kubeeye/checks/notReadOnlyRootFilesystem.yaml

17 lines
385 B
YAML

#successMessage: Filesystem is read only
promptMessage: Filesystem should be read only
category: Security
target: Container
schema:
'$schema': http://json-schema.org/draft-07/schema
type: object
required:
- securityContext
properties:
securityContext:
required:
- readOnlyRootFilesystem
properties:
readOnlyRootFilesystem:
const: true