adamant-kite-43734
04/09/2024, 1:15 PMalert-potato-16010
04/10/2024, 7:43 AM- action: deny
comment: DENY 70001 out of default namespace
containers:
- containers
criteria:
- name: user
op: containsAny
path: user
value: "70001"
- name: namespace
op: notContainsAny
path: namespace
value: default
- name: userGroups
op: containsAny
path: userGroups
value: "700001"
disabled: false
rule_mode: ""
alert-potato-16010
04/10/2024, 7:48 AMapiVersion: apps/v1
kind: Deployment
metadata:
labels:
app: user70001
name: user70001
spec:
replicas: 1
selector:
matchLabels:
app: user70001
strategy: {}
template:
metadata:
creationTimestamp: null
labels:
app: user70001
spec:
securityContext:
runAsNonRoot: true
runAsUser: 70001
runAsGroup: 70001
containers:
- args:
- sleep
- INF
image: <http://docker.io/busybox:1.35|docker.io/busybox:1.35>
name: busybox
alert-potato-16010
04/10/2024, 2:53 PMquaint-candle-18606
04/13/2024, 1:01 AMalert-potato-16010
04/13/2024, 6:55 AM