diff --git a/examples/container-deny-escalation/template.yaml b/examples/container-deny-escalation/template.yaml index 411c2bf3..97b46ea3 100755 --- a/examples/container-deny-escalation/template.yaml +++ b/examples/container-deny-escalation/template.yaml @@ -118,6 +118,10 @@ spec: c.securityContext.allowPrivilegeEscalation == true } + container_allows_escalation(c) { + core.missing_field(c, "securityContext") + } + container_allows_escalation(c) { core.missing_field(c.securityContext, "allowPrivilegeEscalation") } diff --git a/examples/policies.md b/examples/policies.md index 696a258e..5c78c4eb 100755 --- a/examples/policies.md +++ b/examples/policies.md @@ -132,6 +132,10 @@ container_allows_escalation(c) { c.securityContext.allowPrivilegeEscalation == true } +container_allows_escalation(c) { + core.missing_field(c, "securityContext") +} + container_allows_escalation(c) { core.missing_field(c.securityContext, "allowPrivilegeEscalation") }