Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Policy Drop capabilities "ALL" #5709

Open
joachimBurket opened this issue Apr 17, 2023 · 3 comments
Open

Policy Drop capabilities "ALL" #5709

joachimBurket opened this issue Apr 17, 2023 · 3 comments

Comments

@joachimBurket
Copy link

In the Drop capabilities policy, there isn't the "ALL" option.

We would like to create a policy to drop at least a list of capabilities (KILL, MKNOD, SETGID, SETUID). But when a deployment drops ALL, the policy is trigged because the deployment doesn't drop the list.
Is there a way to configure a policy to drop the list or more?

@porridge
Copy link
Contributor

@stackrox/core-workflows please let @joachimBurket know what you think.

@porridge
Copy link
Contributor

porridge commented Jun 1, 2023

@joachimBurket making this possible is on the roadmap.

@joachimBurket
Copy link
Author

thanks for you answer @porridge, I'm looking forward for this feature to be available :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants