Policy Examples for Nodes/VMs
apiVersion: security.kubearmor.com/v1 kind: KubeArmorHostPolicy metadata: name: hsp-kubearmor-dev-proc-path-block spec: nodeSelector: matchLabels: kubernetes.io/hostname: kubearmor-dev severity: 5 process: matchPaths: - path: /usr/bin/diff action: Block
apiVersion: security.kubearmor.com/v1 kind: KubeArmorHostPolicy metadata: name: hsp-kubearmor-dev-file-path-audit spec: nodeSelector: matchLabels: kubernetes.io/hostname: kubearmor-dev severity: 5 file: matchPaths: - path: /etc/passwd action: Audit
apiVersion: security.kubearmor.com/v1 kind: KubeArmorHostPolicy metadata: name: audit-all-unlink spec: severity: 3 nodeSelector: matchLabels: kubernetes.io/hostname: vagrant syscalls: matchSyscalls: - syscall: - unlink action: Audit
Last updated
Was this helpful?