From bff5f37f9bbb28b22c933321408a3cff7c4e63a0 Mon Sep 17 00:00:00 2001 From: chgl Date: Thu, 2 Jan 2025 18:25:43 +0000 Subject: [PATCH] docs: updated kubescape reports --- kubescape-reports/cis-v1.23-t1.0.1.html | 138 ++++++++++++------------ kubescape-reports/nsa.html | 80 +++++++------- 2 files changed, 109 insertions(+), 109 deletions(-) diff --git a/kubescape-reports/cis-v1.23-t1.0.1.html b/kubescape-reports/cis-v1.23-t1.0.1.html index d8cc05fd..5936cc90 100644 --- a/kubescape-reports/cis-v1.23-t1.0.1.html +++ b/kubescape-reports/cis-v1.23-t1.0.1.html @@ -320,10 +320,10 @@

Failed Resources:


-

Name: -magnifhir

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -magnifhir

+

Name: -fhir-server-exporter-test-metrics-endpoint

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-server-exporter-test-metrics-endpoint

Namespace:

@@ -340,7 +340,7 @@

Name: -magnifhir

- + @@ -374,33 +374,6 @@

Name: -fhir-server-exporter

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-server-exporter-test-metrics-endpoint

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-server-exporter-test-metrics-endpoint

-

Namespace:

- - - - - - - - - - - - - - - - - - - -
SeverityNameDocsAssisted Remediation
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

- -

Name: -pathling-server-test-connection

ApiVersion: v1

Kind: Pod

@@ -489,10 +462,10 @@

Name: -ohdsi-webapi

-

Name: -ohdsi-test-connection

+

Name: -fhir-server-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -ohdsi-test-connection

+

Name: -fhir-server-test-connection

Namespace:

@@ -516,10 +489,10 @@

Name: -ohdsi-test-connection

-

Name: -ohdsi-atlas

+

Name: -fhir-server

ApiVersion: apps/v1

Kind: Deployment

-

Name: -ohdsi-atlas

+

Name: -fhir-server

Namespace:

@@ -532,21 +505,28 @@

Name: -ohdsi-atlas

+ + + + + + + - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[10].name

spec.template.spec.containers[0].env[11].name

spec.template.spec.containers[0].env[9].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -postgresql

+

Name: -pathling-server

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -postgresql

+

Kind: Deployment

+

Name: -pathling-server

Namespace:

@@ -563,17 +543,24 @@

Name: -postgresql

- + + + + + + + +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[4].name

spec.template.spec.containers[0].env[4].name

spec.template.spec.containers[0].env[5].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -pathling-server

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -pathling-server

+

Name: -magnifhir-test

+

ApiVersion: v1

+

Kind: Pod

+

Name: -magnifhir-test

Namespace:

@@ -586,28 +573,21 @@

Name: -pathling-server

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

spec.template.spec.containers[0].env[5].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-server

+

Name: -ohdsi-atlas

ApiVersion: apps/v1

Kind: Deployment

-

Name: -fhir-server

+

Name: -ohdsi-atlas

Namespace:

@@ -621,12 +601,32 @@

Name: -fhir-server

- - - - + + + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[10].name

spec.template.spec.containers[0].env[11].name

spec.template.spec.containers[0].env[9].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

+ + +

Name: -magnifhir

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -magnifhir

+

Namespace:

+ + + + + + + + + + + @@ -638,10 +638,10 @@

Name: -fhir-server

SeverityNameDocsAssisted Remediation
High CIS-5.7.3 Apply Security Context to Your Pods and Containers
-

Name: -fhir-server-test-connection

+

Name: -ohdsi-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -fhir-server-test-connection

+

Name: -ohdsi-test-connection

Namespace:

@@ -665,10 +665,10 @@

Name: -fhir-server-test-connection

-

Name: -magnifhir-test

-

ApiVersion: v1

-

Kind: Pod

-

Name: -magnifhir-test

+

Name: -postgresql

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -682,10 +682,10 @@

Name: -magnifhir-test

- - - - + + + + diff --git a/kubescape-reports/nsa.html b/kubescape-reports/nsa.html index 3f768327..dc59c2f6 100644 --- a/kubescape-reports/nsa.html +++ b/kubescape-reports/nsa.html @@ -284,10 +284,10 @@

Failed Resources:


-

Name: -magnifhir-test

-

ApiVersion: v1

-

Kind: Pod

-

Name: -magnifhir-test

+

Name: -pathling-server

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -pathling-server

Namespace:

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

@@ -300,6 +300,13 @@

Name: -magnifhir-test

+ + + + + + + @@ -311,10 +318,10 @@

Name: -magnifhir-test

HighApplications credentials in configuration filesC-0012

spec.template.spec.containers[0].env[3].name

spec.template.spec.containers[0].env[3].value

Medium Ingress and Egress blocked
-

Name: -pathling-server-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -pathling-server-test-connection

+

Name: -ohdsi-atlas

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -ohdsi-atlas

Namespace:

@@ -327,6 +334,13 @@

Name: -pathling-server-test-connection

+ + + + + + + @@ -365,10 +379,10 @@

Name: -fhir-server

LowImmutable container filesystemC-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

Medium Ingress and Egress blocked
-

Name: -fhir-server-exporter

+

Name: -magnifhir

ApiVersion: apps/v1

Kind: Deployment

-

Name: -fhir-server-exporter

+

Name: -magnifhir

Namespace:

@@ -392,10 +406,10 @@

Name: -fhir-server-exporter

-

Name: -ohdsi-webapi

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -ohdsi-webapi

+

Name: -ohdsi-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -ohdsi-test-connection

Namespace:

@@ -419,10 +433,10 @@

Name: -ohdsi-webapi

-

Name: -fhir-server-test-connection

+

Name: -pathling-server-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -fhir-server-test-connection

+

Name: -pathling-server-test-connection

Namespace:

@@ -446,10 +460,10 @@

Name: -fhir-server-test-connection

-

Name: -ohdsi-test-connection

+

Name: -fhir-server-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -ohdsi-test-connection

+

Name: -fhir-server-test-connection

Namespace:

@@ -473,10 +487,10 @@

Name: -ohdsi-test-connection

-

Name: -pathling-server

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -pathling-server

+

Name: -magnifhir-test

+

ApiVersion: v1

+

Kind: Pod

+

Name: -magnifhir-test

Namespace:

@@ -496,21 +510,14 @@

Name: -pathling-server

- - - - - - -
HighApplications credentials in configuration filesC-0012

spec.template.spec.containers[0].env[3].name

spec.template.spec.containers[0].env[3].value

-

Name: -magnifhir

+

Name: -ohdsi-webapi

ApiVersion: apps/v1

Kind: Deployment

-

Name: -magnifhir

+

Name: -ohdsi-webapi

Namespace:

@@ -561,10 +568,10 @@

Name: -fhir-server-exporter-test-metrics-endpoint

-

Name: -ohdsi-atlas

+

Name: -fhir-server-exporter

ApiVersion: apps/v1

Kind: Deployment

-

Name: -ohdsi-atlas

+

Name: -fhir-server-exporter

Namespace:

@@ -584,13 +591,6 @@

Name: -ohdsi-atlas

- - - - - - -
LowImmutable container filesystemC-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true