Skip to content

Conversation

@sysdig-aws-us-1
Copy link

Sysdig opened the pull request on behalf of Andrea Vivaldi.

Sysdig analysis found violations for workload "observer"

The PR includes remediations for the following attributes: "SecurityContext.ReadOnlyRootFileSystem"


Remediated Attribute: "SecurityContext.ReadOnlyRootFileSystem"
  • Severity: 🔴 High
  • Source:
    • Container: observer
  • Violated Control:
    • Container with writable root file system
      A container with writable root filesystem is more exposed to attacks as it allows tampering with executables
  • Change Impact: The container will not be able to modify the root file system of the container.

The following policy requirements applied to this resource include the above control:

Requirement Policy
1.2 - Immutable container filesystem Sysdig Kubernetes

…ystem" for control "Container with writable root file system"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant