KICS #713
Annotations
1 error and 10 warnings
KICS scan
KICS scan failed with exit code 50
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L225
Containers should not run with allowPrivilegeEscalation in order to prevent them from gaining more privileges than their parent process
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L225
Containers should not run with allowPrivilegeEscalation in order to prevent them from gaining more privileges than their parent process
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L225
Containers should only run as non-root user. This limits the exploitability of security misconfigurations and restricts an attacker's possibilities in case of compromise
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L225
Containers should only run as non-root user. This limits the exploitability of security misconfigurations and restricts an attacker's possibilities in case of compromise
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L225
Check if containers are running with low UID, which might cause conflicts with the host's user table.
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L32
Check if containers are running with low UID, which might cause conflicts with the host's user table.
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L225
Check if containers are running with low UID, which might cause conflicts with the host's user table.
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L225
Memory limits should be defined for each container. This prevents potential resource exhaustion by ensuring that containers consume not more than the designated amount of memory
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L225
Memory limits should be defined for each container. This prevents potential resource exhaustion by ensuring that containers consume not more than the designated amount of memory
|
KICS scan:
charts/centralidp/templates/job-seeding.yaml#L225
Memory requests should be defined for each container. This allows the kubelet to reserve the requested amount of system resources and prevents over-provisioning on individual nodes
|
Loading