Skip to content

Commit

Permalink
feat(plugins/k8saudit/rules) add detection for portforwarding
Browse files Browse the repository at this point in the history
  • Loading branch information
RichardoC committed Nov 15, 2023
1 parent 042f3f2 commit 458a2b5
Showing 1 changed file with 12 additions and 0 deletions.
12 changes: 12 additions & 0 deletions plugins/k8saudit/rules/k8s_audit_rules.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -298,6 +298,18 @@
source: k8s_audit
tags: [k8s]

- macro: user_known_portforward_activities
condition: (k8s_audit_never_true)

- rule: port-forward
desc: >
Detect any attempt to portforward
condition: ka.target.subresource in (portforward) and not user_known_portforward_activities
output: Portforward to pod (user=%ka.user.name pod=%ka.target.name ns=%ka.target.namespace action=%ka.target.subresource )
priority: NOTICE
source: k8s_audit
tags: [k8s]

- macro: user_known_pod_debug_activities
condition: (k8s_audit_never_true)

Expand Down

0 comments on commit 458a2b5

Please sign in to comment.