Skip to content

Improvement: CIS-5.7.4 The default namespace should not be used #644

Open
@ad-zsolt-imre

Description

@ad-zsolt-imre

Overview

I've go a report: CIS-5.7.4 The default namespace should not be used. It is highlighting that the kubernetes Endpoint is in the default namespace. There are no other Endpoints in the default namespace. If I'm not mistaken the related rule impl is in rules/endpoints-in-default-namespace/raw.rego.

Problem

I did some research and found that the kubernetes Endpoint is acceptable to be in the default namespace. See screenshot of the CIS benchmark below.

Screenshot 2024-12-07 at 18 04 51

Solution

I'm probably not familiar with all the frameworks you are supporting, but, it the above mentioned rule is simply based on CIS (as indicated by the title) it would be great to have it updated to ignore the kubernetes endpoint in the default namespace.

Alternatives

N/A

Additional context

N/A

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

  • Status

    Accepted

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions