Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Exclude WIZ namespace by default from admission controller #239

Open
denisovval opened this issue Nov 22, 2023 · 0 comments
Open

Exclude WIZ namespace by default from admission controller #239

denisovval opened this issue Nov 22, 2023 · 0 comments

Comments

@denisovval
Copy link

denisovval commented Nov 22, 2023

Hello folks,

By default, wiz ignores only resources in the kube-system namespace. Which is reasonable but another exclusion must me made for wiz resources itself.

By default, wiz pods are not passing Kubernetes pod security standard, especially this rule -Pod should run containers with the runtime/default seccomp profile

In a future, there can be more.
This leads to an inability to update/upgrade wiz resources with K8S admission policy set to block.

Please, come up with a solution to exclude wiz resources by default. For example, it can be done via assigned kubernetes labels on all wiz resources.
Plus, documentation should explicitly state that these resources are excluded.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant