Hi everyone. We have a set of namespaces where eph...
# neuvector_suse-security
n
Hi everyone. We have a set of namespaces where ephemeral job pods get created. So, we created a custom group that matches on all these namespaces and allows the processes we want to allow for all these ephemeral jobs. But, We're still receiving security event notifications about process profile rule violation. Why is that?
q
can you screencap the rules(s) and alerts? πŸ™‚
n
Screenshot 2025-11-12 092644.png,Screenshot 2025-11-12 093059.png,Screenshot 2025-11-12 093110.png
it looks to me like the group neuvector automatically generates for each each ephemeral pod takes precedence over the umbrella custom group we created.
Any idea @quaint-candle-18606?
@quaint-candle-18606 Sorry to bump again, but we're still evaluating whether we can use NeuVector or not due to this. Is there some additional info I could provide to make troubleshooting easier?
q
Oh hello; sorry. I've been traveling for the last 3 1/2 weeks and didn't even see alerts from this slack instance.
n
No worries, thanks for responding. I hope you had safe and pleasant travels πŸ™‚
q
I'm asking around, because this one's a little bit new to me and I'm not sure I have the perfect answer for it.
What country are you in, and are you working with anybody at SUSE right now?
n
Canada. I don't know if we have regular contact with a SUSE representative, but I doubt it. I don't think we're subscribed to any paid service that SUSE offers.
q
Gotcha πŸ‘
n
Would it be better to open an issue on GitHub? The reason I asked here in the first place is that I'm unsure whether it's just us misunderstanding how custom groups behave, or if there is truly a bug.
q
I think your GH issue idea is best. Yes, please.
πŸ‘ 1
Drop that link here when you do so we can all pile on it like crazy little nerd monkeys. πŸ˜„
n
haha! Alright, will do πŸ™‚
Process generates security event even though custom group should allow: https://github.com/neuvector/neuvector/issues/2161
q
Update: So this issue is in and being worked as a bug. If you have the time/desire, see if v5.4.5 still acts this way.
n
Hi! Just to be clear, we were on 5.4.6 when we noticed it happening, since then we have upgraded to 5.4.7.
πŸ‘ 1
q
I'm told there was a fix in 5.4.4/5 but had to regress for reasons but it's being worked again.
πŸ‘ 1
n
Ahh ok I see! Thanks for following up. I'll see if I can arrange us to test if we see the behavior in 5.4.5.
q
thank you