compliantkubernetes-apps
compliantkubernetes-apps copied to clipboard
Alert for blocked network traffic
Is your feature request related to a problem? Please describe. We have added a lot of network policies recently. If they block traffic then it is likely either
- something that is miss-configured and should be fixed
- or the environment is compromised and we should investigate. This is especially true in sc. In wc it might also be that the users are trying to configure their own network policies or are figuring out how to use the platform.
Describe the solution you'd like
We should add an alert that triggers whenever network policies are blocking traffic. Something similar to rate(no_policy_drop_counter[1m]) > 1
.
Describe alternatives you've considered
Additional context
Definition of done:
- There is an alert for dropped traffic.