1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-09 09:26:54 +00:00
kyverno/samples/best_practices/disallow_hostpid_hostipc.yaml

25 lines
864 B
YAML
Raw Normal View History

apiVersion: kyverno.io/v1alpha1
kind: ClusterPolicy
metadata:
2019-11-07 19:03:09 -08:00
name: validate-host-pid-ipc
2019-10-11 18:57:16 -07:00
annotations:
policies.kyverno.io/category: Security
2019-10-14 16:33:19 -07:00
policies.kyverno.io/description: Sharing the host's PID namespace allows visibility of process
on the host, potentially exposing process information. Sharing the host's IPC namespace allows
the container process to communicate with processes on the host. To avoid pod container from
having visibility to host process space, validate that 'hostPID' and 'hostIPC' are set to 'false'.
spec:
validationFailureAction: audit
rules:
2019-11-07 19:03:09 -08:00
- name: validate-host-pid-ipc
match:
resources:
kinds:
- Pod
validate:
2019-11-07 19:03:09 -08:00
message: "Use of host PID and IPC namespaces is not allowed"
pattern:
spec:
2019-11-07 19:03:09 -08:00
=(hostPID): "false"
=(hostIPC): "false"