| All | Failed | Skipped |
|---|---|---|
| 137 | 18 | 11 |
| Severity | Control Name | Failed Resources | All Resources | Risk Score, % |
|---|---|---|---|---|
| Critical | CVE-2022-39328-grafana-auth-bypass | 0 | 0 | 0 |
| High | Agent Sandbox claim override restrictions | 0 | 0 | 0 |
| High | Agent Sandbox container resource limits | 0 | 0 | 0 |
| High | Agent Sandbox egress policy enforcement | 0 | 0 | 0 |
| High | Agent Sandbox hardened runtime class | 0 | 0 | 0 |
| High | Agent Sandbox image provenance | 0 | 0 | 0 |
| High | Agent Sandbox managed network policy | 0 | 0 | 0 |
| High | Agent Sandbox resource ceilings | 0 | 0 | 0 |
| High | Agent Sandbox service account token isolation | 0 | 0 | 0 |
| High | Agent Sandbox strict egress policy | 0 | 0 | 0 |
| High | Agent Substrate Worker Pod resource ceilings | 0 | 0 | 0 |
| High | Agent runtime image digest pinning | 0 | 0 | 0 |
| High | Agent runtime image registries | 0 | 0 | 0 |
| High | Anonymous user has RoleBinding | 0 | 0 | 0 |
| High | Applications credentials in configuration files | 1 | 13 | 8 |
| High | Apply Security Context to Your Pods and Containers | 12 | 12 | 100 |
| High | Avoid use of system:masters group | 0 | 0 | 0 |
| High | CVE-2021-25742-nginx-ingress-snippet-annotation-vulnerability | 0 | 0 | 0 |
| High | CVE-2022-47633-kyverno-signature-bypass | 0 | 0 | 0 |
| High | Check if signature exists | 12 | 12 | 100 |
| High | Configure Image Provenance using ImagePolicyWebhook admission controller | 0 | 0 | 0 |
| High | Ensure CPU limits are set | 0 | 12 | 0 |
| High | Ensure memory limits are set | 0 | 12 | 0 |
| High | Forbidden Container Registries | 0 | 12 | 0 |
| High | Host PID/IPC privileges | 0 | 12 | 0 |
| High | HostNetwork access | 0 | 12 | 0 |
| High | HostPath mount | 0 | 12 | 0 |
| High | Ingress uses TLS | 0 | 0 | 0 |
| High | Insecure capabilities | 0 | 12 | 0 |
| High | List Kubernetes secrets | 0 | 0 | 0 |
| High | Minimize the admission of Windows HostProcess Containers | 0 | 0 | 0 |
| High | Minimize the admission of privileged containers | 0 | 0 | 0 |
| High | Minimize wildcard use in Roles and ClusterRoles | 0 | 0 | 0 |
| High | Privileged container | 0 | 12 | 0 |
| High | Resource limits | 0 | 12 | 0 |
| High | Resources CPU limit and request | 0 | 12 | 0 |
| High | Resources memory limit and request | 0 | 12 | 0 |
| High | ServiceAccount token mounted | 0 | 2 | 0 |
| High | Verify image signature | 0 | 12 | 0 |
| High | Workload with credential access | 1 | 12 | 8 |
| High | Workload with secret access | 0 | 14 | 0 |
| High | Workloads with Critical vulnerabilities exposed to external traffic | 0 | 0 | 0 |
| High | Workloads with RCE vulnerabilities exposed to external traffic | 0 | 0 | 0 |
| High | Writable hostPath mount | 0 | 12 | 0 |
| Medium | Access container service account | 0 | 0 | 0 |
| Medium | Administrative Roles | 0 | 0 | 0 |
| Medium | Allow privilege escalation | 0 | 12 | 0 |
| Medium | Automatic mapping of service account | 0 | 18 | 0 |
| Medium | Bootstrap token authentication should not be used for users | 0 | 0 | 0 |
| Medium | CVE-2022-24348-argocddirtraversal | 0 | 0 | 0 |
| Medium | Client certificate authentication should not be used for users | 0 | 0 | 0 |
| Medium | Cluster internal networking | 0 | 0 | 0 |
| Medium | Configured liveness probe | 1 | 12 | 8 |
| Medium | Container hostPort | 0 | 12 | 0 |
| Medium | Container runtime socket mounted | 0 | 12 | 0 |
| Medium | CoreDNS poisoning | 0 | 0 | 0 |
| Medium | Dangling Gateway API backend | 0 | 8 | 0 |
| Medium | Dangling HPA target | 0 | 7 | 0 |
| Medium | Dangling Ingress backend | 0 | 8 | 0 |
| Medium | Dangling NetworkPolicy | 0 | 12 | 0 |
| Medium | Delete Kubernetes events | 0 | 0 | 0 |
| Medium | Deprecated Kubernetes image registry | 0 | 0 | 0 |
| Medium | Enable audit Logs | 0 | 0 | 0 |
| Medium | Ensure Image Vulnerability Scanning using Amazon ECR image scanning or a third party provider | 0 | 0 | 0 |
| Medium | Ensure that Service Account Tokens are only mounted where necessary | 0 | 18 | 0 |
| Medium | Ensure that all Namespaces have Network Policies defined | 0 | 0 | 0 |
| Medium | Ensure that default service accounts are not actively used | 0 | 0 | 0 |
| Medium | Ensure that the cluster has at least one active policy control mechanism in place | 0 | 0 | 0 |
| Medium | Ensure that the seccomp profile is set to docker/default in your pod definitions | 2 | 12 | 17 |
| Medium | Images from allowed registry | 0 | 12 | 0 |
| Medium | Ingress and Egress blocked | 12 | 12 | 100 |
| Medium | Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster | 0 | 0 | 0 |
| Medium | Linux hardening | 2 | 12 | 17 |
| Medium | Minimize access to create persistent volumes | 0 | 0 | 0 |
| Medium | Minimize access to create pods | 0 | 0 | 0 |
| Medium | Minimize access to secrets | 0 | 0 | 0 |
| Medium | Minimize access to the approval sub-resource of certificatesigningrequests objects | 0 | 0 | 0 |
| Medium | Minimize access to the proxy sub-resource of nodes | 0 | 0 | 0 |
| Medium | Minimize access to the service account token creation | 0 | 0 | 0 |
| Medium | Minimize access to webhook configuration objects | 0 | 0 | 0 |
| Medium | Minimize the admission of HostPath volumes | 0 | 0 | 0 |
| Medium | Minimize the admission of containers which use HostPorts | 0 | 0 | 0 |
| Medium | Minimize the admission of containers wishing to share the host IPC namespace | 0 | 0 | 0 |
| Medium | Minimize the admission of containers wishing to share the host IPC namespace | 0 | 0 | 0 |
| Medium | Minimize the admission of containers wishing to share the host IPC namespace | 0 | 12 | 0 |
| Medium | Minimize the admission of containers wishing to share the host network namespace | 0 | 0 | 0 |
| Medium | Minimize the admission of containers wishing to share the host network namespace | 0 | 0 | 0 |
| Medium | Minimize the admission of containers wishing to share the host process ID namespace | 0 | 12 | 0 |
| Medium | Minimize the admission of containers wishing to share the host process ID namespace | 0 | 0 | 0 |
| Medium | Minimize the admission of containers wishing to share the host process ID namespace | 0 | 0 | 0 |
| Medium | Minimize the admission of containers with added capabilities | 0 | 0 | 0 |
| Medium | Minimize the admission of containers with added capabilities | 0 | 0 | 0 |
| Medium | Minimize the admission of containers with allowPrivilegeEscalation | 0 | 0 | 0 |
| Medium | Minimize the admission of containers with allowPrivilegeEscalation | 0 | 0 | 0 |
| Medium | Minimize the admission of containers with capabilities assigned | 0 | 0 | 0 |
| Medium | Minimize the admission of containers with capabilities assigned | 0 | 0 | 0 |
| Medium | Minimize the admission of containers with the NET_RAW capability | 0 | 0 | 0 |
| Medium | Minimize the admission of root containers | 0 | 0 | 0 |
| Medium | Minimize the admission of root containers | 0 | 0 | 0 |
| Medium | Missing network policy | 12 | 13 | 92 |
| Medium | Mount service principal | 0 | 12 | 0 |
| Medium | Nginx Ingress Controller End of Life | 0 | 7 | 0 |
| Medium | No impersonation | 0 | 0 | 0 |
| Medium | Non-existent service account | 1 | 18 | 6 |
| Medium | Non-root containers | 0 | 12 | 0 |
| Medium | Portforwarding privileges | 0 | 0 | 0 |
| Medium | Prefer using secrets as files over secrets as environment variables | 5 | 12 | 42 |
| Medium | Prevent containers from allowing command execution | 0 | 0 | 0 |
| Medium | Restrict untrusted workloads | 0 | 0 | 0 |
| Medium | Roles with delete capabilities | 0 | 0 | 0 |
| Medium | Service account token authentication should not be used for users | 0 | 0 | 0 |
| Medium | Sudo in container entrypoint | 0 | 12 | 0 |
| Medium | Workload with ConfigMap access | 1 | 13 | 8 |
| Medium | Workload with PVC access | 0 | 13 | 0 |
| Medium | Workload with administrative roles | 0 | 2 | 0 |
| Medium | Workload with cluster takeover roles | 0 | 2 | 0 |
| Medium | Workloads with excessive amount of vulnerabilities | 0 | 0 | 0 |
| Low | Access Kubernetes dashboard | 0 | 12 | 0 |
| Low | Configured readiness probe | 1 | 12 | 8 |
| Low | Deprecated serviceAccount field | 0 | 12 | 0 |
| Low | Duplicate environment variable | 0 | 12 | 0 |
| Low | Ensure CPU requests are set | 0 | 12 | 0 |
| Low | Ensure memory requests are set | 0 | 12 | 0 |
| Low | Image pull policy on latest tag | 0 | 12 | 0 |
| Low | Images not pinned to digest | 0 | 12 | 0 |
| Low | Immutable container filesystem | 2 | 12 | 17 |
| Low | K8s common labels usage | 0 | 12 | 0 |
| Low | Label usage for resources | 12 | 12 | 100 |
| Low | Mismatching selector | 0 | 7 | 0 |
| Low | Naked pods | 4 | 4 | 100 |
| Low | Network mapping | 0 | 0 | 0 |
| Low | No rolling update strategy | 2 | 6 | 33 |
| Low | Outdated Kubernetes version | 0 | 0 | 0 |
| Low | PSP enabled | 0 | 0 | 0 |
| Low | Pods in default namespace | 10 | 12 | 83 |
| Low | SSH server running inside container | 0 | 0 | 0 |
| Low | Service with no workload | 0 | 20 | 0 |
ApiVersion: v1
Kind: Pod
Name: -fhir-server-exporter-test-metrics-endpoint
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Medium | Ingress and Egress blocked | C-0030 | |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Naked pods | C-0073 | |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (probe-metrics-endpoint) |
| High | Check if signature exists | C-0237 | spec.containers[0].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-metrics-endpoint) |
| Medium | Missing network policy | C-0260 |
ApiVersion: apps/v1
Kind: Deployment
Name: -ohdsi-webapi
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Medium | Ingress and Egress blocked | C-0030 | |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE spec.template.metadata.labels[app]=YOUR_VALUE |
| Medium | Prefer using secrets as files over secrets as environment variables | C-0207 | spec.template.spec.containers[0].env[14].name (webapi) spec.template.spec.containers[0].env[4].name (webapi) |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (webapi) spec.template.spec.securityContext.fsGroupChangePolicy=Always |
| High | Check if signature exists | C-0237 | spec.template.spec.containers[0].image (current: docker.io/ohdsi/webapi:2.15.2@sha256:bc5cffde0d6f29bccc994876bf3cb290e8c3f4e5c087ab28c7163343c0b67393) (webapi) |
| Medium | Missing network policy | C-0260 |
ApiVersion: apps/v1
Kind: Deployment
Name: -fhir-server-exporter
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Medium | Ingress and Egress blocked | C-0030 | |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE spec.template.metadata.labels[app]=YOUR_VALUE |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (fhir-server-exporter) spec.template.spec.securityContext.fsGroupChangePolicy=Always |
| High | Check if signature exists | C-0237 | spec.template.spec.containers[0].image (current: ghcr.io/chgl/fhir-server-exporter:v3.0.19@sha256:26f8963a44d4e714c3413afad9afb3d9726f7ff6add1b755dda82145e5c03df9) (fhir-server-exporter) |
| Medium | Missing network policy | C-0260 |
ApiVersion: apps/v1
Kind: Deployment
Name: -magnifhir
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Medium | Ingress and Egress blocked | C-0030 | |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE spec.template.metadata.labels[app]=YOUR_VALUE |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (magnifhir) spec.template.spec.securityContext.fsGroupChangePolicy=Always |
| High | Check if signature exists | C-0237 | spec.template.spec.containers[0].image (current: ghcr.io/chgl/magnifhir:v1.5.2@sha256:13f121613edd4e52051e864892fa532714c9ab935688c00fb9b772f502c413e9) (magnifhir) |
| Medium | Missing network policy | C-0260 |
ApiVersion: apps/v1
Kind: Deployment
Name: -minio
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Medium | Ingress and Egress blocked | C-0030 | |
| Medium | Linux hardening | C-0055 | spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE (minio) |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE spec.template.metadata.labels[app]=YOUR_VALUE |
| Medium | Prefer using secrets as files over secrets as environment variables | C-0207 | spec.template.spec.containers[0].env[0].name (minio) spec.template.spec.containers[0].env[1].name (minio) |
| Medium | Ensure that the seccomp profile is set to docker/default in your pod definitions | C-0210 | spec.template.spec.containers[0].securityContext.seccompProfile.type=RuntimeDefault (minio) |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (minio) spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE (minio) |
| High | Check if signature exists | C-0237 | spec.template.spec.containers[0].image (current: docker.io/cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened@sha256:8dc02a7e509336c8bbb67962086d691bdcde20a2c9327ed68e5081a681f6dbfc) (minio) |
| Medium | Missing network policy | C-0260 | |
| Low | No rolling update strategy | C-0305 | spec.strategy.type=RollingUpdate spec.strategy.type (current: Recreate) |
ApiVersion: v1
Kind: Pod
Name: -pathling-server-test-connection
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Medium | Ingress and Egress blocked | C-0030 | |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Naked pods | C-0073 | |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (probe-fhir-metadata-endpoint) spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE (probe-fhir-patient-endpoint) spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE (probe-fhir-condition-count-endpoint) spec.containers[3].securityContext.seLinuxOptions=YOUR_VALUE (probe-actuator-health-endpoint) |
| High | Check if signature exists | C-0237 | spec.containers[0].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-fhir-metadata-endpoint) spec.containers[1].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-fhir-patient-endpoint) spec.containers[2].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-fhir-condition-count-endpoint) spec.containers[3].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-actuator-health-endpoint) |
| Medium | Missing network policy | C-0260 |
ApiVersion: apps/v1
Kind: Deployment
Name: -ohdsi-atlas
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Low | Immutable container filesystem | C-0017 | spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true (atlas) |
| Medium | Ingress and Egress blocked | C-0030 | |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE spec.template.metadata.labels[app]=YOUR_VALUE |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true (atlas) spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (atlas) spec.template.spec.securityContext.fsGroupChangePolicy=Always |
| High | Check if signature exists | C-0237 | spec.template.spec.containers[0].image (current: docker.io/ohdsi/atlas:2.15.0@sha256:6814e8c5b5366b50bc197b1eb2881689e5852784742b91b9636eec514f5a555e) (atlas) |
| Medium | Missing network policy | C-0260 |
ApiVersion: apps/v1
Kind: StatefulSet
Name: -postgres
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Low | Immutable container filesystem | C-0017 | spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true (postgres) |
| Medium | Ingress and Egress blocked | C-0030 | |
| Medium | Linux hardening | C-0055 | spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE (postgres) |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE spec.template.metadata.labels[app]=YOUR_VALUE |
| Medium | Prefer using secrets as files over secrets as environment variables | C-0207 | spec.template.spec.containers[0].env[3].name (postgres) |
| Medium | Ensure that the seccomp profile is set to docker/default in your pod definitions | C-0210 | spec.template.spec.containers[0].securityContext.seccompProfile.type=RuntimeDefault (postgres) |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true (postgres) spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (postgres) spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE (postgres) spec.template.spec.securityContext.fsGroupChangePolicy=Always |
| High | Check if signature exists | C-0237 | spec.template.spec.containers[0].image (current: docker.io/postgres:18.4@sha256:d129b9577d274bb96cbd44d902bdeb1b935c89247d161241e9154cba64e13df4) (postgres) |
| Medium | Workload with ConfigMap access | C-0258 | spec.template.spec.containers[0].volumeMounts[1] (postgres) |
| Medium | Missing network policy | C-0260 |
ApiVersion: v1
Kind: Pod
Name: -magnifhir-test
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Medium | Ingress and Egress blocked | C-0030 | |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Naked pods | C-0073 | |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (probe-web-endpoint) spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE (probe-metrics-endpoint) |
| High | Check if signature exists | C-0237 | spec.containers[0].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-web-endpoint) spec.containers[1].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-metrics-endpoint) |
| Medium | Missing network policy | C-0260 |
ApiVersion: batch/v1beta1
Kind: CronJob
Name: -ohdsi-achilles-cron
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Low | Configured readiness probe | C-0018 | spec.jobTemplate.spec.template.spec.containers[0].readinessProbe=YOUR_VALUE (achilles-cron) |
| Medium | Ingress and Egress blocked | C-0030 | |
| Medium | Configured liveness probe | C-0056 | spec.jobTemplate.spec.template.spec.containers[0].livenessProbe=YOUR_VALUE (achilles-cron) |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE spec.jobTemplate.spec.template.metadata.labels[app]=YOUR_VALUE |
| Medium | Prefer using secrets as files over secrets as environment variables | C-0207 | spec.jobTemplate.spec.template.spec.containers[0].env[2].name (achilles-cron) |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.jobTemplate.spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (achilles-cron) spec.jobTemplate.spec.template.spec.securityContext.fsGroupChangePolicy=Always |
| High | Check if signature exists | C-0237 | spec.jobTemplate.spec.template.spec.containers[0].image (current: docker.io/ohdsi/broadsea-achilles:sha-bccd396@sha256:a881063aff6200d0d368ec30eb633381465fb8aa15e7d7138b7d48b6256a6feb) (achilles-cron) |
| Medium | Missing network policy | C-0260 | |
| Medium | Non-existent service account | C-0307 |
ApiVersion: apps/v1
Kind: Deployment
Name: -pathling-server
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| High | Applications credentials in configuration files | C-0012 | spec.template.spec.containers[0].env[3].name (pathling-server) spec.template.spec.containers[0].env[3].value (pathling-server) |
| Medium | Ingress and Egress blocked | C-0030 | |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE spec.template.metadata.labels[app]=YOUR_VALUE |
| Medium | Prefer using secrets as files over secrets as environment variables | C-0207 | spec.template.spec.containers[0].env[4].name (pathling-server) spec.template.spec.containers[0].env[5].name (pathling-server) spec.template.spec.initContainers[1].env[3].name (create-warehouse-bucket) spec.template.spec.initContainers[1].env[4].name (create-warehouse-bucket) |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (pathling-server) |
| High | Check if signature exists | C-0237 | spec.template.spec.containers[0].image (current: ghcr.io/aehrc/pathling:3.0.0@sha256:463d11d0e757c6b838afbc6553fc726d2d46dd1eccd65bc37fd2b5da0f1f59eb) (pathling-server) |
| High | Workload with credential access | C-0259 | spec.template.spec.containers[0].env[3].name (pathling-server) spec.template.spec.containers[0].env[3].value (pathling-server) |
| Medium | Missing network policy | C-0260 | |
| Low | No rolling update strategy | C-0305 | spec.strategy.type=RollingUpdate spec.strategy.type (current: Recreate) |
ApiVersion: v1
Kind: Pod
Name: -ohdsi-test-connection
Namespace:
| Severity | Name | Docs | Assisted Remediation |
|---|---|---|---|
| Medium | Ingress and Egress blocked | C-0030 | |
| Low | Pods in default namespace | C-0061 | metadata.namespace=YOUR_NAMESPACE |
| Low | Naked pods | C-0073 | |
| Low | Label usage for resources | C-0076 | metadata.labels[app]=YOUR_VALUE |
| High | Apply Security Context to Your Pods and Containers | C-0211 | spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (test-webapi) spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE (test-atlas) |
| High | Check if signature exists | C-0237 | spec.containers[0].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (test-webapi) spec.containers[1].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (test-atlas) |
| Medium | Missing network policy | C-0260 |