You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When I looked at the k8s_audit_rules.yaml of my falco deployment (uses the k8saudit-eks plugin), I noticed that there are rules that use variables which aren't defined anywhere. For example:
falco_privileged_images -> only exists inside falco_rules.yaml
falco_sensitive_mount_images -> doesn't get defined anywhere (there is only a comment about it in falco_rules.yaml)
The rules_file example of the plugin's documentation suggest that you don't mount falco_rules.yaml in the deployment.
Therefore, users cannot specify an overwrite to append items to that list.
Expected behaviour
The following commit seems to related to this problem as it tries to introduce / rename lists from falco_ to k8s_audit_.
The current version of the rules files already addresses this problem (see).
However, it looks like the k8saudit-eks plugin hasn't been updated accordingly.
Describe the bug
When I looked at the
k8s_audit_rules.yaml
of my falco deployment (uses thek8saudit-eks
plugin), I noticed that there are rules that use variables which aren't defined anywhere. For example:falco_privileged_images
-> only exists inside falco_rules.yamlfalco_sensitive_mount_images
-> doesn't get defined anywhere (there is only a comment about it in falco_rules.yaml)The
rules_file
example of the plugin's documentation suggest that you don't mountfalco_rules.yaml
in the deployment.Therefore, users cannot specify an overwrite to append items to that list.
Expected behaviour
The following commit seems to related to this problem as it tries to introduce / rename lists from
falco_
tok8s_audit_
.The current version of the rules files already addresses this problem (see).
However, it looks like the
k8saudit-eks
plugin hasn't been updated accordingly.Environment
Kubernetes via Helm Chart falco-4.3.0
The text was updated successfully, but these errors were encountered: