Skip to content

Instantly share code, notes, and snippets.

@mateobur
Last active February 7, 2019 07:55
Show Gist options
  • Save mateobur/0c4bd458adca8d8bbc007569ed5da4ad to your computer and use it in GitHub Desktop.
Save mateobur/0c4bd458adca8d8bbc007569ed5da4ad to your computer and use it in GitHub Desktop.
Kube-system Kubernetes security with Sysdig Secure
- podname: etcd
proc: [etcd]
write_dir: [/var/lib/etcd]
outbound_proc: [etcd]
listen_proc: [etcd]
- podname: kube_apiserver
proc: [kube-apiserver]
write_dir: false
outbound_proc: [kube-apiserver]
listen_proc: [kube-apiserver]
- podname: kube_dns
proc: [dnsmasq, dnsmasq-nanny, sidecar, kube-dns]
write_dir: [/var/run/dnsmasq.pid, /dev/null]
outbound_proc: [kube-dns]
listen_proc: [kube-dns, sidecar, dnsmasq]
- podname: kube_controller
proc: [kube-controller-manager]
write_dir: false
outbound_proc: [kube-controller-manager]
listen_proc: [kube-controller-manager]
- podname: kube_scheduler
proc: [kube-scheduler]
write_dir: false
outbound_proc: [kube-scheduler]
listen_proc: [kube-scheduler]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment