From 20d7af45ac9e537c9fc7c7dce614110df7272cbc Mon Sep 17 00:00:00 2001 From: "miracum-renovate[bot]" Date: Sun, 22 Dec 2024 11:17:55 +0000 Subject: [PATCH] docs: updated kubescape reports --- kubescape-reports/cis-v1.23-t1.0.1.html | 578 ++++++++++---------- kubescape-reports/nsa.html | 694 ++++++++++++------------ 2 files changed, 636 insertions(+), 636 deletions(-) diff --git a/kubescape-reports/cis-v1.23-t1.0.1.html b/kubescape-reports/cis-v1.23-t1.0.1.html index 57621860..994c5612 100644 --- a/kubescape-reports/cis-v1.23-t1.0.1.html +++ b/kubescape-reports/cis-v1.23-t1.0.1.html @@ -320,10 +320,10 @@

Failed Resources:


-

Name: -datashield-opal

+

Name: -fhir-pseudonymizer

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -datashield-opal

+

Kind: Deployment

+

Name: -fhir-pseudonymizer

Namespace:

@@ -337,27 +337,47 @@

Name: -datashield-opal

- - - - + + + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[2].env[12].name

spec.template.spec.containers[2].env[16].name

spec.template.spec.containers[2].env[1].name

spec.template.spec.containers[2].env[4].name

spec.template.spec.containers[2].env[6].name

spec.template.spec.containers[2].env[8].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

+ + +

Name: -fhir-pseudonymizer-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-pseudonymizer-test-connection

+

Namespace:

+ + + + + + + + + + + - +
SeverityNameDocsAssisted Remediation
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps

+

Name: -recruit-postgres

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -vfps

+

Kind: StatefulSet

+

Name: -recruit-postgres

Namespace:

@@ -374,24 +394,24 @@

Name: -vfps

- + - +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[3].name

spec.template.spec.containers[0].env[4].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.runAsGroup=1000

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps-test-connection

+

Name: -fhir-pseudonymizer-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -415,10 +435,10 @@

Name: -vfps-test-connection

-

Name: -recruit-query

+

Name: -fhir-gateway-gateway

ApiVersion: apps/v1

Kind: Deployment

-

Name: -recruit-query

+

Name: -fhir-gateway-gateway

Namespace:

@@ -449,33 +469,6 @@

Name: -recruit-query

-

Name: -mailhog

-

ApiVersion: v1

-

Kind: ServiceAccount

-

Name: -mailhog

-

Namespace:

- - - - - - - - - - - - - - - - - - - -
SeverityNameDocsAssisted Remediation
MediumCIS-5.1.6 Ensure that Service Account Tokens are only mounted where necessaryC-0190

automountServiceAccountToken=false

- -

Name: -vfps-migrations-v1-3-5

ApiVersion: batch/v1

Kind: Job

@@ -510,10 +503,10 @@

Name: -vfps-migrations-v1-3-5

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -blaze-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -blaze-test-connection

Namespace:

@@ -530,17 +523,17 @@

Name: -fhir-pseudonymizer-test-connection

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -ohdsi-atlas

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -ohdsi-atlas

+

Name: -gateway-vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -gateway-vfps-migrations-v1-3-5

Namespace:

@@ -553,21 +546,28 @@

Name: -ohdsi-atlas

+ + + + + + + - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -datashield-rock

+

Name: -postgresql

ApiVersion: apps/v1

Kind: StatefulSet

-

Name: -datashield-rock

+

Name: -postgresql

Namespace:

@@ -584,24 +584,17 @@

Name: -datashield-rock

- - - - - - - - +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[2].env[4].name

spec.template.spec.containers[2].env[6].name

spec.template.spec.containers[2].env[8].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].env[4].name

-

Name: -gateway-vfps-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -gateway-vfps-test-connection

+

Name: -blaze

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -blaze

Namespace:

@@ -618,17 +611,17 @@

Name: -gateway-vfps-test-connection

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-gateway-gateway

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-gateway-gateway

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

@@ -652,17 +645,17 @@

Name: -fhir-gateway-gateway

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-gateway-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-gateway-test-connection

+

Name: -fhir-pseudonymizer

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-pseudonymizer

Namespace:

@@ -679,17 +672,17 @@

Name: -fhir-gateway-test-connection

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-pseudonymizer

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Name: -hapi-fhir-jpaserver-test-endpoints

+

ApiVersion: v1

+

Kind: Pod

+

Name: -hapi-fhir-jpaserver-test-endpoints

Namespace:

@@ -706,17 +699,17 @@

Name: -fhir-pseudonymizer

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -recruit-list

+

Name: -postgresql

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -recruit-list

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -730,20 +723,20 @@

Name: -recruit-list

- - - - + + + +
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

-

Name: -vfps-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -fhir-gateway-loinc-converter

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-gateway-loinc-converter

Namespace:

@@ -760,17 +753,17 @@

Name: -vfps-test-connection

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -postgresql

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -787,24 +780,17 @@

Name: -vfps-migrations-v1-3-5

- - - - - - - - +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[3].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].env[4].name

-

Name: -ohdsi-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -ohdsi-test-connection

+

Name: -postgresql

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -818,20 +804,20 @@

Name: -ohdsi-test-connection

- - - - + + + +
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

-

Name: -fhir-pseudonymizer-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -recruit-query

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -recruit-query

Namespace:

@@ -844,21 +830,28 @@

Name: -fhir-pseudonymizer-test-connection

+ + + + + + + - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps-postgres

+

Name: -datashield-rock

ApiVersion: apps/v1

Kind: StatefulSet

-

Name: -vfps-postgres

+

Name: -datashield-rock

Namespace:

@@ -875,17 +868,24 @@

Name: -vfps-postgres

- + + + + + + + +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[4].name

spec.template.spec.containers[2].env[4].name

spec.template.spec.containers[2].env[6].name

spec.template.spec.containers[2].env[8].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps

+

Name: -ohdsi-webapi

ApiVersion: apps/v1

Kind: Deployment

-

Name: -vfps

+

Name: -ohdsi-webapi

Namespace:

@@ -902,7 +902,7 @@

Name: -vfps

- + @@ -916,10 +916,10 @@

Name: -vfps

Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[3].name

spec.template.spec.containers[0].env[14].name

spec.template.spec.containers[0].env[4].name

-

Name: -blaze-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -blaze-test-connection

+

Name: -fhir-pseudonymizer

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-pseudonymizer

Namespace:

@@ -936,17 +936,17 @@

Name: -blaze-test-connection

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -postgresql

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -postgresql

+

Name: -gateway-vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -gateway-vfps-test-connection

Namespace:

@@ -960,20 +960,20 @@

Name: -postgresql

- - - - + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -recruit-postgres

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -recruit-postgres

+

Name: -datashield-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -datashield-test-connection

Namespace:

@@ -986,28 +986,21 @@

Name: -recruit-postgres

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.runAsGroup=1000

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -fhir-gateway-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-gateway-test-connection

Namespace:

@@ -1020,28 +1013,21 @@

Name: -vfps-migrations-v1-3-5

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -postgresql

+

Name: -vfps

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -postgresql

+

Kind: Deployment

+

Name: -vfps

Namespace:

@@ -1058,17 +1044,24 @@

Name: -postgresql

- + + + + + + + +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[4].name

spec.template.spec.containers[0].env[3].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -hapi-fhir-jpaserver-test-endpoints

+

Name: -recruit-test-health-probes

ApiVersion: v1

Kind: Pod

-

Name: -hapi-fhir-jpaserver-test-endpoints

+

Name: -recruit-test-health-probes

Namespace:

@@ -1092,10 +1085,10 @@

Name: -hapi-fhir-jpaserver-test-endpoints

-

Name: -vfps-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -vfps

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -vfps

Namespace:

@@ -1108,21 +1101,28 @@

Name: -vfps-test-connection

+ + + + + + + - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -datashield-test-connection

+

Name: -fhir-pseudonymizer-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -datashield-test-connection

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -1146,10 +1146,10 @@

Name: -datashield-test-connection

-

Name: -recruit-notify

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -recruit-notify

+

Name: -ohdsi-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -ohdsi-test-connection

Namespace:

@@ -1162,28 +1162,21 @@

Name: -recruit-notify

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[7].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps

+

Name: -postgresql

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -vfps

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -1200,24 +1193,24 @@

Name: -vfps

- + - +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[3].name

spec.template.spec.containers[0].env[4].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.runAsGroup=1000

-

Name: -mailhog

+

Name: -recruit-list

ApiVersion: apps/v1

Kind: Deployment

-

Name: -mailhog

+

Name: -recruit-list

Namespace:

@@ -1234,17 +1227,17 @@

Name: -mailhog

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -hapi-fhir-jpaserver

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -hapi-fhir-jpaserver

+

Name: -vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -vfps-test-connection

Namespace:

@@ -1257,28 +1250,21 @@

Name: -hapi-fhir-jpaserver

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[2].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -postgresql

+

Name: -mailhog

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -postgresql

+

Kind: Deployment

+

Name: -mailhog

Namespace:

@@ -1292,20 +1278,20 @@

Name: -postgresql

- - - - + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -gateway-vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -gateway-vfps-migrations-v1-3-5

+

Name: -vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -vfps-test-connection

Namespace:

@@ -1318,28 +1304,21 @@

Name: -gateway-vfps-migrations-v1-3-5

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -vfps-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -vfps-test-connection

Namespace:

@@ -1363,10 +1342,10 @@

Name: -fhir-pseudonymizer-test-connection

-

Name: -postgresql

+

Name: -ohdsi-postgres

ApiVersion: apps/v1

Kind: StatefulSet

-

Name: -postgresql

+

Name: -ohdsi-postgres

Namespace:

@@ -1390,10 +1369,10 @@

Name: -postgresql

-

Name: -ohdsi-webapi

+

Name: -datashield-opal

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -ohdsi-webapi

+

Kind: StatefulSet

+

Name: -datashield-opal

Namespace:

@@ -1410,24 +1389,24 @@

Name: -ohdsi-webapi

- + - +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[14].name

spec.template.spec.containers[0].env[4].name

spec.template.spec.containers[2].env[12].name

spec.template.spec.containers[2].env[16].name

spec.template.spec.containers[2].env[1].name

spec.template.spec.containers[2].env[4].name

spec.template.spec.containers[2].env[6].name

spec.template.spec.containers[2].env[8].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -recruit-test-health-probes

-

ApiVersion: v1

-

Kind: Pod

-

Name: -recruit-test-health-probes

+

Name: -recruit-notify

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -recruit-notify

Namespace:

@@ -1440,21 +1419,28 @@

Name: -recruit-test-health-probes

+ + + + + + + - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[7].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -postgresql

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -postgresql

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

@@ -1471,17 +1457,24 @@

Name: -postgresql

- + + + + + + + +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[4].name

spec.template.spec.containers[0].env[3].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-pseudonymizer

+

Name: -hapi-fhir-jpaserver

ApiVersion: apps/v1

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Name: -hapi-fhir-jpaserver

Namespace:

@@ -1494,6 +1487,13 @@

Name: -fhir-pseudonymizer

+ + + + + + + @@ -1505,10 +1505,10 @@

Name: -fhir-pseudonymizer

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[2].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers
-

Name: -gateway-vfps

+

Name: -vfps-postgres

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -gateway-vfps

+

Kind: StatefulSet

+

Name: -vfps-postgres

Namespace:

@@ -1525,24 +1525,17 @@

Name: -gateway-vfps

- - - - - - - - +
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[3].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].env[4].name

-

Name: -ohdsi-postgres

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -ohdsi-postgres

+

Name: -mailhog

+

ApiVersion: v1

+

Kind: ServiceAccount

+

Name: -mailhog

Namespace:

@@ -1557,19 +1550,19 @@

Name: -ohdsi-postgres

- - - + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

CIS-5.1.6 Ensure that Service Account Tokens are only mounted where necessaryC-0190

automountServiceAccountToken=false

-

Name: -fhir-pseudonymizer

+

Name: -gateway-vfps

ApiVersion: apps/v1

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Name: -gateway-vfps

Namespace:

@@ -1582,6 +1575,13 @@

Name: -fhir-pseudonymizer

+ + + + + + + @@ -1593,10 +1593,10 @@

Name: -fhir-pseudonymizer

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers
-

Name: -fhir-gateway-loinc-converter

+

Name: -postgresql

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-gateway-loinc-converter

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -1610,20 +1610,20 @@

Name: -fhir-gateway-loinc-converter

- - - - + + + +
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

-

Name: -blaze

+

Name: -vfps

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -blaze

+

Kind: Deployment

+

Name: -vfps

Namespace:

@@ -1636,21 +1636,28 @@

Name: -blaze

+ + + + + + + - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -postgresql

+

Name: -ohdsi-atlas

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -postgresql

+

Kind: Deployment

+

Name: -ohdsi-atlas

Namespace:

@@ -1663,18 +1670,11 @@

Name: -postgresql

- - - - - - - - + diff --git a/kubescape-reports/nsa.html b/kubescape-reports/nsa.html index d009073c..9f12aab9 100644 --- a/kubescape-reports/nsa.html +++ b/kubescape-reports/nsa.html @@ -284,10 +284,10 @@

Failed Resources:


-

Name: -mailhog

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -mailhog

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.runAsGroup=1000

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

@@ -300,20 +300,6 @@

Name: -mailhog

- - - - - - - - - - - - - - @@ -325,10 +311,10 @@

Name: -mailhog

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -recruit-notify

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -recruit-notify

Namespace:

@@ -341,13 +327,6 @@

Name: -vfps-migrations-v1-3-5

- - - - - - - @@ -362,6 +341,13 @@

Name: -vfps-migrations-v1-3-5

+ + + + + + +
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

High Ensure memory limits are set
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

@@ -382,13 +368,6 @@

Name: -recruit-query

- - High - Ensure CPU limits are set - C-0270 -

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

- - High Ensure memory limits are set @@ -403,14 +382,21 @@

Name: -recruit-query

+ + High + Ensure CPU limits are set + C-0270 +

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

+ + -

Name: -fhir-pseudonymizer-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -fhir-gateway-gateway

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-gateway-gateway

Namespace:

@@ -434,10 +420,10 @@

Name: -fhir-pseudonymizer-test-connection

-

Name: -fhir-pseudonymizer

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

@@ -461,10 +447,10 @@

Name: -fhir-pseudonymizer

-

Name: -blaze

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -blaze

+

Name: -vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -vfps-test-connection

Namespace:

@@ -488,10 +474,10 @@

Name: -blaze

-

Name: -fhir-gateway-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-gateway-test-connection

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

@@ -504,6 +490,13 @@

Name: -fhir-gateway-test-connection

+ + + + + + + @@ -511,14 +504,21 @@

Name: -fhir-gateway-test-connection

+ + + + + + +
HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

-

Name: -hapi-fhir-jpaserver

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -hapi-fhir-jpaserver

+

Name: -blaze-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -blaze-test-connection

Namespace:

@@ -531,20 +531,6 @@

Name: -hapi-fhir-jpaserver

- - - - - - - - - - - - - - @@ -556,10 +542,10 @@

Name: -hapi-fhir-jpaserver

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -fhir-gateway-gateway

+

Name: -fhir-pseudonymizer

ApiVersion: apps/v1

Kind: Deployment

-

Name: -fhir-gateway-gateway

+

Name: -fhir-pseudonymizer

Namespace:

@@ -583,10 +569,10 @@

Name: -fhir-gateway-gateway

-

Name: -vfps-test-connection

+

Name: -ohdsi-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -ohdsi-test-connection

Namespace:

@@ -599,6 +585,13 @@

Name: -vfps-test-connection

+ + + + + + + @@ -606,14 +599,21 @@

Name: -vfps-test-connection

+ + + + + + +
HighEnsure memory limits are setC-0271

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
HighEnsure CPU limits are setC-0270

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.containers[0].resources.limits.cpu=YOUR_VALUE

-

Name: -postgresql

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -postgresql

+

Name: -hapi-fhir-jpaserver-test-endpoints

+

ApiVersion: v1

+

Kind: Pod

+

Name: -hapi-fhir-jpaserver-test-endpoints

Namespace:

@@ -626,35 +626,35 @@

Name: -postgresql

- - - - - - - - + - - - + + + + + + + + + +
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

High Ensure memory limits are set C-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[2].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

MediumNon-root containersC-0013

spec.template.spec.containers[0].securityContext.runAsGroup=1000

Ingress and Egress blockedC-0030
HighEnsure CPU limits are setC-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[2].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

-

Name: -fhir-pseudonymizer

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Name: -recruit-test-health-probes

+

ApiVersion: v1

+

Kind: Pod

+

Name: -recruit-test-health-probes

Namespace:

@@ -667,6 +667,13 @@

Name: -fhir-pseudonymizer

+ + + + + + + @@ -674,6 +681,13 @@

Name: -fhir-pseudonymizer

+ + + + + + +
HighEnsure memory limits are setC-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[2].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
HighEnsure CPU limits are setC-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[2].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

@@ -694,13 +708,6 @@

Name: -vfps

- - High - Ensure CPU limits are set - C-0270 -

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

- - High Ensure memory limits are set @@ -715,14 +722,21 @@

Name: -vfps

+ + High + Ensure CPU limits are set + C-0270 +

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

+ + -

Name: -vfps

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -vfps

+

Name: -fhir-pseudonymizer-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -735,6 +749,13 @@

Name: -vfps

+ + + + + + + @@ -742,14 +763,21 @@

Name: -vfps

+ + + + + + +
HighEnsure memory limits are setC-0271

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
HighEnsure CPU limits are setC-0270

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.containers[0].resources.limits.cpu=YOUR_VALUE

-

Name: -vfps-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -fhir-pseudonymizer

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-pseudonymizer

Namespace:

@@ -773,10 +801,10 @@

Name: -vfps-test-connection

-

Name: -fhir-pseudonymizer

+

Name: -fhir-gateway-loinc-converter

ApiVersion: apps/v1

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Name: -fhir-gateway-loinc-converter

Namespace:

@@ -790,34 +818,20 @@

Name: -fhir-pseudonymizer

- - - - - - - - - - - - - - - - - - + + + +
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

MediumIngress and Egress blockedC-0030MediumIngress and Egress blockedC-0030
-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -ohdsi-atlas

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -ohdsi-atlas

Namespace:

@@ -830,6 +844,13 @@

Name: -vfps-migrations-v1-3-5

+ + + + + + + @@ -837,14 +858,28 @@

Name: -vfps-migrations-v1-3-5

+ + + + + + + + + + + + + +
HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

LowImmutable container filesystemC-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

-

Name: -datashield-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -datashield-test-connection

+

Name: -ohdsi-webapi

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -ohdsi-webapi

Namespace:

@@ -857,6 +892,13 @@

Name: -datashield-test-connection

+ + + + + + + @@ -864,14 +906,21 @@

Name: -datashield-test-connection

+ + + + + + +
HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

-

Name: -gateway-vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -gateway-vfps-migrations-v1-3-5

+

Name: -fhir-pseudonymizer

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-pseudonymizer

Namespace:

@@ -884,6 +933,13 @@

Name: -gateway-vfps-migrations-v1-3-5

+ + + + + + + @@ -891,14 +947,21 @@

Name: -gateway-vfps-migrations-v1-3-5

+ + + + + + +
HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

-

Name: -hapi-fhir-jpaserver-test-endpoints

+

Name: -datashield-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -hapi-fhir-jpaserver-test-endpoints

+

Name: -datashield-test-connection

Namespace:

@@ -911,20 +974,6 @@

Name: -hapi-fhir-jpaserver-test-endpoints

- - - - - - - - - - - - - - @@ -936,10 +985,10 @@

Name: -hapi-fhir-jpaserver-test-endpoints

HighEnsure CPU limits are setC-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[2].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[2].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -recruit-notify

+

Name: -blaze

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -recruit-notify

+

Kind: StatefulSet

+

Name: -blaze

Namespace:

@@ -952,20 +1001,6 @@

Name: -recruit-notify

- - - - - - - - - - - - - - @@ -977,10 +1012,10 @@

Name: -recruit-notify

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -fhir-gateway-loinc-converter

+

Name: -datashield-rock

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-gateway-loinc-converter

+

Kind: StatefulSet

+

Name: -datashield-rock

Namespace:

@@ -1004,10 +1039,10 @@

Name: -fhir-gateway-loinc-converter

-

Name: -recruit-test-health-probes

-

ApiVersion: v1

-

Kind: Pod

-

Name: -recruit-test-health-probes

+

Name: -hapi-fhir-jpaserver

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -hapi-fhir-jpaserver

Namespace:

@@ -1020,18 +1055,11 @@

Name: -recruit-test-health-probes

- - - - - - - - + @@ -1041,14 +1069,21 @@

Name: -recruit-test-health-probes

+ + + + + + +
HighEnsure CPU limits are setC-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[2].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

High Ensure memory limits are set C-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[2].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

-

Name: -vfps-test-connection

+

Name: -fhir-gateway-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -fhir-gateway-test-connection

Namespace:

@@ -1061,20 +1096,6 @@

Name: -vfps-test-connection

- - - - - - - - - - - - - - @@ -1086,10 +1107,10 @@

Name: -vfps-test-connection

HighEnsure CPU limits are setC-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -gateway-vfps

+

Name: -vfps

ApiVersion: apps/v1

Kind: Deployment

-

Name: -gateway-vfps

+

Name: -vfps

Namespace:

@@ -1113,10 +1134,10 @@

Name: -gateway-vfps

-

Name: -datashield-rock

+

Name: -vfps

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -datashield-rock

+

Kind: Deployment

+

Name: -vfps

Namespace:

@@ -1140,10 +1161,10 @@

Name: -datashield-rock

-

Name: -gateway-vfps-test-connection

+

Name: -vfps-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -gateway-vfps-test-connection

+

Name: -vfps-test-connection

Namespace:

@@ -1167,10 +1188,10 @@

Name: -gateway-vfps-test-connection

-

Name: -blaze-test-connection

+

Name: -mailhog

ApiVersion: v1

-

Kind: Pod

-

Name: -blaze-test-connection

+

Kind: ServiceAccount

+

Name: -mailhog

Namespace:

@@ -1185,9 +1206,9 @@

Name: -blaze-test-connection

- - - + + + @@ -1210,13 +1231,6 @@

Name: -recruit-list

- - - - - - - @@ -1231,6 +1245,13 @@

Name: -recruit-list

+ + + + + + + @@ -1242,10 +1263,10 @@

Name: -recruit-list

MediumIngress and Egress blockedC-0030Automatic mapping of service accountC-0034

automountServiceAccountToken=false

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

High Ensure memory limits are set
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

High Applications credentials in configuration files
-

Name: -ohdsi-webapi

+

Name: -mailhog

ApiVersion: apps/v1

Kind: Deployment

-

Name: -ohdsi-webapi

+

Name: -mailhog

Namespace:

@@ -1258,13 +1279,6 @@

Name: -ohdsi-webapi

- - - - - - - @@ -1279,14 +1293,21 @@

Name: -ohdsi-webapi

+ + + + + + +
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

High Ensure memory limits are set
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

-

Name: -fhir-pseudonymizer-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -postgresql

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -1301,19 +1322,33 @@

Name: -fhir-pseudonymizer-test-connection

- - - + + + + + + + + + + + + + + + + +
MediumIngress and Egress blockedC-0030Non-root containersC-0013

spec.template.spec.containers[0].securityContext.runAsGroup=1000

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

-

Name: -ohdsi-atlas

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -ohdsi-atlas

+

Name: -fhir-pseudonymizer-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -1326,27 +1361,6 @@

Name: -ohdsi-atlas

- - - - - - - - - - - - - - - - - - - - - @@ -1358,10 +1372,10 @@

Name: -ohdsi-atlas

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

LowImmutable container filesystemC-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

Medium Ingress and Egress blocked
-

Name: -recruit-postgres

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -recruit-postgres

+

Name: -gateway-vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -gateway-vfps-migrations-v1-3-5

Namespace:

@@ -1374,34 +1388,6 @@

Name: -recruit-postgres

- - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -1413,10 +1399,10 @@

Name: -recruit-postgres

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

MediumNon-root containersC-0013

spec.template.spec.containers[0].securityContext.runAsGroup=1000

LowImmutable container filesystemC-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

Medium Ingress and Egress blocked
-

Name: -vfps

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -vfps

+

Name: -fhir-pseudonymizer-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -1440,10 +1426,10 @@

Name: -vfps

-

Name: -datashield-opal

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -datashield-opal

+

Name: -vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -vfps-test-connection

Namespace:

@@ -1457,10 +1443,10 @@

Name: -datashield-opal

- - - - + + + + @@ -1470,14 +1456,21 @@

Name: -datashield-opal

+ + + + + + +
LowImmutable container filesystemC-0017

spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true

HighEnsure memory limits are setC-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

HighEnsure CPU limits are setC-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -gateway-vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -gateway-vfps-test-connection

Namespace:

@@ -1501,10 +1494,10 @@

Name: -vfps-migrations-v1-3-5

-

Name: -ohdsi-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -ohdsi-test-connection

+

Name: -recruit-postgres

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -recruit-postgres

Namespace:

@@ -1518,17 +1511,17 @@

Name: -ohdsi-test-connection

- - - - + + + + - + @@ -1538,14 +1531,28 @@

Name: -ohdsi-test-connection

+ + + + + + + + + + + + + +
HighEnsure CPU limits are setC-0270

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.containers[0].resources.limits.cpu=YOUR_VALUE

MediumNon-root containersC-0013

spec.template.spec.containers[0].securityContext.runAsGroup=1000

High Ensure memory limits are set C-0271

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

LowImmutable container filesystemC-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

-

Name: -fhir-pseudonymizer-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -gateway-vfps

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -gateway-vfps

Namespace:

@@ -1558,20 +1565,6 @@

Name: -fhir-pseudonymizer-test-connection

- - - - - - - - - - - - - - @@ -1583,10 +1576,10 @@

Name: -fhir-pseudonymizer-test-connection

HighEnsure CPU limits are setC-0270

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -mailhog

-

ApiVersion: v1

-

Kind: ServiceAccount

-

Name: -mailhog

+

Name: -datashield-opal

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -datashield-opal

Namespace:

@@ -1601,9 +1594,16 @@

Name: -mailhog

- - - + + + + + + + + + +
MediumAutomatic mapping of service accountC-0034

automountServiceAccountToken=false

Ingress and Egress blockedC-0030
LowImmutable container filesystemC-0017

spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true