From d03760bd561fe8bff89ec2905c3491ded8f122a3 Mon Sep 17 00:00:00 2001 From: chgl Date: Tue, 17 Dec 2024 00:18:57 +0000 Subject: [PATCH] docs: updated kubescape reports --- kubescape-reports/cis-v1.23-t1.0.1.html | 676 ++++++++++++------------ kubescape-reports/nsa.html | 584 ++++++++++---------- 2 files changed, 630 insertions(+), 630 deletions(-) diff --git a/kubescape-reports/cis-v1.23-t1.0.1.html b/kubescape-reports/cis-v1.23-t1.0.1.html index ed2db7c2..12dd2eb3 100644 --- a/kubescape-reports/cis-v1.23-t1.0.1.html +++ b/kubescape-reports/cis-v1.23-t1.0.1.html @@ -320,10 +320,10 @@

Failed Resources:


-

Name: -recruit-postgres

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -recruit-postgres

+

Name: -fhir-pseudonymizer-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -336,28 +336,21 @@

Name: -recruit-postgres

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.runAsGroup=1000

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-gateway-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-gateway-test-connection

+

Name: -gateway-vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -gateway-vfps-migrations-v1-3-5

Namespace:

@@ -374,17 +367,24 @@

Name: -fhir-gateway-test-connection

- + + + + + + + +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

-

Name: -vfps

+

Name: -fhir-gateway-gateway

ApiVersion: apps/v1

Kind: Deployment

-

Name: -vfps

+

Name: -fhir-gateway-gateway

Namespace:

@@ -397,13 +397,6 @@

Name: -vfps

- - - - - - - @@ -411,6 +404,13 @@

Name: -vfps

+ + + + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

@@ -442,10 +442,10 @@

Name: -postgresql

-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -recruit-test-health-probes

+

ApiVersion: v1

+

Kind: Pod

+

Name: -recruit-test-health-probes

Namespace:

@@ -458,28 +458,48 @@

Name: -vfps-migrations-v1-3-5

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -postgresql

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -postgresql

+

Namespace:

+ + + + + + + + + + + + + + + + + + + +
SeverityNameDocsAssisted Remediation
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

+ + +

Name: -recruit-list

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -recruit-list

Namespace:

@@ -496,17 +516,17 @@

Name: -vfps-test-connection

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -gateway-vfps-test-connection

+

Name: -vfps-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -gateway-vfps-test-connection

+

Name: -vfps-test-connection

Namespace:

@@ -530,10 +550,10 @@

Name: -gateway-vfps-test-connection

-

Name: -ohdsi-postgres

+

Name: -postgresql

ApiVersion: apps/v1

Kind: StatefulSet

-

Name: -ohdsi-postgres

+

Name: -postgresql

Namespace:

@@ -546,6 +566,13 @@

Name: -ohdsi-postgres

+ + + + + + + @@ -557,10 +584,10 @@

Name: -ohdsi-postgres

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.runAsGroup=1000

Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables
-

Name: -recruit-query

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -recruit-query

+

Name: -fhir-pseudonymizer-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -574,27 +601,47 @@

Name: -recruit-query

- - - - + + + + + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

+ + +

Name: -hapi-fhir-jpaserver-test-endpoints

+

ApiVersion: v1

+

Kind: Pod

+

Name: -hapi-fhir-jpaserver-test-endpoints

+

Namespace:

+ + + + + + + + + - +
SeverityNameDocsAssisted Remediation
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-gateway-loinc-converter

+

Name: -fhir-pseudonymizer

ApiVersion: apps/v1

Kind: Deployment

-

Name: -fhir-gateway-loinc-converter

+

Name: -fhir-pseudonymizer

Namespace:

@@ -618,10 +665,10 @@

Name: -fhir-gateway-loinc-converter

-

Name: -mailhog

-

ApiVersion: v1

-

Kind: ServiceAccount

-

Name: -mailhog

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

@@ -634,21 +681,28 @@

Name: -mailhog

+ + + + + + + - - - + + +
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.1.6 Ensure that Service Account Tokens are only mounted where necessaryC-0190

automountServiceAccountToken=false

CIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

-

Name: -postgresql

+

Name: -ohdsi-atlas

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -postgresql

+

Kind: Deployment

+

Name: -ohdsi-atlas

Namespace:

@@ -662,20 +716,20 @@

Name: -postgresql

- - - - + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -hapi-fhir-jpaserver-test-endpoints

-

ApiVersion: v1

-

Kind: Pod

-

Name: -hapi-fhir-jpaserver-test-endpoints

+

Name: -hapi-fhir-jpaserver

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -hapi-fhir-jpaserver

Namespace:

@@ -692,17 +746,24 @@

Name: -hapi-fhir-jpaserver-test-endpoints

- + + + + + + + +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[2].name

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -datashield-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -datashield-test-connection

Namespace:

@@ -726,10 +787,10 @@

Name: -fhir-pseudonymizer-test-connection

-

Name: -fhir-pseudonymizer

+

Name: -ohdsi-postgres

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Kind: StatefulSet

+

Name: -ohdsi-postgres

Namespace:

@@ -743,20 +804,20 @@

Name: -fhir-pseudonymizer

- - - - + + + +
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

-

Name: -blaze

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -blaze

+

Name: -gateway-vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -gateway-vfps-test-connection

Namespace:

@@ -773,7 +834,7 @@

Name: -blaze

- + @@ -807,10 +868,10 @@

Name: -blaze-test-connection

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -recruit-notify

+

Name: -ohdsi-webapi

ApiVersion: apps/v1

Kind: Deployment

-

Name: -recruit-notify

+

Name: -ohdsi-webapi

Namespace:

@@ -823,13 +884,6 @@

Name: -recruit-notify

- - - - - - - @@ -837,14 +891,21 @@

Name: -recruit-notify

- -
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[7].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

+ + Medium + CIS-5.4.1 Prefer using secrets as files over secrets as environment variables + C-0207 +

spec.template.spec.containers[0].env[14].name

spec.template.spec.containers[0].env[4].name

+ + + + -

Name: -vfps-postgres

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -vfps-postgres

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

@@ -857,21 +918,28 @@

Name: -vfps-postgres

+ + + + + + + - +
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[4].name

spec.template.spec.containers[0].env[3].name

-

Name: -datashield-opal

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -datashield-opal

+

Name: -vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -vfps-test-connection

Namespace:

@@ -884,28 +952,21 @@

Name: -datashield-opal

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[2].env[12].name

spec.template.spec.containers[2].env[16].name

spec.template.spec.containers[2].env[1].name

spec.template.spec.containers[2].env[4].name

spec.template.spec.containers[2].env[6].name

spec.template.spec.containers[2].env[8].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-pseudonymizer

+

Name: -recruit-query

ApiVersion: apps/v1

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Name: -recruit-query

Namespace:

@@ -925,14 +986,21 @@

Name: -fhir-pseudonymizer

+ + + + + + +

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

-

Name: -postgresql

+

Name: -datashield-rock

ApiVersion: apps/v1

Kind: StatefulSet

-

Name: -postgresql

+

Name: -datashield-rock

Namespace:

@@ -945,28 +1013,28 @@

Name: -postgresql

- - - - - - - - + + + + + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.runAsGroup=1000

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[2].env[4].name

spec.template.spec.containers[2].env[6].name

spec.template.spec.containers[2].env[8].name

-

Name: -vfps-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -postgresql

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -980,20 +1048,20 @@

Name: -vfps-test-connection

- - - - + + + +
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

-

Name: -vfps

+

Name: -fhir-pseudonymizer

ApiVersion: apps/v1

Kind: Deployment

-

Name: -vfps

+

Name: -fhir-pseudonymizer

Namespace:

@@ -1006,13 +1074,6 @@

Name: -vfps

- - - - - - - @@ -1024,10 +1085,10 @@

Name: -vfps

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers
-

Name: -ohdsi-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -ohdsi-test-connection

+

Name: -fhir-gateway-loinc-converter

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-gateway-loinc-converter

Namespace:

@@ -1044,17 +1105,17 @@

Name: -ohdsi-test-connection

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -vfps

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -vfps

Namespace:

@@ -1067,6 +1128,13 @@

Name: -vfps-migrations-v1-3-5

+ + + + + + + @@ -1074,21 +1142,14 @@

Name: -vfps-migrations-v1-3-5

- - - - - - -
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables

spec.template.spec.containers[0].env[3].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-gateway-gateway

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-gateway-gateway

+

Name: -mailhog

+

ApiVersion: v1

+

Kind: ServiceAccount

+

Name: -mailhog

Namespace:

@@ -1103,26 +1164,19 @@

Name: -fhir-gateway-gateway

- - - - - - - - - - + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

CIS-5.1.6 Ensure that Service Account Tokens are only mounted where necessaryC-0190

automountServiceAccountToken=false

-

Name: -ohdsi-webapi

+

Name: -recruit-notify

ApiVersion: apps/v1

Kind: Deployment

-

Name: -ohdsi-webapi

+

Name: -recruit-notify

Namespace:

@@ -1135,13 +1189,6 @@

Name: -ohdsi-webapi

- - - - - - - @@ -1149,14 +1196,21 @@

Name: -ohdsi-webapi

+ + + + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[14].name

spec.template.spec.containers[0].env[4].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[7].name

-

Name: -fhir-pseudonymizer-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -mailhog

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -mailhog

Namespace:

@@ -1173,17 +1227,17 @@

Name: -fhir-pseudonymizer-test-connection

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -postgresql

+

Name: -blaze

ApiVersion: apps/v1

Kind: StatefulSet

-

Name: -postgresql

+

Name: -blaze

Namespace:

@@ -1197,20 +1251,20 @@

Name: -postgresql

- - - - + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -datashield-rock

+

Name: -gateway-vfps

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -datashield-rock

+

Kind: Deployment

+

Name: -gateway-vfps

Namespace:

@@ -1223,18 +1277,18 @@

Name: -datashield-rock

- - - - - - - - + + + + + + + + @@ -1268,10 +1322,10 @@

Name: -postgresql

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[2].env[4].name

spec.template.spec.containers[2].env[6].name

spec.template.spec.containers[2].env[8].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

-

Name: -gateway-vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -gateway-vfps-migrations-v1-3-5

+

Name: -ohdsi-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -ohdsi-test-connection

Namespace:

@@ -1284,28 +1338,21 @@

Name: -gateway-vfps-migrations-v1-3-5

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -ohdsi-atlas

+

Name: -vfps

ApiVersion: apps/v1

Kind: Deployment

-

Name: -ohdsi-atlas

+

Name: -vfps

Namespace:

@@ -1322,17 +1369,24 @@

Name: -ohdsi-atlas

- + + + + + + + +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

-

Name: -recruit-list

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -recruit-list

+

Name: -fhir-gateway-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-gateway-test-connection

Namespace:

@@ -1349,7 +1403,7 @@

Name: -recruit-list

- + @@ -1383,10 +1437,10 @@

Name: -fhir-pseudonymizer-test-connection

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -fhir-pseudonymizer

+

Name: -postgresql

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -1400,20 +1454,20 @@

Name: -fhir-pseudonymizer

- - - - + + + +
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

-

Name: -recruit-test-health-probes

-

ApiVersion: v1

-

Kind: Pod

-

Name: -recruit-test-health-probes

+

Name: -recruit-postgres

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -recruit-postgres

Namespace:

@@ -1430,17 +1484,24 @@

Name: -recruit-test-health-probes

- + + + + + + + +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.runAsGroup=1000

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[4].name

-

Name: -hapi-fhir-jpaserver

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -hapi-fhir-jpaserver

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

@@ -1453,28 +1514,28 @@

Name: -hapi-fhir-jpaserver

- - - - - - - - + + + + + + + +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[2].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

-

Name: -vfps-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -fhir-pseudonymizer

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-pseudonymizer

Namespace:

@@ -1491,17 +1552,17 @@

Name: -vfps-test-connection

- +
High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -vfps-test-connection

Namespace:

@@ -1514,28 +1575,21 @@

Name: -vfps-migrations-v1-3-5

- - - - - - - - +
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -postgresql

+

Name: -vfps-postgres

ApiVersion: apps/v1

Kind: StatefulSet

-

Name: -postgresql

+

Name: -vfps-postgres

Namespace:

@@ -1575,13 +1629,6 @@

Name: -vfps

- - - - - - - @@ -1589,53 +1636,6 @@

Name: -vfps

- -
MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[0].env[3].name

High CIS-5.7.3 Apply Security Context to Your Pods and Containers

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

- - -

Name: -mailhog

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -mailhog

-

Namespace:

- - - - - - - - - - - - - - - - - - - -
SeverityNameDocsAssisted Remediation
HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

- - -

Name: -gateway-vfps

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -gateway-vfps

-

Namespace:

- - - - - - - - - - - @@ -1643,21 +1643,14 @@

Name: -gateway-vfps

- - - - - - -
SeverityNameDocsAssisted Remediation
Medium CIS-5.4.1 Prefer using secrets as files over secrets as environment variables

spec.template.spec.containers[0].env[3].name

HighCIS-5.7.3 Apply Security Context to Your Pods and ContainersC-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroup=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

-

Name: -datashield-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -datashield-test-connection

+

Name: -datashield-opal

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -datashield-opal

Namespace:

@@ -1674,7 +1667,14 @@

Name: -datashield-test-connection

- + + + + + + + + diff --git a/kubescape-reports/nsa.html b/kubescape-reports/nsa.html index 13c8f8d4..c1d2ab0f 100644 --- a/kubescape-reports/nsa.html +++ b/kubescape-reports/nsa.html @@ -284,10 +284,10 @@

Failed Resources:


-

Name: -ohdsi-atlas

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -ohdsi-atlas

+

Name: -gateway-vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -gateway-vfps-migrations-v1-3-5

Namespace:

High CIS-5.7.3 Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.securityContext.sysctls.name=YOUR_VALUE

spec.securityContext.sysctls.value=YOUR_VALUE

spec.securityContext.supplementalGroups=YOUR_VALUE

spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

spec.template.spec.securityContext.sysctls.name=YOUR_VALUE

spec.template.spec.securityContext.sysctls.value=YOUR_VALUE

spec.template.spec.securityContext.supplementalGroups=YOUR_VALUE

MediumCIS-5.4.1 Prefer using secrets as files over secrets as environment variablesC-0207

spec.template.spec.containers[2].env[12].name

spec.template.spec.containers[2].env[16].name

spec.template.spec.containers[2].env[1].name

spec.template.spec.containers[2].env[4].name

spec.template.spec.containers[2].env[6].name

spec.template.spec.containers[2].env[8].name

@@ -301,25 +301,31 @@

Name: -ohdsi-atlas

- - - - - - - - - - - + + + + + +
HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

MediumIngress and Egress blockedC-0030
+ + +

Name: -vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -vfps-test-connection

+

Namespace:

+ + - - - - + + + + + + @@ -332,10 +338,10 @@

Name: -ohdsi-atlas

LowImmutable container filesystemC-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

SeverityNameDocsAssisted Remediation
Medium
-

Name: -gateway-vfps-test-connection

+

Name: -hapi-fhir-jpaserver-test-endpoints

ApiVersion: v1

Kind: Pod

-

Name: -gateway-vfps-test-connection

+

Name: -hapi-fhir-jpaserver-test-endpoints

Namespace:

@@ -348,6 +354,20 @@

Name: -gateway-vfps-test-connection

+ + + + + + + + + + + + + + @@ -359,10 +379,10 @@

Name: -gateway-vfps-test-connection

HighEnsure CPU limits are setC-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[2].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[2].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -datashield-opal

+

Name: -recruit-postgres

ApiVersion: apps/v1

Kind: StatefulSet

-

Name: -datashield-opal

+

Name: -recruit-postgres

Namespace:

@@ -375,11 +395,32 @@

Name: -datashield-opal

+ + + + + + + - + + + + + + + + + + + + + + + @@ -393,10 +434,10 @@

Name: -datashield-opal

MediumNon-root containersC-0013

spec.template.spec.containers[0].securityContext.runAsGroup=1000

Low Immutable container filesystem C-0017

spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

-

Name: -vfps

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -vfps

+

Name: -vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -vfps-test-connection

Namespace:

@@ -413,14 +454,14 @@

Name: -vfps

- + - + @@ -475,10 +516,10 @@

Name: -hapi-fhir-jpaserver

High Ensure CPU limits are set C-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

High Ensure memory limits are set C-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

-

Name: -blaze-test-connection

+

Name: -vfps-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -blaze-test-connection

+

Name: -vfps-test-connection

Namespace:

@@ -502,10 +543,10 @@

Name: -blaze-test-connection

-

Name: -hapi-fhir-jpaserver-test-endpoints

+

Name: -datashield-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -hapi-fhir-jpaserver-test-endpoints

+

Name: -datashield-test-connection

Namespace:

@@ -518,20 +559,6 @@

Name: -hapi-fhir-jpaserver-test-endpoints

- - - - - - - - - - - - - - @@ -543,10 +570,10 @@

Name: -hapi-fhir-jpaserver-test-endpoints

HighEnsure CPU limits are setC-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[2].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[2].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -mailhog

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -mailhog

Namespace:

@@ -584,10 +611,10 @@

Name: -vfps-migrations-v1-3-5

-

Name: -recruit-query

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -recruit-query

+

Name: -fhir-gateway-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-gateway-test-connection

Namespace:

@@ -600,20 +627,6 @@

Name: -recruit-query

- - - - - - - - - - - - - - @@ -625,10 +638,10 @@

Name: -recruit-query

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -recruit-postgres

+

Name: -recruit-notify

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -recruit-postgres

+

Kind: Deployment

+

Name: -recruit-notify

Namespace:

@@ -648,13 +661,6 @@

Name: -recruit-postgres

- - - - - - - @@ -662,13 +668,6 @@

Name: -recruit-postgres

- - - - - - - @@ -707,10 +706,10 @@

Name: -datashield-rock

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

MediumNon-root containersC-0013

spec.template.spec.containers[0].securityContext.runAsGroup=1000

High Ensure memory limits are set

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

LowImmutable container filesystemC-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

Medium Ingress and Egress blocked
-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -gateway-vfps-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -gateway-vfps-test-connection

Namespace:

@@ -734,10 +733,10 @@

Name: -vfps-migrations-v1-3-5

-

Name: -fhir-gateway-gateway

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-gateway-gateway

+

Name: -ohdsi-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -ohdsi-test-connection

Namespace:

@@ -751,31 +750,18 @@

Name: -fhir-gateway-gateway

- - - - + + + + - -
MediumIngress and Egress blockedC-0030HighEnsure CPU limits are setC-0270

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.containers[0].resources.limits.cpu=YOUR_VALUE

- - -

Name: -gateway-vfps

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -gateway-vfps

-

Namespace:

- - - - - - + + + + - - @@ -788,10 +774,10 @@

Name: -gateway-vfps

SeverityNameDocsAssisted RemediationHighEnsure memory limits are setC-0271

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium
-

Name: -blaze

-

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -blaze

+

Name: -recruit-test-health-probes

+

ApiVersion: v1

+

Kind: Pod

+

Name: -recruit-test-health-probes

Namespace:

@@ -805,31 +791,18 @@

Name: -blaze

- - - - + + + + - -
MediumIngress and Egress blockedC-0030HighEnsure CPU limits are setC-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[2].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

- - -

Name: -datashield-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -datashield-test-connection

-

Namespace:

- - - - - - + + + + - - @@ -842,10 +815,10 @@

Name: -datashield-test-connection

SeverityNameDocsAssisted RemediationHighEnsure memory limits are setC-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[2].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

Medium
-

Name: -vfps

+

Name: -ohdsi-atlas

ApiVersion: apps/v1

Kind: Deployment

-

Name: -vfps

+

Name: -ohdsi-atlas

Namespace:

@@ -859,31 +832,11 @@

Name: -vfps

- - - - - - - -
MediumIngress and Egress blockedC-0030
- - -

Name: -recruit-list

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -recruit-list

-

Namespace:

- - - - - - - + + + + - - @@ -899,13 +852,6 @@

Name: -recruit-list

- - - - - - - @@ -917,10 +863,10 @@

Name: -recruit-list

SeverityNameDocsAssisted RemediationLowImmutable container filesystemC-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

High

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

HighApplications credentials in configuration filesC-0012

spec.template.spec.containers[0].env[1].name

spec.template.spec.containers[0].env[1].value

Medium Ingress and Egress blocked
-

Name: -fhir-gateway-loinc-converter

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-gateway-loinc-converter

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

@@ -944,10 +890,10 @@

Name: -fhir-gateway-loinc-converter

-

Name: -mailhog

-

ApiVersion: v1

-

Kind: ServiceAccount

-

Name: -mailhog

+

Name: -fhir-pseudonymizer

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-pseudonymizer

Namespace:

@@ -962,19 +908,19 @@

Name: -mailhog

- - - + + +
MediumAutomatic mapping of service accountC-0034

automountServiceAccountToken=false

Ingress and Egress blockedC-0030
-

Name: -fhir-gateway-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-gateway-test-connection

+

Name: -fhir-pseudonymizer

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -fhir-pseudonymizer

Namespace:

@@ -998,10 +944,10 @@

Name: -fhir-gateway-test-connection

-

Name: -fhir-pseudonymizer-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -vfps

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -vfps

Namespace:

@@ -1025,10 +971,10 @@

Name: -fhir-pseudonymizer-test-connection

-

Name: -fhir-pseudonymizer

+

Name: -blaze

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Kind: StatefulSet

+

Name: -blaze

Namespace:

@@ -1052,10 +998,10 @@

Name: -fhir-pseudonymizer

-

Name: -recruit-notify

+

Name: -fhir-gateway-loinc-converter

ApiVersion: apps/v1

Kind: Deployment

-

Name: -recruit-notify

+

Name: -fhir-gateway-loinc-converter

Namespace:

@@ -1068,20 +1014,6 @@

Name: -recruit-notify

- - - - - - - - - - - - - - @@ -1093,10 +1025,10 @@

Name: -recruit-notify

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -ohdsi-webapi

+

Name: -postgresql

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -ohdsi-webapi

+

Kind: StatefulSet

+

Name: -postgresql

Namespace:

@@ -1109,6 +1041,13 @@

Name: -ohdsi-webapi

+ + + + + + + @@ -1123,21 +1062,14 @@

Name: -ohdsi-webapi

- - - - - - -
MediumNon-root containersC-0013

spec.template.spec.containers[0].securityContext.runAsGroup=1000

High Ensure CPU limits are set

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

MediumIngress and Egress blockedC-0030
-

Name: -ohdsi-test-connection

+

Name: -fhir-pseudonymizer-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -ohdsi-test-connection

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -1150,20 +1082,6 @@

Name: -ohdsi-test-connection

- - - - - - - - - - - - - - @@ -1175,10 +1093,10 @@

Name: -ohdsi-test-connection

HighEnsure CPU limits are setC-0270

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -fhir-pseudonymizer

+

Name: -fhir-gateway-gateway

ApiVersion: apps/v1

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Name: -fhir-gateway-gateway

Namespace:

@@ -1229,10 +1147,10 @@

Name: -vfps

-

Name: -postgresql

+

Name: -fhir-pseudonymizer

ApiVersion: apps/v1

-

Kind: StatefulSet

-

Name: -postgresql

+

Kind: Deployment

+

Name: -fhir-pseudonymizer

Namespace:

@@ -1252,13 +1170,6 @@

Name: -postgresql

- - - - - - - @@ -1266,14 +1177,21 @@

Name: -postgresql

+ + + + + + +

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

MediumNon-root containersC-0013

spec.template.spec.containers[0].securityContext.runAsGroup=1000

High Ensure memory limits are set

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

MediumIngress and Egress blockedC-0030
-

Name: -vfps-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -vfps

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -vfps

Namespace:

@@ -1290,14 +1208,14 @@

Name: -vfps-test-connection

- + - + @@ -1311,10 +1229,10 @@

Name: -vfps-test-connection

High Ensure CPU limits are set C-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

High Ensure memory limits are set C-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

-

Name: -fhir-pseudonymizer

-

ApiVersion: apps/v1

-

Kind: Deployment

-

Name: -fhir-pseudonymizer

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

Namespace:

@@ -1352,10 +1270,10 @@

Name: -fhir-pseudonymizer

-

Name: -vfps-test-connection

+

Name: -mailhog

ApiVersion: v1

-

Kind: Pod

-

Name: -vfps-test-connection

+

Kind: ServiceAccount

+

Name: -mailhog

Namespace:

@@ -1370,19 +1288,19 @@

Name: -vfps-test-connection

- - - + + +
MediumIngress and Egress blockedC-0030Automatic mapping of service accountC-0034

automountServiceAccountToken=false

-

Name: -fhir-pseudonymizer-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -recruit-list

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -recruit-list

Namespace:

@@ -1395,18 +1313,25 @@

Name: -fhir-pseudonymizer-test-connection

+ + + + + + + - + - + @@ -1420,10 +1345,64 @@

Name: -fhir-pseudonymizer-test-connection

HighApplications credentials in configuration filesC-0012

spec.template.spec.containers[0].env[1].name

spec.template.spec.containers[0].env[1].value

High Ensure CPU limits are set C-0270

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

High Ensure memory limits are set C-0271

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

-

Name: -recruit-test-health-probes

+

Name: -vfps-migrations-v1-3-5

+

ApiVersion: batch/v1

+

Kind: Job

+

Name: -vfps-migrations-v1-3-5

+

Namespace:

+ + + + + + + + + + + + + + + + + + + +
SeverityNameDocsAssisted Remediation
MediumIngress and Egress blockedC-0030
+ + +

Name: -gateway-vfps

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -gateway-vfps

+

Namespace:

+ + + + + + + + + + + + + + + + + + + +
SeverityNameDocsAssisted Remediation
MediumIngress and Egress blockedC-0030
+ + +

Name: -fhir-pseudonymizer-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -recruit-test-health-probes

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -1440,14 +1419,14 @@

Name: -recruit-test-health-probes

- + - + @@ -1461,10 +1440,10 @@

Name: -recruit-test-health-probes

High Ensure CPU limits are set C-0270

spec.containers[0].resources.limits.cpu=YOUR_VALUE

spec.containers[2].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.containers[1].resources.limits.cpu=YOUR_VALUE

spec.containers[0].resources.limits.cpu=YOUR_VALUE

High Ensure memory limits are set C-0271

spec.containers[0].resources.limits.memory=YOUR_VALUE

spec.containers[2].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.containers[1].resources.limits.memory=YOUR_VALUE

spec.containers[0].resources.limits.memory=YOUR_VALUE

-

Name: -vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -vfps-migrations-v1-3-5

+

Name: -fhir-pseudonymizer-test-connection

+

ApiVersion: v1

+

Kind: Pod

+

Name: -fhir-pseudonymizer-test-connection

Namespace:

@@ -1488,10 +1467,10 @@

Name: -vfps-migrations-v1-3-5

-

Name: -mailhog

+

Name: -recruit-query

ApiVersion: apps/v1

Kind: Deployment

-

Name: -mailhog

+

Name: -recruit-query

Namespace:

@@ -1529,10 +1508,10 @@

Name: -mailhog

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -blaze-test-connection

ApiVersion: v1

Kind: Pod

-

Name: -fhir-pseudonymizer-test-connection

+

Name: -blaze-test-connection

Namespace:

@@ -1556,10 +1535,10 @@

Name: -fhir-pseudonymizer-test-connection

-

Name: -vfps-test-connection

-

ApiVersion: v1

-

Kind: Pod

-

Name: -vfps-test-connection

+

Name: -ohdsi-webapi

+

ApiVersion: apps/v1

+

Kind: Deployment

+

Name: -ohdsi-webapi

Namespace:

@@ -1572,6 +1551,20 @@

Name: -vfps-test-connection

+ + + + + + + + + + + + + + @@ -1583,10 +1576,10 @@

Name: -vfps-test-connection

HighEnsure CPU limits are setC-0270

spec.template.spec.containers[0].resources.limits.cpu=YOUR_VALUE

HighEnsure memory limits are setC-0271

spec.template.spec.containers[0].resources.limits.memory=YOUR_VALUE

Medium Ingress and Egress blocked
-

Name: -gateway-vfps-migrations-v1-3-5

-

ApiVersion: batch/v1

-

Kind: Job

-

Name: -gateway-vfps-migrations-v1-3-5

+

Name: -datashield-opal

+

ApiVersion: apps/v1

+

Kind: StatefulSet

+

Name: -datashield-opal

Namespace:

@@ -1599,6 +1592,13 @@

Name: -gateway-vfps-migrations-v1-3-5

+ + + + + + +
LowImmutable container filesystemC-0017

spec.template.spec.containers[2].securityContext.readOnlyRootFilesystem=true

Medium Ingress and Egress blocked