You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A end user brought this up at KubeCon EU 2024. A number of sample policies target containers in a pod, but do not handle initContainers and ephemeralContainers.
Note that this is not an issue for any Pod Security Standard related policies, but applies to best practices and other security samples.
However, this may be something end users are oblivious of and hence end up using the sample policy which leaves a potential gap.
This can be handled easily as done in the following policy:
Kyverno Version
1.12
Kubernetes Version
1.29
Kubernetes Platform
Minikube
Description
A end user brought this up at KubeCon EU 2024. A number of sample policies target containers in a pod, but do not handle initContainers and ephemeralContainers.
Note that this is not an issue for any Pod Security Standard related policies, but applies to best practices and other security samples.
However, this may be something end users are oblivious of and hence end up using the sample policy which leaves a potential gap.
This can be handled easily as done in the following policy:
https://kyverno.io/policies/psp-migration/restrict-adding-capabilities/restrict-adding-capabilities/
Here is a list of some of these policies:
Steps to reproduce
Expected behavior
Screenshots
No response
Kyverno logs
No response
Slack discussion
No response
Troubleshooting
The text was updated successfully, but these errors were encountered: