default ServiceAccount permissions and token automounting | terraform/kubernetes/default_service_account_in_use |
| RoleBinding targets the default ServiceAccount | terraform/kubernetes/role_binding_to_default_service_account |
| Kubernetes workload uses sensitive host directories | terraform/kubernetes/workload_mounting_with_sensitive_os_directory |
| Review protection of Kubernetes OS directory mounts | terraform/kubernetes/volume_mount_with_os_directory_write_permissions |
| Review exposure of Kubernetes LoadBalancer Services | terraform/kubernetes/service_with_external_load_balancer |
| Review container image digest pinning | terraform/kubernetes/image_without_digest |
| Review hostPath use in ordinary Kubernetes workloads | terraform/kubernetes/non_kube_system_pod_with_host_mount |
| Review volume claim access modes | terraform/kubernetes/incorrect_volume_claim_access_mode_read_write_once |
| Review Kubernetes metadata label syntax | terraform/kubernetes/metadata_label_is_invalid |
| Review container image references | terraform/kubernetes/invalid_image |
| Kubernetes PodSecurityPolicy permits additional capabilities | terraform/kubernetes/psp_with_added_capabilities |
| Review Linux capability reduction for containers | terraform/kubernetes/no_drop_capabilities_for_containers |
| Review container image pull policies | terraform/kubernetes/image_pull_policy_of_container_is_not_always |
| Review container root filesystem write protection | terraform/kubernetes/root_container_not_mounted_as_read_only |