gardener / diki

Diki is a compliance checker that aims to enhance the security posture of your Kubernetes clusters.
Apache License 2.0
7 stars 8 forks source link

[Security Hardened Shoot Cluster] Rule 2004 Implementation #365

Closed georgibaltiev closed 1 week ago

georgibaltiev commented 1 week ago

What this PR does / why we need it: This PR is an implementation of Rule 2004 of the Security Hardened Shoot Cluster Ruleset. It evaluates the admission plugins of the shoot's kube-apiserver by checking if the ValidatingAdmissionWebhook is enabled (explicitly or by default).

Which issue(s) this PR fixes: Part of #304

Special notes for your reviewer:

Release note:

Implementation for rule `2004` from the `security-hardened-shoot-cluster` ruleset for provider `garden`.