rego-policies
rego-policies copied to clipboard
Policy to deny pod running with high vulnerabilities
Investigate if it's possible to hookup the data from the below operator to deny images that are bad:
- https://operatorhub.io/operator/project-quay-container-security-operator
@sabre1041 ; do you know if there is anything already in the quay ecosystem that would do this already?
can be solved by RHACS (https://www.redhat.com/en/technologies/cloud-computing/openshift/advanced-cluster-security-kubernetes) or another admission controller (https://kyverno.io/policies/other/rec-req/require-vulnerability-scan/require-vulnerability-scan/)