File tree
867 files changed
+6938
-6938
lines changed- best-practices
- add-safe-to-evict/.chainsaw-test
- disallow-cri-sock-mount/.chainsaw-test
- disallow-default-namespace/.chainsaw-test
- disallow-helm-tiller/.chainsaw-test
- disallow-latest-tag/.chainsaw-test
- require-drop-all/.chainsaw-test
- require-drop-cap-net-raw/.chainsaw-test
- require-labels/.chainsaw-test
- require-pod-requests-limits/.chainsaw-test
- require-probes/.chainsaw-test
- require-ro-rootfs/.chainsaw-test
- restrict-image-registries/.chainsaw-test
- best-practices-cel
- disallow-cri-sock-mount/.chainsaw-test
- disallow-default-namespace/.chainsaw-test
- disallow-helm-tiller/.chainsaw-test
- disallow-latest-tag/.chainsaw-test
- require-drop-all/.chainsaw-test
- require-drop-cap-net-raw/.chainsaw-test
- require-labels/.chainsaw-test
- require-pod-requests-limits/.chainsaw-test
- require-probes/.chainsaw-test
- require-ro-rootfs/.chainsaw-test
- restrict-image-registries/.chainsaw-test
- cleanup/cleanup-bare-pods/.chainsaw-test
- istio
- prevent-disabling-injection-pods/.chainsaw-test
- service-mesh-disallow-capabilities/.chainsaw-test
- service-mesh-require-run-as-nonroot/.chainsaw-test
- istio-cel/prevent-disabling-injection-pods/.chainsaw-test
- karpenter
- add-karpenter-daemonset-priority-class/.chainsaw-test
- add-karpenter-donot-evict/.chainsaw-test
- add-karpenter-nodeselector/.chainsaw-test
- set-karpenter-non-cpu-limits/.chainsaw-test
- kasten/kasten-data-protection-by-label/.chainsaw-test
- kasten-cel/k10-data-protection-by-label/.chainsaw-test
- kubecost
- enable-kubecost-continuous-rightsizing/.chainsaw-test
- require-kubecost-labels/.chainsaw-test
- kubecost-cel/require-kubecost-labels/.chainsaw-test
- kubevirt/enforce-instancetype/.chainsaw-test
- linkerd
- prevent-linkerd-pod-injection-override/.chainsaw-test
- prevent-linkerd-port-skipping/.chainsaw-test
- require-linkerd-server/.chainsaw-test
- linkerd-cel
- prevent-linkerd-pod-injection-override/.chainsaw-test
- prevent-linkerd-port-skipping/.chainsaw-test
- other
- add-certificates-volume/.chainsaw-test
- add-default-resources/.chainsaw-test
- add-default-securitycontext/.chainsaw-test
- add-env-vars-from-cm/.chainsaw-test
- add-imagepullsecrets/.chainsaw-test
- add-imagepullsecrets-for-containers-and-initcontainers/.chainsaw-test
- add-labels/.chainsaw-test
- add-ndots/.chainsaw-test
- add-node-labels-pod/.chainsaw-test
- add-nodeSelector/.chainsaw-test
- add-pod-proxies/.chainsaw-test
- add-ttl-jobs/.chainsaw-test
- advanced-restrict-image-registries/.chainsaw-test
- allowed-annotations/.chainsaw-test
- allowed-base-images/.chainsaw-test
- allowed-image-repos/.chainsaw-test
- allowed-label-changes/.chainsaw-test
- allowed-pod-priorities/.chainsaw-test
- always-pull-images/.chainsaw-test
- apply-pss-restricted-profile/.chainsaw-test
- audit-event-on-exec/.chainsaw-test
- block-cluster-admin-from-ns/.chainsaw-test
- block-ephemeral-containers/.chainsaw-test
- block-images-with-volumes/.chainsaw-test
- block-large-images/.chainsaw-test
- block-pod-exec-by-namespace/.chainsaw-test
- block-pod-exec-by-namespace-label/.chainsaw-test
- block-pod-exec-by-pod-and-container/.chainsaw-test
- block-pod-exec-by-pod-label/.chainsaw-test
- block-pod-exec-by-pod-name/.chainsaw-test
- block-stale-images/.chainsaw-test
- check-env-vars/.chainsaw-test
- check-hpa-exists/.chainsaw-test
- check-nvidia-gpu/.chainsaw-test
- check-serviceaccount/.chainsaw-test
- check-vpa-configuration/.chainsaw-test
- copy-namespace-labels/.chainsaw-test
- create-default-pdb/.chainsaw-test
- create-pod-antiaffinity/.chainsaw-test
- deny-commands-in-exec-probe/.chainsaw-test
- deployment-replicas-higher-than-pdb/.chainsaw-test
- disable-service-discovery/.chainsaw-test
- disallow-all-secrets/.chainsaw-test
- disallow-secrets-from-env-vars/.chainsaw-test
- dns-policy-and-dns-config/.chainsaw-test
- docker-socket-requires-label/.chainsaw-test
- enforce-pod-duration/.chainsaw-test
- enforce-resources-as-ratio/.chainsaw-test
- ensure-probes-different/.chainsaw-test
- ensure-production-matches-staging/.chainsaw-test
- ensure-readonly-hostpath/.chainsaw-test
- exclude-namespaces-dynamically/.chainsaw-test
- forbid-cpu-limits/.chainsaw-test
- get-debug-information/.chainsaw-test
- imagepullpolicy-always/.chainsaw-test
- inject-sidecar-deployment/.chainsaw-test
- limit-containers-per-pod/.chainsaw-test
- limit-hostpath-vols/.chainsaw-test
- memory-requests-equal-limits/.chainsaw-test
- metadata-match-regex/.chainsaw-test
- mitigate-log4shell/.chainsaw-test
- mutate-large-termination-gps/.chainsaw-test
- mutate-pod-binding/.chainsaw-test
- only-trustworthy-registries-set-root/.chainsaw-test
- prevent-bare-pods/.chainsaw-test
- prevent-cr8escape/.chainsaw-test
- record-creation-details/.chainsaw-test
- refresh-env-var-in-pod/.chainsaw-test
- refresh-volumes-in-pods/.chainsaw-test
- remove-hostpath-volumes/.chainsaw-test
- remove-serviceaccount-token/.chainsaw-test
- replace-image-registry/.chainsaw-test
- require-annotations/.chainsaw-test
- require-base-image/.chainsaw-test
- require-container-port-names/.chainsaw-test
- require-cpu-limits/.chainsaw-test
- require-deployments-have-multiple-replicas/.chainsaw-test
- require-emptydir-requests-limits/.chainsaw-test
- require-image-checksum/.chainsaw-test
- require-imagepullsecrets/.chainsaw-test
- require-netpol/.chainsaw-test
- require-non-root-groups/.chainsaw-test
- require-pdb/.chainsaw-test
- require-pod-priorityclassname/.chainsaw-test
- require-qos-burstable/.chainsaw-test
- require-qos-guaranteed/.chainsaw-test
- require-replicas-allow-disruption/.chainsaw-test
- require-storageclass/.chainsaw-test
- require-unique-uid-per-workload/.chainsaw-test
- resolve-image-to-digest/.chainsaw-test
- restart-deployment-on-secret-change/.chainsaw-test
- restrict-annotations/.chainsaw-test
- restrict-automount-sa-token/.chainsaw-test
- restrict-controlplane-scheduling/.chainsaw-test
- restrict-deprecated-registry/.chainsaw-test
- restrict-jobs/.chainsaw-test
- restrict-node-affinity/.chainsaw-test
- restrict-node-selection/.chainsaw-test
- restrict-pod-controller-serviceaccount-updates/.chainsaw-test
- restrict-secrets-by-label/.chainsaw-test
- restrict-secrets-by-name/.chainsaw-test
- restrict-usergroup-fsgroup-id/.chainsaw-test
- scale-deployment-zero/.chainsaw-test
- spread-pods-across-topology/.chainsaw-test
- topologyspreadconstraints-policy/.chainsaw-test
- update-image-tag/.chainsaw-test
- verify-vpa-target/.chainsaw-test
- other-cel
- advanced-restrict-image-registries/.chainsaw-test
- allowed-annotations/.chainsaw-test
- allowed-pod-priorities/.chainsaw-test
- block-ephemeral-containers/.chainsaw-test
- check-env-vars/.chainsaw-test
- deny-commands-in-exec-probe/.chainsaw-test
- disallow-all-secrets/.chainsaw-test
- disallow-secrets-from-env-vars/.chainsaw-test
- docker-socket-requires-label/.chainsaw-test
- enforce-pod-duration/.chainsaw-test
- ensure-probes-different/.chainsaw-test
- ensure-readonly-hostpath/.chainsaw-test
- exclude-namespaces-dynamically/.chainsaw-test
- forbid-cpu-limits/.chainsaw-test
- imagepullpolicy-always/.chainsaw-test
- limit-containers-per-pod/.chainsaw-test
- limit-hostpath-vols/.chainsaw-test
- memory-requests-equal-limits/.chainsaw-test
- metadata-match-regex/.chainsaw-test
- prevent-bare-pods/.chainsaw-test
- prevent-cr8escape/.chainsaw-test
- require-annotations/.chainsaw-test
- require-container-port-names/.chainsaw-test
- require-deployments-have-multiple-replicas/.chainsaw-test
- require-emptydir-requests-limits/.chainsaw-test
- require-image-checksum/.chainsaw-test
- require-non-root-groups/.chainsaw-test
- require-pod-priorityclassname/.chainsaw-test
- require-qos-burstable/.chainsaw-test
- require-qos-guaranteed/.chainsaw-test
- require-storageclass/.chainsaw-test
- restrict-annotations/.chainsaw-test
- restrict-controlplane-scheduling/.chainsaw-test
- restrict-deprecated-registry/.chainsaw-test
- restrict-jobs/.chainsaw-test
- restrict-node-affinity/.chainsaw-test
- restrict-pod-controller-serviceaccount-updates/.chainsaw-test
- restrict-secrets-by-name/.chainsaw-test
- restrict-usergroup-fsgroup-id/.chainsaw-test
- topologyspreadconstraints-policy/.chainsaw-test
- pod-security
- baseline
- disallow-capabilities/.chainsaw-test
- disallow-host-namespaces/.chainsaw-test
- disallow-host-path/.chainsaw-test
- disallow-host-ports/.chainsaw-test
- disallow-host-ports-range/.chainsaw-test
- disallow-host-process/.chainsaw-test
- disallow-privileged-containers/.chainsaw-test
- disallow-selinux/.chainsaw-test
- restrict-apparmor-profiles/.chainsaw-test
- restrict-seccomp/.chainsaw-test
- restrict-sysctls/.chainsaw-test
- restricted
- disallow-capabilities-strict/.chainsaw-test
- disallow-privilege-escalation/.chainsaw-test
- require-run-as-non-root-user/.chainsaw-test
- require-run-as-nonroot/.chainsaw-test
- restrict-seccomp-strict/.chainsaw-test
- restrict-volume-types/.chainsaw-test
- subrule/restricted
- restricted-exclude-capabilities/.chainsaw-test
- restricted-exclude-seccomp/.chainsaw-test
- restricted-latest/.chainsaw-test
- pod-security-cel
- baseline
- disallow-capabilities/.chainsaw-test
- disallow-host-namespaces/.chainsaw-test
- disallow-host-path/.chainsaw-test
- disallow-host-ports/.chainsaw-test
- disallow-host-ports-range/.chainsaw-test
- disallow-host-process/.chainsaw-test
- disallow-privileged-containers/.chainsaw-test
- disallow-selinux/.chainsaw-test
- restrict-seccomp/.chainsaw-test
- restrict-sysctls/.chainsaw-test
- restricted
- disallow-capabilities-strict/.chainsaw-test
- disallow-privilege-escalation/.chainsaw-test
- require-run-as-non-root-user/.chainsaw-test
- require-run-as-nonroot/.chainsaw-test
- restrict-seccomp-strict/.chainsaw-test
- restrict-volume-types/.chainsaw-test
- psp-migration
- check-supplemental-groups/.chainsaw-test
- restrict-adding-capabilities/.chainsaw-test
- psp-migration-cel
- check-supplemental-groups/.chainsaw-test
- restrict-adding-capabilities/.chainsaw-test
- velero/backup-all-volumes/.chainsaw-test
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
867 files changed
+6938
-6938
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
9 |
| - | |
| 9 | + | |
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
19 |
| - | |
| 19 | + | |
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
13 | 13 |
| |
14 | 14 |
| |
15 | 15 |
| |
16 |
| - | |
| 16 | + | |
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
|
Lines changed: 4 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
32 |
| - | |
| 32 | + | |
33 | 33 |
| |
34 | 34 |
| |
35 | 35 |
| |
| |||
50 | 50 |
| |
51 | 51 |
| |
52 | 52 |
| |
53 |
| - | |
| 53 | + | |
54 | 54 |
| |
55 | 55 |
| |
56 | 56 |
| |
| |||
65 | 65 |
| |
66 | 66 |
| |
67 | 67 |
| |
68 |
| - | |
| 68 | + | |
69 | 69 |
| |
70 | 70 |
| |
71 | 71 |
| |
| |||
90 | 90 |
| |
91 | 91 |
| |
92 | 92 |
| |
93 |
| - | |
| 93 | + | |
94 | 94 |
| |
95 | 95 |
| |
96 | 96 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
7 | 7 |
| |
8 | 8 |
| |
9 | 9 |
| |
10 |
| - | |
| 10 | + | |
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
19 |
| - | |
| 19 | + | |
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
18 |
| - | |
| 18 | + | |
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
7 | 7 |
| |
8 | 8 |
| |
9 | 9 |
| |
10 |
| - | |
| 10 | + | |
11 | 11 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
18 |
| - | |
| 18 | + | |
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 |
| - | |
| 10 | + | |
11 | 11 |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 |
| - | |
| 10 | + | |
11 | 11 |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 |
| - | |
| 10 | + | |
11 | 11 |
|
Lines changed: 6 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 |
| - | |
| 10 | + | |
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
| |||
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
19 |
| - | |
| 19 | + | |
20 | 20 |
| |
21 |
| - | |
| 21 | + | |
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
31 | 31 |
| |
32 |
| - | |
| 32 | + | |
33 | 33 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
|
Lines changed: 8 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
| 15 | + | |
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
| 23 | + | |
24 | 24 |
| |
25 | 25 |
| |
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
31 | 31 |
| |
32 | 32 |
| |
33 | 33 |
| |
| |||
36 | 36 |
| |
37 | 37 |
| |
38 | 38 |
| |
39 |
| - | |
| 39 | + | |
40 | 40 |
| |
41 | 41 |
| |
42 | 42 |
| |
43 | 43 |
| |
44 | 44 |
| |
45 | 45 |
| |
46 |
| - | |
| 46 | + | |
47 | 47 |
| |
48 | 48 |
| |
49 | 49 |
| |
50 | 50 |
| |
51 | 51 |
| |
52 | 52 |
| |
53 | 53 |
| |
54 |
| - | |
| 54 | + | |
55 | 55 |
| |
56 |
| - | |
| 56 | + | |
57 | 57 |
| |
58 | 58 |
| |
59 | 59 |
| |
|
Lines changed: 6 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
| 15 | + | |
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
| |||
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
29 |
| - | |
| 29 | + | |
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
33 | 33 |
| |
34 |
| - | |
| 34 | + | |
35 | 35 |
| |
36 | 36 |
| |
37 | 37 |
| |
| |||
45 | 45 |
| |
46 | 46 |
| |
47 | 47 |
| |
48 |
| - | |
| 48 | + | |
49 | 49 |
| |
50 | 50 |
| |
51 | 51 |
| |
52 | 52 |
| |
53 | 53 |
| |
54 |
| - | |
| 54 | + | |
55 | 55 |
|
Lines changed: 6 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
| 15 | + | |
16 | 16 |
| |
17 | 17 |
| |
18 |
| - | |
| 18 | + | |
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
| |||
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
32 |
| - | |
| 32 | + | |
33 | 33 |
| |
34 |
| - | |
| 34 | + | |
35 | 35 |
| |
36 | 36 |
| |
37 | 37 |
| |
38 | 38 |
| |
39 | 39 |
| |
40 | 40 |
| |
41 | 41 |
| |
42 |
| - | |
| 42 | + | |
43 | 43 |
| |
44 | 44 |
| |
45 | 45 |
| |
|
0 commit comments