UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects
Commit 444e8b6e authored by Micah Nagel's avatar Micah Nagel
Browse files

Merge branch 'Twistlock-14-UpdateTwistlock-IstioSidecar' into 'master'

Add exemption note for hostNetworking gatekeeper-TL

See merge request platform-one/big-bang/bigbang!954
parents 313df0bb bcb7d90a
No related branches found
No related tags found
1 merge request!954Add exemption note for hostNetworking gatekeeper-TL
Pipeline #513098 passed
......@@ -55,6 +55,10 @@ violations: # Try to keep this in alpha order to make it easier to find keys
hostNetworking:
parameters:
excludedResources:
# Twistlock, by default, does its own network monitoring. hostNetworking is enabled by default for this purpose
# With hostNetworking enabled, Istio sidecar injection is disabled. If this function is disabled, Twistlock wil
# not be able to self monitor. If both Istio sidecar injection and TL monitoring are disabled, a security gap will
# be created for network monitoring in Twistlock, so it is important to make sure at least one is enabled.
- twistlock/twistlock-defender-ds-.*
noHostNamespace:
parameters:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment