Add rkhunter in the binaries allowed to read sensitive files
What type of PR is this?
Uncomment one (or more)
/kind <>lines:
/kind feature
/kind bug
/kind cleanup
/kind design
/kind documentation
/kind failing-test
Any specific area of the project related to this PR?
Uncomment one (or more)
/area <>lines:
/area rules
/area registry
/area build
/area documentation
Proposed rule maturity level
Uncomment one (or more)
/area <>lines (only for PRs that add or modify rules):
/area maturity-stable
/area maturity-incubating
/area maturity-sandbox
/area maturity-deprecated
What this PR does / why we need it:
https://www.rkhunter.dev/ tool needs to read sensitive files (at least /etc/shadow)
In my custom config, I also restricted it on the host (container.id=host), this PR allows it anywhere.
[APPROVALNOTIFIER] This PR is NOT APPROVED
This pull-request has been approved by: mossroy Once this PR has been reviewed and has the lgtm label, please assign loresuso for approval. For more information see the Kubernetes Code Review Process.
The full list of commands accepted by this bot can be found here.
Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment