Virtual Patch: Exploit Public Facing Applications
M1051 is "Update Software Regularly". Virtual Patch is an intermediate step before the actual update.
There is a set of annotations (CVEs) on the pods
Nimbus can look at the CVEs, and then attempt a live patch on these pods to mitigate the CVE
As part of live patch, Also, Nimbus can also create NetPol in case of workloads exposed to Public INternet
Design Doc for the intent: https://docs.google.com/document/d/1CoooyoEG8NKXOpfrsnV8PHCqYk7OUbZYbPtQRD7lr5k/edit#heading=h.18eqtrsy88hg
Design/Architecture Discussion needed.
Moving to backlog till demo on June 20.
Document under review. @VedRatan Can you link the design doc please?
The design doc is in the description of the issue itself @nandhued
WIP on generate policy approach.
List the assumptions on the design doc with sample JSON and confirm w KA team.
WIP
Done w KA generator policies. Kyverno and netpol WIP.
Adding scheduling for CVEs.
PR to be raised today.