falcon-operator icon indicating copy to clipboard operation
falcon-operator copied to clipboard

[Feature Request] Falcon Admission must have at less 2 replicas & a PDB

Open YvesEarnix opened this issue 6 months ago • 0 comments

Currently by default Falcon Admission run with only one pod and on the validating Webhook configuration, failurePolicy is set to Ignore.

It's mean that is not possible to guarenty that that a policy like 'run as root' is apply.

Currently an attacker can potentially "DDos" the validating webhook hook and bypass it.

To be able to change the failurePolicy to Fail (as do https://kyverno.io/), we must ensure that at less one admission pod is running, then we need to have two pods (with node anti affinity) and PodDisruptionBudget defined.

YvesEarnix avatar Jun 26 '25 06:06 YvesEarnix