diff --git a/kubescape-reports/cis-v1.23-t1.0.1.html b/kubescape-reports/cis-v1.23-t1.0.1.html index 9eb54874..8aa1618e 100644 --- a/kubescape-reports/cis-v1.23-t1.0.1.html +++ b/kubescape-reports/cis-v1.23-t1.0.1.html @@ -320,10 +320,10 @@
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -recruit-postgres
+ApiVersion: v1
+Kind: Pod
+Name: -gateway-vfps-test-connection
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true spec.template.spec.containers[0].securityContext.runAsGroup=1000 spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+
+
ApiVersion: v1
+Kind: Pod
+Name: -vfps-test-connection
+Namespace:
+Medium | -CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | -C-0207 | - spec.template.spec.containers[0].env[4].name |
+ Severity | +Name | +Docs | +Assisted Remediation | +
---|---|---|---|---|---|---|---|
High | +CIS-5.7.3 Apply Security Context to Your Pods and Containers | +C-0211 | + spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -ohdsi-postgres
+ApiVersion: batch/v1
+Kind: Job
+Name: -vfps-migrations-v1-3-6
Namespace:
High | +CIS-5.7.3 Apply Security Context to Your Pods and Containers | +C-0211 | + spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ |
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[0].env[4].name |
+ spec.template.spec.containers[0].env[3].name |
ApiVersion: v1
-Kind: ServiceAccount
-Name: -mailhog
+Kind: Pod
+Name: -ohdsi-test-connection
Namespace:
Medium | -CIS-5.1.6 Ensure that Service Account Tokens are only mounted where necessary | -C-0190 | - automountServiceAccountToken=false |
+ High | +CIS-5.7.3 Apply Security Context to Your Pods and Containers | +C-0211 | + spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: apps/v1
Kind: StatefulSet
-Name: -vfps-postgres
+Name: -datashield-rock
Namespace:
High | +CIS-5.7.3 Apply Security Context to Your Pods and Containers | +C-0211 | + spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ |
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[0].env[4].name |
+ spec.template.spec.containers[2].env[4].name spec.template.spec.containers[2].env[6].name spec.template.spec.containers[2].env[8].name |
ApiVersion: v1
-Kind: Pod
-Name: -blaze-test-connection
+ApiVersion: apps/v1
+Kind: StatefulSet
+Name: -postgresql
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.runAsGroup=1000 |
+
+
+
Medium | +CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | +C-0207 | + spec.template.spec.containers[0].env[4].name |
ApiVersion: v1
-Kind: Pod
-Name: -recruit-test-health-probes
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -fhir-gateway-gateway
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+
+
+
Medium | +CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | +C-0207 | + spec.template.spec.containers[0].env[3].name |
ApiVersion: apps/v1
Kind: Deployment
-Name: -recruit-notify
+Name: -vfps
Namespace:
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[0].env[7].name |
+ spec.template.spec.containers[0].env[3].name |
ApiVersion: apps/v1
Kind: StatefulSet
-Name: -datashield-opal
+Name: -postgresql
Namespace:
High | -CIS-5.7.3 Apply Security Context to Your Pods and Containers | -C-0211 | - spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
- |
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[2].env[12].name spec.template.spec.containers[2].env[16].name spec.template.spec.containers[2].env[1].name spec.template.spec.containers[2].env[4].name spec.template.spec.containers[2].env[6].name spec.template.spec.containers[2].env[8].name |
+ spec.template.spec.containers[0].env[4].name |
ApiVersion: v1
Kind: Pod
-Name: -fhir-gateway-test-connection
+Name: -vfps-test-connection
Namespace:
ApiVersion: batch/v1
-Kind: Job
-Name: -vfps-migrations-v1-3-6
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -fhir-gateway-loinc-converter
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+
+
+
+
ApiVersion: apps/v1
+Kind: Deployment
+Name: -mailhog
+Namespace:
+Severity | +Name | +Docs | +Assisted Remediation | ||||
---|---|---|---|---|---|---|---|
Medium | -CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | -C-0207 | - spec.template.spec.containers[0].env[3].name |
+ High | +CIS-5.7.3 Apply Security Context to Your Pods and Containers | +C-0211 | + spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: apps/v1
Kind: Deployment
-Name: -fhir-gateway-gateway
+Name: -vfps
Namespace:
ApiVersion: apps/v1
-Kind: Deployment
-Name: -vfps
+Kind: StatefulSet
+Name: -datashield-opal
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[0].env[3].name |
+ spec.template.spec.containers[2].env[12].name spec.template.spec.containers[2].env[16].name spec.template.spec.containers[2].env[1].name spec.template.spec.containers[2].env[4].name spec.template.spec.containers[2].env[6].name spec.template.spec.containers[2].env[8].name |
ApiVersion: apps/v1
Kind: StatefulSet
-Name: -postgresql
+Name: -recruit-postgres
Namespace:
High | +CIS-5.7.3 Apply Security Context to Your Pods and Containers | +C-0211 | + spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true spec.template.spec.containers[0].securityContext.runAsGroup=1000 spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | @@ -767,10 +835,10 @@
ApiVersion: v1
-Kind: Pod
-Name: -vfps-test-connection
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -ohdsi-atlas
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: v1
Kind: Pod
-Name: -datashield-test-connection
+Name: -fhir-pseudonymizer-test-connection
Namespace:
ApiVersion: apps/v1
Kind: Deployment
-Name: -fhir-pseudonymizer
+Name: -recruit-notify
Namespace:
spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ |||
Medium | +CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | +C-0207 | + spec.template.spec.containers[0].env[7].name |
+
ApiVersion: apps/v1
Kind: Deployment
-Name: -fhir-pseudonymizer
+Name: -gateway-vfps
Namespace:
spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ |||
Medium | +CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | +C-0207 | + spec.template.spec.containers[0].env[3].name |
+
ApiVersion: apps/v1
-Kind: Deployment
-Name: -fhir-gateway-loinc-converter
+ApiVersion: v1
+Kind: Pod
+Name: -hapi-fhir-jpaserver-test-endpoints
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: batch/v1
-Kind: Job
-Name: -vfps-migrations-v1-3-5
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -ohdsi-webapi
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[0].env[3].name |
+ spec.template.spec.containers[0].env[14].name spec.template.spec.containers[0].env[4].name |
ApiVersion: v1
Kind: Pod
-Name: -fhir-pseudonymizer-test-connection
+Name: -blaze-test-connection
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: apps/v1
-Kind: Deployment
-Name: -recruit-query
+Kind: StatefulSet
+Name: -postgresql
Namespace:
High | -CIS-5.7.3 Apply Security Context to Your Pods and Containers | -C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
- |
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[0].env[3].name |
+ spec.template.spec.containers[0].env[4].name |
ApiVersion: v1
-Kind: Pod
-Name: -vfps-test-connection
+ApiVersion: apps/v1
+Kind: StatefulSet
+Name: -blaze
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: v1
-Kind: Pod
-Name: -gateway-vfps-test-connection
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -fhir-pseudonymizer
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: apps/v1
-Kind: Deployment
-Name: -vfps
+ApiVersion: batch/v1
+Kind: Job
+Name: -vfps-migrations-v1-3-5
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: apps/v1
Kind: Deployment
-Name: -gateway-vfps
+Name: -hapi-fhir-jpaserver
Namespace:
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[0].env[3].name |
+ spec.template.spec.containers[0].env[2].name |
ApiVersion: apps/v1
Kind: Deployment
-Name: -ohdsi-atlas
+Name: -vfps
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+
+
+
Medium | +CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | +C-0207 | + spec.template.spec.containers[0].env[3].name |
ApiVersion: v1
-Kind: Pod
-Name: -ohdsi-test-connection
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -fhir-pseudonymizer
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -postgresql
+ApiVersion: v1
+Kind: Pod
+Name: -recruit-test-health-probes
Namespace:
Medium | -CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | -C-0207 | - spec.template.spec.containers[0].env[4].name |
+ High | +CIS-5.7.3 Apply Security Context to Your Pods and Containers | +C-0211 | + spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: batch/v1
Kind: Job
-Name: -gateway-vfps-migrations-v1-3-5
+Name: -vfps-migrations-v1-3-6
Namespace:
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -datashield-rock
+ApiVersion: v1
+Kind: Pod
+Name: -fhir-gateway-test-connection
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
-
-
- |
Medium | -CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | -C-0207 | - spec.template.spec.containers[2].env[4].name spec.template.spec.containers[2].env[6].name spec.template.spec.containers[2].env[8].name |
+ spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: apps/v1
Kind: StatefulSet
-Name: -postgresql
+Name: -vfps-postgres
Namespace:
High | -CIS-5.7.3 Apply Security Context to Your Pods and Containers | -C-0211 | - spec.template.spec.containers[0].securityContext.runAsGroup=1000 |
-
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | @@ -1302,10 +1370,10 @@
ApiVersion: apps/v1
Kind: Deployment
-Name: -vfps
+Name: -recruit-query
Namespace:
ApiVersion: apps/v1
Kind: Deployment
-Name: -ohdsi-webapi
+Name: -fhir-pseudonymizer
Namespace:
spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
- |||
Medium | -CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | -C-0207 | - spec.template.spec.containers[0].env[14].name spec.template.spec.containers[0].env[4].name |
-
ApiVersion: v1
Kind: Pod
-Name: -fhir-pseudonymizer-test-connection
+Name: -vfps-test-connection
Namespace:
ApiVersion: apps/v1
-Kind: Deployment
-Name: -mailhog
-Namespace:
-Severity | -Name | -Docs | -Assisted Remediation | -
---|---|---|---|
High | -CIS-5.7.3 Apply Security Context to Your Pods and Containers | -C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
-
ApiVersion: batch/v1
-Kind: Job
-Name: -vfps-migrations-v1-3-6
+Kind: StatefulSet
+Name: -postgresql
Namespace:
High | -CIS-5.7.3 Apply Security Context to Your Pods and Containers | -C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
-
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[0].env[3].name |
-
ApiVersion: v1
-Kind: Pod
-Name: -hapi-fhir-jpaserver-test-endpoints
-Namespace:
-Severity | -Name | -Docs | -Assisted Remediation | -|
---|---|---|---|---|
High | -CIS-5.7.3 Apply Security Context to Your Pods and Containers | -C-0211 | - spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].env[4].name |
ApiVersion: v1
Kind: Pod
-Name: -vfps-test-connection
+Name: -fhir-pseudonymizer-test-connection
Namespace:
ApiVersion: apps/v1
-Kind: Deployment
-Name: -hapi-fhir-jpaserver
+ApiVersion: batch/v1
+Kind: Job
+Name: -gateway-vfps-migrations-v1-3-5
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
Medium | CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | C-0207 | - spec.template.spec.containers[0].env[2].name |
+ spec.template.spec.containers[0].env[3].name |
ApiVersion: apps/v1
-Kind: Deployment
-Name: -fhir-pseudonymizer
+ApiVersion: v1
+Kind: ServiceAccount
+Name: -mailhog
Namespace:
High | -CIS-5.7.3 Apply Security Context to Your Pods and Containers | -C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroup=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ Medium | +CIS-5.1.6 Ensure that Service Account Tokens are only mounted where necessary | +C-0190 | + automountServiceAccountToken=false |
ApiVersion: v1
-Kind: Pod
-Name: -fhir-pseudonymizer-test-connection
+ApiVersion: apps/v1
+Kind: StatefulSet
+Name: -ohdsi-postgres
Namespace:
High | -CIS-5.7.3 Apply Security Context to Your Pods and Containers | -C-0211 | - spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
+ Medium | +CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | +C-0207 | + spec.template.spec.containers[0].env[4].name |
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -postgresql
+ApiVersion: v1
+Kind: Pod
+Name: -fhir-pseudonymizer-test-connection
Namespace:
Medium | -CIS-5.4.1 Prefer using secrets as files over secrets as environment variables | -C-0207 | - spec.template.spec.containers[0].env[4].name |
+ High | +CIS-5.7.3 Apply Security Context to Your Pods and Containers | +C-0211 | + spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -blaze
+ApiVersion: v1
+Kind: Pod
+Name: -datashield-test-connection
Namespace:
High | CIS-5.7.3 Apply Security Context to Your Pods and Containers | C-0211 | - spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.template.spec.securityContext.fsGroupChangePolicy=Always spec.template.spec.securityContext.sysctls.name=YOUR_VALUE spec.template.spec.securityContext.sysctls.value=YOUR_VALUE spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE |
+ spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE spec.securityContext.sysctls.name=YOUR_VALUE spec.securityContext.sysctls.value=YOUR_VALUE spec.securityContext.supplementalGroups=YOUR_VALUE |
diff --git a/kubescape-reports/nsa.html b/kubescape-reports/nsa.html
index 4ce773b2..d98b29c9 100644
--- a/kubescape-reports/nsa.html
+++ b/kubescape-reports/nsa.html
@@ -284,10 +284,10 @@
- | |||
High | -Ensure CPU limits are set | -C-0270 | - spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
-
High | -Ensure memory limits are set | -C-0271 | - spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
-
Medium | -Non-root containers | -C-0013 | - spec.template.spec.containers[0].securityContext.runAsGroup=1000 |
-
Low | -Immutable container filesystem | -C-0017 | - spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true |
-
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -postgresql
+Kind: Deployment
+Name: -fhir-pseudonymizer
Namespace:
High | -Ensure CPU limits are set | -C-0270 | - spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
- |||
High | -Ensure memory limits are set | -C-0271 | - spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
- |||
Medium | -Non-root containers | -C-0013 | - spec.template.spec.containers[0].securityContext.runAsGroup=1000 |
+ Ingress and Egress blocked | +C-0030 | +
ApiVersion: v1
-Kind: Pod
-Name: -vfps-test-connection
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -mailhog
Namespace:
+ | |||
High | +Ensure CPU limits are set | +C-0270 | + spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
+
High | +Ensure memory limits are set | +C-0271 | + spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
+
ApiVersion: apps/v1
-Kind: Deployment
-Name: -gateway-vfps
+ApiVersion: batch/v1
+Kind: Job
+Name: -gateway-vfps-migrations-v1-3-5
Namespace:
ApiVersion: apps/v1
Kind: Deployment
-Name: -vfps
+Name: -hapi-fhir-jpaserver
Namespace:
+ | |||
High | +Ensure CPU limits are set | +C-0270 | + spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
+
High | +Ensure memory limits are set | +C-0271 | + spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
+
ApiVersion: batch/v1
-Kind: Job
-Name: -gateway-vfps-migrations-v1-3-5
+ApiVersion: v1
+Kind: Pod
+Name: -hapi-fhir-jpaserver-test-endpoints
Namespace:
+ | |||
High | +Ensure CPU limits are set | +C-0270 | + spec.containers[0].resources.limits.cpu=YOUR_VALUE spec.containers[2].resources.limits.cpu=YOUR_VALUE spec.containers[1].resources.limits.cpu=YOUR_VALUE |
+
High | +Ensure memory limits are set | +C-0271 | + spec.containers[0].resources.limits.memory=YOUR_VALUE spec.containers[2].resources.limits.memory=YOUR_VALUE spec.containers[1].resources.limits.memory=YOUR_VALUE |
+
ApiVersion: apps/v1
-Kind: Deployment
-Name: -vfps
+Kind: StatefulSet
+Name: -recruit-postgres
Namespace:
Medium | +Non-root containers | +C-0013 | + spec.template.spec.containers[0].securityContext.runAsGroup=1000 |
+
Low | +Immutable container filesystem | +C-0017 | + spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true |
+
Medium | Ingress and Egress blocked | @@ -529,10 +543,10 @@
ApiVersion: apps/v1
Kind: Deployment
-Name: -fhir-pseudonymizer
+Name: -vfps
Namespace:
ApiVersion: v1
-Kind: Pod
-Name: -datashield-test-connection
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -fhir-pseudonymizer
Namespace:
+ | |||
High | +Ensure CPU limits are set | +C-0270 | + spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
+
High | +Ensure memory limits are set | +C-0271 | + spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
+
ApiVersion: v1
-Kind: Pod
-Name: -fhir-gateway-test-connection
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -vfps
Namespace:
+ | |||
High | +Ensure CPU limits are set | +C-0270 | + spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
+
High | +Ensure memory limits are set | +C-0271 | + spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
+
ApiVersion: v1
-Kind: Pod
-Name: -gateway-vfps-test-connection
+ApiVersion: batch/v1
+Kind: Job
+Name: -vfps-migrations-v1-3-6
Namespace:
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -datashield-opal
+ApiVersion: v1
+Kind: Pod
+Name: -datashield-test-connection
Namespace:
- | |||
Low | -Immutable container filesystem | -C-0017 | - spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true |
-
ApiVersion: apps/v1
-Kind: Deployment
-Name: -fhir-gateway-loinc-converter
+ApiVersion: batch/v1
+Kind: Job
+Name: -vfps-migrations-v1-3-6
Namespace:
ApiVersion: apps/v1
Kind: Deployment
-Name: -ohdsi-webapi
+Name: -recruit-notify
Namespace:
ApiVersion: apps/v1
Kind: Deployment
-Name: -vfps
+Name: -fhir-pseudonymizer
Namespace:
ApiVersion: apps/v1
-Kind: Deployment
-Name: -fhir-pseudonymizer
+ApiVersion: batch/v1
+Kind: Job
+Name: -vfps-migrations-v1-3-5
Namespace:
ApiVersion: apps/v1
-Kind: Deployment
-Name: -mailhog
+ApiVersion: v1
+Kind: Pod
+Name: -fhir-pseudonymizer-test-connection
Namespace:
- | |||
High | -Ensure CPU limits are set | -C-0270 | - spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
-
High | -Ensure memory limits are set | -C-0271 | - spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
-
ApiVersion: v1
-Kind: Pod
-Name: -vfps-test-connection
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -gateway-vfps
Namespace:
ApiVersion: v1
-Kind: Pod
-Name: -fhir-pseudonymizer-test-connection
+Kind: ServiceAccount
+Name: -mailhog
Namespace:
Medium | -Ingress and Egress blocked | -C-0030 | -+ | Automatic mapping of service account | +C-0034 | + automountServiceAccountToken=false |
ApiVersion: apps/v1
+Kind: StatefulSet
+Name: -blaze
+Namespace:
+High | -Ensure CPU limits are set | -C-0270 | - spec.containers[1].resources.limits.cpu=YOUR_VALUE spec.containers[0].resources.limits.cpu=YOUR_VALUE |
+ Severity | +Name | +Docs | +Assisted Remediation |
---|---|---|---|---|---|---|---|
High | -Ensure memory limits are set | -C-0271 | - spec.containers[1].resources.limits.memory=YOUR_VALUE spec.containers[0].resources.limits.memory=YOUR_VALUE |
+ Medium | +Ingress and Egress blocked | +C-0030 | +
ApiVersion: v1
Kind: Pod
-Name: -vfps-test-connection
+Name: -recruit-test-health-probes
Namespace:
High | Ensure CPU limits are set | C-0270 | - spec.containers[0].resources.limits.cpu=YOUR_VALUE spec.containers[1].resources.limits.cpu=YOUR_VALUE |
+ spec.containers[0].resources.limits.cpu=YOUR_VALUE spec.containers[2].resources.limits.cpu=YOUR_VALUE spec.containers[1].resources.limits.cpu=YOUR_VALUE |
High | Ensure memory limits are set | C-0271 | - spec.containers[0].resources.limits.memory=YOUR_VALUE spec.containers[1].resources.limits.memory=YOUR_VALUE |
+ spec.containers[0].resources.limits.memory=YOUR_VALUE spec.containers[2].resources.limits.memory=YOUR_VALUE spec.containers[1].resources.limits.memory=YOUR_VALUE |
ApiVersion: batch/v1
-Kind: Job
-Name: -vfps-migrations-v1-3-6
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -ohdsi-atlas
Namespace:
Low | +Immutable container filesystem | +C-0017 | + spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true |
+
Medium | Ingress and Egress blocked | @@ -980,14 +1021,28 @@||
High | +Ensure CPU limits are set | +C-0270 | + spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
+
High | +Ensure memory limits are set | +C-0271 | + spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
+
ApiVersion: v1
Kind: Pod
-Name: -blaze-test-connection
+Name: -ohdsi-test-connection
Namespace:
+ | |||
High | +Ensure CPU limits are set | +C-0270 | + spec.containers[1].resources.limits.cpu=YOUR_VALUE spec.containers[0].resources.limits.cpu=YOUR_VALUE |
+
High | +Ensure memory limits are set | +C-0271 | + spec.containers[1].resources.limits.memory=YOUR_VALUE spec.containers[0].resources.limits.memory=YOUR_VALUE |
+
ApiVersion: apps/v1
-Kind: Deployment
-Name: -fhir-gateway-gateway
+ApiVersion: v1
+Kind: Pod
+Name: -vfps-test-connection
Namespace:
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -datashield-rock
+Kind: Deployment
+Name: -fhir-gateway-gateway
Namespace:
ApiVersion: apps/v1
-Kind: Deployment
-Name: -recruit-query
+ApiVersion: v1
+Kind: Pod
+Name: -blaze-test-connection
Namespace:
- | |||
High | -Ensure CPU limits are set | -C-0270 | - spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
-
High | -Ensure memory limits are set | -C-0271 | - spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
-
ApiVersion: apps/v1
-Kind: Deployment
-Name: -recruit-notify
+ApiVersion: v1
+Kind: Pod
+Name: -fhir-pseudonymizer-test-connection
Namespace:
- | |||
High | -Ensure CPU limits are set | -C-0270 | - spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
-
High | -Ensure memory limits are set | -C-0271 | - spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
-
ApiVersion: v1
-Kind: Pod
-Name: -fhir-pseudonymizer-test-connection
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -vfps
Namespace:
ApiVersion: apps/v1
Kind: Deployment
-Name: -recruit-list
+Name: -recruit-query
Namespace:
High | -Applications credentials in configuration files | -C-0012 | - spec.template.spec.containers[0].env[1].name spec.template.spec.containers[0].env[1].value |
-
Medium | Ingress and Egress blocked | @@ -1222,10 +1256,10 @@
ApiVersion: v1
-Kind: Pod
-Name: -hapi-fhir-jpaserver-test-endpoints
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -recruit-list
Namespace:
High | Ensure CPU limits are set | C-0270 | - spec.containers[0].resources.limits.cpu=YOUR_VALUE spec.containers[2].resources.limits.cpu=YOUR_VALUE spec.containers[1].resources.limits.cpu=YOUR_VALUE |
+ spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
High | Ensure memory limits are set | C-0271 | - spec.containers[0].resources.limits.memory=YOUR_VALUE spec.containers[2].resources.limits.memory=YOUR_VALUE spec.containers[1].resources.limits.memory=YOUR_VALUE |
+ spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
+
High | +Applications credentials in configuration files | +C-0012 | + spec.template.spec.containers[0].env[1].name spec.template.spec.containers[0].env[1].value |
ApiVersion: apps/v1
-Kind: StatefulSet
-Name: -blaze
+Kind: Deployment
+Name: -ohdsi-webapi
Namespace:
- - |
ApiVersion: v1
-Kind: ServiceAccount
-Name: -mailhog
-Namespace:
-Severity | -Name | -Docs | -Assisted Remediation | +High | +Ensure CPU limits are set | +C-0270 | + spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
---|---|---|---|---|---|---|---|
Medium | -Automatic mapping of service account | -C-0034 | - automountServiceAccountToken=false |
+ High | +Ensure memory limits are set | +C-0271 | + spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
ApiVersion: batch/v1
-Kind: Job
-Name: -vfps-migrations-v1-3-5
+ApiVersion: v1
+Kind: Pod
+Name: -fhir-pseudonymizer-test-connection
Namespace:
High | Ensure CPU limits are set | C-0270 | - spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
+ spec.containers[1].resources.limits.cpu=YOUR_VALUE spec.containers[0].resources.limits.cpu=YOUR_VALUE |
High | Ensure memory limits are set | C-0271 | - spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
+ spec.containers[1].resources.limits.memory=YOUR_VALUE spec.containers[0].resources.limits.memory=YOUR_VALUE |
ApiVersion: apps/v1
-Kind: Deployment
-Name: -fhir-pseudonymizer
+ApiVersion: v1
+Kind: Pod
+Name: -vfps-test-connection
Namespace:
ApiVersion: apps/v1
-Kind: Deployment
-Name: -ohdsi-atlas
+Kind: StatefulSet
+Name: -datashield-opal
Namespace:
Low | +Immutable container filesystem | +C-0017 | + spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true |
+
Medium | Ingress and Egress blocked | @@ -1408,35 +1443,14 @@||
High | -Ensure CPU limits are set | -C-0270 | - spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE |
-
High | -Ensure memory limits are set | -C-0271 | - spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE |
-
Low | -Immutable container filesystem | -C-0017 | - spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true |
-
ApiVersion: v1
Kind: Pod
-Name: -recruit-test-health-probes
+Name: -fhir-gateway-test-connection
Namespace:
- | |||
High | -Ensure CPU limits are set | -C-0270 | - spec.containers[0].resources.limits.cpu=YOUR_VALUE spec.containers[2].resources.limits.cpu=YOUR_VALUE spec.containers[1].resources.limits.cpu=YOUR_VALUE |
-
High | -Ensure memory limits are set | -C-0271 | - spec.containers[0].resources.limits.memory=YOUR_VALUE spec.containers[2].resources.limits.memory=YOUR_VALUE spec.containers[1].resources.limits.memory=YOUR_VALUE |
-
ApiVersion: v1
-Kind: Pod
-Name: -ohdsi-test-connection
+ApiVersion: apps/v1
+Kind: Deployment
+Name: -fhir-gateway-loinc-converter
Namespace:
- | |||
High | -Ensure CPU limits are set | -C-0270 | - spec.containers[1].resources.limits.cpu=YOUR_VALUE spec.containers[0].resources.limits.cpu=YOUR_VALUE |
-
High | -Ensure memory limits are set | -C-0271 | - spec.containers[1].resources.limits.memory=YOUR_VALUE spec.containers[0].resources.limits.memory=YOUR_VALUE |
-
ApiVersion: v1
-Kind: Pod
-Name: -fhir-pseudonymizer-test-connection
+ApiVersion: apps/v1
+Kind: StatefulSet
+Name: -datashield-rock
Namespace:
ApiVersion: batch/v1
-Kind: Job
-Name: -vfps-migrations-v1-3-6
+ApiVersion: v1
+Kind: Pod
+Name: -vfps-test-connection
Namespace:
+ | |||
High | +Ensure CPU limits are set | +C-0270 | + spec.containers[0].resources.limits.cpu=YOUR_VALUE spec.containers[1].resources.limits.cpu=YOUR_VALUE |
+
High | +Ensure memory limits are set | +C-0271 | + spec.containers[0].resources.limits.memory=YOUR_VALUE spec.containers[1].resources.limits.memory=YOUR_VALUE |
+
ApiVersion: apps/v1
-Kind: Deployment
-Name: -hapi-fhir-jpaserver
+Kind: StatefulSet
+Name: -postgresql
Namespace:
Medium | -Ingress and Egress blocked | -C-0030 | -+ | Non-root containers | +C-0013 | + spec.template.spec.containers[0].securityContext.runAsGroup=1000 |