discovery-engine
discovery-engine copied to clipboard
Discover least permissive security posture, Network Microsegmentation, and Application behaviour based on visibility/observability data emitted from policy engines..
- [ ] do not skip TLS cert check ... cluster-mgmt server is using self-signed-cert and thus the checks are failing for HTTP client in knoxautopolicy. Currently we are skipping...
Basically, knoxAutoPolicy discovers the system policy based on the system log/alert. Also, we need to support the functionality that can discover the system policy from the dropped system log as...
As of now, if at least 1 kubeArmorPolicy applied, KubeArmor doesn't generate the system logs anymore. Rather, it generates the system alert events. Thus, we need to discover the system...
Update github document for system policy discovery parts
Performance test with Cilium L7 visibility base (no L7 visibility) HTTP visibility will be tested by Apache Bench
Based on [K8s PodSecurityPolicy](https://kubernetes.io/docs/concepts/policy/pod-security-policy/)
Based on the [Document](https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF)