Skip to content

Improve granularity of diki rule options #472

@AleksandarSavchev

Description

@AleksandarSavchev

What would you like to be added:
Rule options should be revisited and where possible improve granularity of silence targets. For example rule 2001 of security-hardened-k8s should allow configuring accepted containers in addition to pods:

    - ruleID: "2001"
      args:
        acceptedPods:
        - matchLabels:
            foo: bar
          namespaceMatchLabels:
            foo: bar
          acceptedContainers: #improvement
          - foo
          justification: "justification"

Why is this needed:
Allow users to silence findings more precisely

Metadata

Metadata

Assignees

Labels

kind/enhancementEnhancement, improvement, extensionlifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.priority/4Priority (lower number equals higher priority)

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions