This repository has been archived by the owner on Oct 30, 2024. It is now read-only.
This repository has been archived by the owner on Oct 30, 2024. It is now read-only.
False positive 'CapabilityOrSecurityContextMissing' #572
Open
Description
ISSUE TYPE
- Bug Report
- Feature Idea
BUG REPORT
SUMMARY
We defined securityContext for containers in our deployments, but Kubeaudit still returns an error 'CapabilityOrSecurityContextMissing. Message: Security Context not set'.
ENVIRONMENT
- Kubeaudit version: 0.22.0
- Kubeaudit install method: Binary
STEPS TO REPRODUCE
Run kubeaudit all
EXPECTED RESULTS
Not having error 'CapabilityOrSecurityContextMissing. Message: Security Context not set'.
ACTUAL RESULTS
[error] CapabilityOrSecurityContextMissing
Message: Security Context not set. The Security Context should be specified and all Capabilities should be dropped by setting the Drop list to ALL.
ADDITIONAL INFORMATION
To debug the problem we also tried to output both pod and deployment as a yaml and run Kubeaudit on that, but still seeing an error.
SecurityContext in pod:
apiVersion: v1
kind: Pod
spec:
containers:
securityContext:
allowPrivilegeEscalation: false
runAsGroup: 100
runAsNonRoot: true
runAsUser: 1000
Metadata
Metadata
Assignees
Labels
No labels
Activity