SAP-archive / karydia

Kubernetes Security Walnut
Other
77 stars 10 forks source link

NetworkPolicy should only block the relevant MetaData Service IP #188

Closed CodeClinch closed 4 years ago

CodeClinch commented 5 years ago

Description

There should be a way to figure out on what cloud Kubernetes is running and then we should only block the relevant IP.

User Story

As a Kubernetes user I want to block only relevant IPs in order to reduce failures .

[OPTIONAL] Implementation idea

curl http://169.254.169.254/latest/meta-data