UNCLASSIFIED - NO CUI

Skip to content

Kyverno ephemeral containers

Isah Yusuf requested to merge kyverno-ephemeral-containers into main

General MR

Summary

Adding block-ephemeral-containers policy and test

Relevant logs/screenshots

Link to BB MR: big-bang/bigbang!5420

Pods created in test manifests have limited permissions and cannot execute kubectl commands therefore a separate test script was created: test-ephemeral.sh

Test Script shows the policy sucessfully denies execution of kubectl debug command:

image

Linked Issue

issue

Upgrade Notices

N/A

Edited by Jasdeep Basra

Merge request reports