accuknox / discovery-engine

Discover least permissive security posture, Network Microsegmentation, and Application behaviour based on visibility/observability data emitted from policy engines..
30 stars 36 forks source link

System policy validation #193

Closed seungsoo-lee closed 2 years ago

seungsoo-lee commented 3 years ago

Like the network policy validation, we can expect that the discovered system policies can be saturated within some time.

Thus, after those discovered system policies are applied, there should be no denied action from KubeArmor.

For the first step, we need to validate it against multiubuntu pods because we know there is some limited actions.

Then, we need to validate it against other real microservices (e.g., google Hipster)

nyrahul commented 2 years ago

This validation is now done. We have a way v2 version of system policies that are stable.