Deployment adcs-sim-deployment in namespace adcs-issuer
metadataAndInstanceMismatched π¬ Warning
Reliability - Label app.kubernetes.io/instance must match metadata.name
missingPodDisruptionBudget π¬ Warning
Reliability - Should have a PodDisruptionBudget
deploymentMissingReplicas π¬ Warning
Reliability - Only one replica is scheduled
automountServiceAccountToken π¬ Warning
Security - The ServiceAccount will be automounted
missingNetworkPolicy π¬ Warning
Security - A NetworkPolicy should match pod labels and contain applied egress and ingress rules
priorityClassNotSet π¬ Warning
Reliability - Priority class should be set
topologySpreadConstraint π¬ Warning
Reliability - Pod should be configured with a valid topology spread constraint
Container manager
runAsRootAllowed β Danger
Security - Should not be allowed to run as root
linuxHardening π¬ Warning
Security - Use one of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities to restrict containers using unwanted privileges
notReadOnlyRootFilesystem π¬ Warning
Security - Filesystem should be read only
privilegeEscalationAllowed β Danger
Security - Privilege escalation should not be allowed
insecureCapabilities π¬ Warning
Security - Container should not have insecure capabilities
livenessProbeMissing π¬ Warning
Reliability - Liveness probe should be configured
readinessProbeMissing π¬ Warning
Reliability - Readiness probe should be configured
ConfigMap adcs-sim-configmap in namespace adcs-issuer
sensitiveConfigmapContent β Danger
Security - Potentially sensitive content is detected in the ConfigMap keys or values
TODO Hardening deployment of adcs simulator
Starting point
Grade: D Score: 65%