CKV_K8S_3

netdata-netdata

Bokeh Plot Bokeh.set_log_level("info"); {"0de8c3ea-5a40-48a5-902e-fe6fd1715e80":{"defs":[],"roots":{"references":[{"attributes":{},"id":"730395","type":"LinearScale"},{"attributes":{},"id":"730402","type":"BasicTicker"},{"attributes":{},"id":"730489","type":"Selection"},{"attributes":{"below":[{"id":"730397"}],"center":[{"id":"730400"},{"id":"730404"}],"height":768,"left":[{"id":"730401"}],"renderers":[{"id":"730425"},{"id":"730465"}],"title":{"id":"730387"},"toolbar":{"id":"730412"},"width":1024,"x_range":{"id":"730389"},"x_scale":{"id":"730393"},"y_range":{"id":"730391"},"y_scale":{"id":"730395"}},"id":"730386","subtype":"Figure","type":"Plot"},{"attributes":{},"id":"730409","type":"ResetTool"},{"attributes":{},"id":"730471","type":"AllLabels"},{"attributes":{"graph_layout":{"CKV_K8S_1":[-0.1962948971612912,-0.062159575715697454],"CKV_K8S_10":[0.12403089322563822,-0.07846306487810767],"CKV_K8S_11":[0.1260383838420528,0.014603661514051798],"CKV_K8S_12":[0.09556861693767423,-0.06285621949380106],"CKV_K8S_13":[0.12214132276093079,-0.0249835494215922],"CKV_K8S_14":[-0.01467520215466245,-0.1321339067197247],"CKV_K8S_17":[0.1608407563885128,-0.010382211259931582],"CKV_K8S_18":[-0.06253865144132241,-0.09663510693060436],"CKV_K8S_19":[0.03164439443879785,-0.17060989734504922],"CKV_K8S_2":[-0.13084755017266136,0.03618276637840824],"CKV_K8S_20":[0.03879895709783448,-0.09521120113631241],"CKV_K8S_22":[0.0857627049524646,0.07291654006808089],"CKV_K8S_23":[0.05151204140811876,0.08624831900661],"CKV_K8S_24":[-0.1499015816859582,-0.060436699789791326],"CKV_K8S_25":[-0.0073861038672384475,-0.16860348821830254],"CKV_K8S_27":[0.15904103255007812,-0.0696410248113532],"CKV_K8S_28":[0.09123351417365176,0.03653249096614436],"CKV_K8S_29":[-0.05372658411102039,-0.14373270933798035],"CKV_K8S_3":[-0.19745405640811725,-0.024186591966125496],"CKV_K8S_30":[0.08370737174486645,-0.10190639249107239],"CKV_K8S_31":[0.045590193637192106,0.045258888792057014],"CKV_K8S_32":[-0.16303999056470483,0.08673047892291542],"CKV_K8S_36":[-0.17334584418168802,0.051336812488724],"CKV_K8S_37":[-0.02095610520580745,0.019979231101512],"CKV_K8S_38":[0.01361187438122291,0.0805468870468514],"CKV_K8S_39":[0.13049338181170125,0.05951584647928697],"CKV_K8S_4":[-0.17011015289641274,-0.09544863763336997],"CKV_K8S_40":[-0.0022962304966184055,-0.06872229500730478],"CKV_K8S_43":[0.0030606158708007245,0.046191092423813085],"CKV_K8S_5":[-0.14708726554800297,-0.014874027696291947],"CKV_K8S_6":[-0.10855733813803974,0.08372168054047076],"CKV_K8S_7":[-0.13154899903096612,0.11051024951228479],"CKV_K8S_8":[0.10837568152866826,-0.14415851382497394],"CKV_K8S_9":[0.06479495164674803,-0.15518207345933863],"DaemonSet.default":[0.05404282817918931,-0.043193040896010934],"Deployment.default":[0.06400715311946649,-0.002088918238452576],"PodSecurityPolicy.default":[-0.19603458798163878,0.020942149663133937],"deps":[0.2854497351375531,1.0],"netdata/netdata":[-0.013945263787012569,-0.02560794863315369]}},"id":"730434","type":"StaticLayoutProvider"},{"attributes":{"bottom_units":"screen","fill_alpha":0.5,"fill_color":"lightgrey","left_units":"screen","level":"overlay","line_alpha":1.0,"line_color":"black","line_dash":[4,4],"line_width":2,"right_units":"screen","syncable":false,"top_units":"screen"},"id":"730411","type":"BoxAnnotation"},{"attributes":{},"id":"730408","type":"SaveTool"},{"attributes":{"background_fill_color":{"value":"white"},"source":{"id":"730427"},"text":{"field":"name"},"x":{"field":"x"},"y":{"field":"y"}},"id":"730465","type":"LabelSet"},{"attributes":{"axis":{"id":"730401"},"dimension":1,"ticker":null},"id":"730404","type":"Grid"},{"attributes":{},"id":"730478","type":"NodesOnly"},{"attributes":{"formatter":{"id":"730470"},"major_label_policy":{"id":"730468"},"ticker":{"id":"730398"}},"id":"730397","type":"LinearAxis"},{"attributes":{},"id":"730430","type":"MultiLine"},{"attributes":{},"id":"730486","type":"UnionRenderers"},{"attributes":{"bottom_units":"screen","fill_alpha":0.5,"fill_color":"lightgrey","left_units":"screen","level":"overlay","line_alpha":1.0,"line_color":"black","line_dash":[4,4],"line_width":2,"right_units":"screen","syncable":false,"top_units":"screen"},"id":"730485","type":"BoxAnnotation"},{"attributes":{},"id":"730470","type":"BasicTickFormatter"},{"attributes":{},"id":"730410","type":"HelpTool"},{"attributes":{"data":{"end":["CKV_K8S_38","CKV_K8S_40","CKV_K8S_23","CKV_K8S_31","CKV_K8S_43","CKV_K8S_30","CKV_K8S_22","CKV_K8S_28","CKV_K8S_20","CKV_K8S_12","CKV_K8S_37","CKV_K8S_10","CKV_K8S_11","CKV_K8S_13","CKV_K8S_19","CKV_K8S_18","CKV_K8S_29","CKV_K8S_27","CKV_K8S_17","CKV_K8S_25","CKV_K8S_39","CKV_K8S_8","CKV_K8S_9","CKV_K8S_14","CKV_K8S_3","CKV_K8S_6","CKV_K8S_24","CKV_K8S_1","CKV_K8S_2","CKV_K8S_5","CKV_K8S_32","CKV_K8S_7","CKV_K8S_36","CKV_K8S_4","Deployment.default","DaemonSet.default","CKV_K8S_40","CKV_K8S_23","CKV_K8S_31","CKV_K8S_43","CKV_K8S_30","CKV_K8S_22","CKV_K8S_28","CKV_K8S_20","CKV_K8S_12","CKV_K8S_37","CKV_K8S_10","CKV_K8S_11","CKV_K8S_13","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","CKV_K8S_18","CKV_K8S_29","CKV_K8S_27","CKV_K8S_17","CKV_K8S_25","CKV_K8S_39","CKV_K8S_8","CKV_K8S_9","CKV_K8S_14","PodSecurityPolicy.default","CKV_K8S_6","CKV_K8S_24","CKV_K8S_1","CKV_K8S_2","CKV_K8S_5","CKV_K8S_32","CKV_K8S_7","CKV_K8S_36","CKV_K8S_4"],"start":["netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","netdata/netdata","CKV_K8S_38","CKV_K8S_38","Deployment.default","Deployment.default","Deployment.default","Deployment.default","Deployment.default","Deployment.default","Deployment.default","Deployment.default","Deployment.default","Deployment.default","Deployment.default","Deployment.default","Deployment.default","CKV_K8S_40","CKV_K8S_23","CKV_K8S_31","CKV_K8S_43","CKV_K8S_30","CKV_K8S_22","CKV_K8S_28","CKV_K8S_20","CKV_K8S_12","CKV_K8S_37","CKV_K8S_10","CKV_K8S_11","CKV_K8S_13","CKV_K8S_19","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","DaemonSet.default","CKV_K8S_3","PodSecurityPolicy.default","PodSecurityPolicy.default","PodSecurityPolicy.default","PodSecurityPolicy.default","PodSecurityPolicy.default","PodSecurityPolicy.default","PodSecurityPolicy.default","PodSecurityPolicy.default","PodSecurityPolicy.default"]},"selected":{"id":"730489"},"selection_policy":{"id":"730488"}},"id":"730431","type":"ColumnDataSource"},{"attributes":{},"id":"730488","type":"UnionRenderers"},{"attributes":{"axis":{"id":"730397"},"ticker":null},"id":"730400","type":"Grid"},{"attributes":{"factors":["root","checkov","chart","helmResource","CVE","image"],"palette":["#3288bd","#66c2a5","#abdda4","#e6f598","#fee08b","#fdae61","#f46d43","#d53e4f"]},"id":"730455","type":"CategoricalColorMapper"},{"attributes":{},"id":"730406","type":"WheelZoomTool"},{"attributes":{"overlay":{"id":"730485"}},"id":"730421","type":"BoxSelectTool"},{"attributes":{"formatter":{"id":"730473"},"major_label_policy":{"id":"730471"},"ticker":{"id":"730402"}},"id":"730401","type":"LinearAxis"},{"attributes":{},"id":"730398","type":"BasicTicker"},{"attributes":{"data_source":{"id":"730431"},"glyph":{"id":"730430"},"hover_glyph":null,"muted_glyph":null,"view":{"id":"730433"}},"id":"730432","type":"GlyphRenderer"},{"attributes":{"data":{"description":["netdata/netdata",null,"Ensure that Service Account Tokens are only mounted where necessary","Deployment.netdata-parent.default (container 0) - netdata","Containers should run as a high UID to avoid host conflict","Minimize the admission of root containers","Ensure that the seccomp profile is set to docker/default or runtime/default","Image should use digest","Apply security context to your pods and containers","Use read-only filesystem for containers where possible","Minimize the admission of containers with the NET_RAW capability"

View BlastRadius Graph

openstack-helm-podsecuritypolicy

Bokeh Plot Bokeh.set_log_level("info"); {"9429c548-1755-44f9-bd96-8d0299daac24":{"defs":[],"roots":{"references":[{"attributes":{},"id":"812802","type":"HelpTool"},{"attributes":{"data":{"description":["openstack-helm/podsecuritypolicy",null,"Do not admit containers wishing to share the host IPC namespace","PodSecurityPolicy.psp-default","Do not admit root containers","Do not allow containers with added capability","Do not admit containers wishing to share the host process ID namespace","Do not admit privileged containers","Containers should not run with allowPrivilegeEscalation","Ensure default seccomp profile set to docker/default or runtime/default","Do not admit containers with the NET_RAW capability","Minimize the admission of containers with capabilities assigned"

View BlastRadius Graph

pnnl-miscscripts-kubeupdater

Bokeh Plot Bokeh.set_log_level("info"); {"72b3c14e-ba66-413f-a20a-87ff57d621a9":{"defs":[],"roots":{"references":[{"attributes":{"bottom_units":"screen","fill_alpha":0.5,"fill_color":"lightgrey","left_units":"screen","level":"overlay","line_alpha":1.0,"line_color":"black","line_dash":[4,4],"line_width":2,"right_units":"screen","syncable":false,"top_units":"screen"},"id":"848443","type":"BoxAnnotation"},{"attributes":{},"id":"848441","type":"ResetTool"},{"attributes":{},"id":"848520","type":"UnionRenderers"},{"attributes":{},"id":"848421","type":"DataRange1d"},{"attributes":{"active_multi":null,"tools":[{"id":"848437"},{"id":"848438"},{"id":"848439"},{"id":"848440"},{"id":"848441"},{"id":"848442"},{"id":"848451"},{"id":"848452"},{"id":"848453"}]},"id":"848444","type":"Toolbar"},{"attributes":{},"id":"848500","type":"AllLabels"},{"attributes":{"formatter":{"id":"848502"},"major_label_policy":{"id":"848500"},"ticker":{"id":"848430"}},"id":"848429","type":"LinearAxis"},{"attributes":{"formatter":{"id":"848505"},"major_label_policy":{"id":"848503"},"ticker":{"id":"848434"}},"id":"848433","type":"LinearAxis"},{"attributes":{"data_source":{"id":"848463"},"glyph":{"id":"848462"},"hover_glyph":null,"muted_glyph":null,"view":{"id":"848465"}},"id":"848464","type":"GlyphRenderer"},{"attributes":{},"id":"848462","type":"MultiLine"},{"attributes":{"data_source":{"id":"848459"},"glyph":{"id":"848488"},"hover_glyph":null,"muted_glyph":null,"view":{"id":"848461"}},"id":"848460","type":"GlyphRenderer"},{"attributes":{"overlay":{"id":"848517"}},"id":"848453","type":"BoxSelectTool"},{"attributes":{"below":[{"id":"848429"}],"center":[{"id":"848432"},{"id":"848436"}],"height":768,"left":[{"id":"848433"}],"renderers":[{"id":"848457"},{"id":"848497"}],"title":{"id":"848419"},"toolbar":{"id":"848444"},"width":1024,"x_range":{"id":"848421"},"x_scale":{"id":"848425"},"y_range":{"id":"848423"},"y_scale":{"id":"848427"}},"id":"848418","subtype":"Figure","type":"Plot"},{"attributes":{},"id":"848438","type":"WheelZoomTool"},{"attributes":{"data":{"description":["pnnl-miscscripts/kubeupdater",null,"Containers should not share the host network namespace","DaemonSet.RELEASE-NAME-kubeupdater.default (container 0) - main","Ensure that Service Account Tokens are only mounted where necessary","Containers should run as a high UID to avoid host conflict","Containers should not share the host IPC namespace","Apply security context to your pods and containers","Minimize the admission of root containers","Ensure that the seccomp profile is set to docker/default or runtime/default","Containers should not share the host process ID namespace"

View BlastRadius Graph

rlex-parca

Bokeh Plot Bokeh.set_log_level("info"); {"91ccc61d-4246-4a9c-8a35-f57c7c358220":{"defs":[],"roots":{"references":[{"attributes":{},"id":"941733","type":"DataRange1d"},{"attributes":{},"id":"941812","type":"AllLabels"},{"attributes":{},"id":"941827","type":"NodesOnly"},{"attributes":{},"id":"941735","type":"DataRange1d"},{"attributes":{"text":"rlex-parca"},"id":"941731","type":"Title"},{"attributes":{"source":{"id":"941775"}},"id":"941777","type":"CDSView"},{"attributes":{},"id":"941831","type":"Selection"},{"attributes":{"data_source":{"id":"941771"},"glyph":{"id":"941800"},"hover_glyph":null,"muted_glyph":null,"view":{"id":"941773"}},"id":"941772","type":"GlyphRenderer"},{"attributes":{},"id":"941749","type":"PanTool"},{"attributes":{"background_fill_color":{"value":"white"},"source":{"id":"941771"},"text":{"field":"name"},"x":{"field":"x"},"y":{"field":"y"}},"id":"941809","type":"LabelSet"},{"attributes":{},"id":"941752","type":"SaveTool"},{"attributes":{},"id":"941833","type":"Selection"},{"attributes":{"below":[{"id":"941741"}],"center":[{"id":"941744"},{"id":"941748"}],"height":768,"left":[{"id":"941745"}],"renderers":[{"id":"941769"},{"id":"941809"}],"title":{"id":"941731"},"toolbar":{"id":"941756"},"width":1024,"x_range":{"id":"941733"},"x_scale":{"id":"941737"},"y_range":{"id":"941735"},"y_scale":{"id":"941739"}},"id":"941730","subtype":"Figure","type":"Plot"},{"attributes":{},"id":"941817","type":"BasicTickFormatter"},{"attributes":{"graph_layout":{"CKV_K8S_1":[-0.27859248640036544,0.26997658413511516],"CKV_K8S_10":[-0.1369998667336848,0.1441191635137082],"CKV_K8S_11":[-0.07547295417530038,0.1196480032891315],"CKV_K8S_12":[-0.12136234532941609,0.09720160325561046],"CKV_K8S_13":[-0.12503985286452052,0.1851077471619913],"CKV_K8S_15":[-0.08968505968983066,0.14626557550215147],"CKV_K8S_16":[-0.1639650515128189,0.05598337292256386],"CKV_K8S_17":[-0.07762932262289628,0.21267718400154736],"CKV_K8S_2":[-0.250717518863487,0.28446211238955693],"CKV_K8S_20":[-0.09442464057574027,0.09891658725972612],"CKV_K8S_22":[-0.10250057175494295,0.19891519491241688],"CKV_K8S_23":[-0.06446729975315758,0.15870782810726053],"CKV_K8S_24":[-0.2727986799113294,0.23882196293118924],"CKV_K8S_26":[-0.17668793119009452,0.07918369653765994],"CKV_K8S_28":[-0.10906635333584247,0.16263220305247744],"CKV_K8S_3":[-0.2912560501341032,0.19671441839131718],"CKV_K8S_31":[-0.049308548800821424,0.12530604983225735],"CKV_K8S_32":[-0.2712053064746858,0.16860658204565288],"CKV_K8S_36":[-0.2952167223714055,0.15037719898407134],"CKV_K8S_37":[-0.14485697808336684,0.11733212980817634],"CKV_K8S_38":[-0.04898017353103365,0.19461637568199916],"CKV_K8S_4":[-0.3129876997817844,0.17844186254690325],"CKV_K8S_40":[-0.11337262379237069,0.12496514705063393],"CKV_K8S_43":[-0.03748179131717863,0.1477409444148217],"CKV_K8S_5":[-0.2232344781433836,0.2754327729785476],"CKV_K8S_6":[-0.23932750779864154,0.2488735032853084],"CKV_K8S_7":[-0.25570494721940595,0.21027170635189113],"CKV_K8S_8":[-0.030037842948114343,0.17213312901650463],"CKV_K8S_9":[-0.13579425666922457,0.05201281069359489],"CVE-2016-10228":[0.07566510175816946,-0.3336385161285738],"CVE-2016-2781":[0.2359141047939533,-0.2569785684398643],"CVE-2018-12886":[0.2489443295148878,-0.16757372285201386],"CVE-2018-7169":[0.2155815662261419,-0.14052566886129153],"CVE-2019-12290":[0.1048881805212784,-0.307163550939031],"CVE-2019-13627":[0.17371467303193597,-0.3607091608936225],"CVE-2019-14855":[0.04575502339331099,-0.2529838253276397],"CVE-2019-15847":[0.20149100934845218,-0.2850460665990118],"CVE-2019-17543":[0.056437686424086767,-0.2965744132728236],"CVE-2019-25013":[0.19821771757177312,-0.3349758126874274],"CVE-2019-3843":[0.2312363709279723,-0.33285073610830773],"CVE-2019-3844":[0.07703549251491505,-0.20089257921632167],"CVE-2020-10029":[0.14002921467403243,-0.15194601962766796],"CVE-2020-14155":[0.18855337329279376,-0.16816844842935405],"CVE-2020-1751":[0.1573679005589899,-0.2986057450462288],"CVE-2020-1752":[0.11399447293418943,-0.3543365941816548],"CVE-2020-27618":[0.22590470440819965,-0.21188221571365531],"CVE-2020-6096":[0.1452691233216767,-0.3398783820469525],"CVE-2021-3326":[0.25053628451560217,-0.30366598960333524],"CVE-2021-33574":[0.271092974226049,-0.19891648031599116],"CVE-2021-33910":[0.27384886375799555,-0.2750830668271832],"CVE-2021-35942":[0.08744149397146246,-0.2578775707062245],"CVE-2021-3711":[0.005045919184179111,0.46615441544943637],"CVE-2021-3712":[0.04976063610428095,0.4480391373295284],"CVE-2021-40528":[0.27640581514804574,-0.23594541240556294],"DaemonSet.default":[-0.0556319513833168,0.0742562470298509],"Deployment.default":[-0.07488441721904407,0.18590874830835447],"PodSecurityPolicy.default":[-0.3013319447389865,0.23307320313312288],"deps":[1.0,-0.461702047441171],"ghcr.io/parca-dev/parca-agent:v0.1.0":[0.14713258452262687,-0.22514823436407366],"ghcr.io/parca-dev/parca:v0.1.0":[-0.0085323934923807,0.3585115600169681],"rlex/parca":[-0.1687090480343259,0.17168206671393715]}},"id":"941778","type":"StaticLayoutProvider"},{"attributes":{},"id":"941742","type":"BasicTicker"},{"attributes":{},"id":"941815","type":"AllLabels"},{"attributes":{"data_source":{"id":"941775"},"glyph":{"id":"941774"},"hover_glyph":null,"muted_glyph":null,"view":{"id":"941777"}},"id":"941776","type":"GlyphRenderer"},{"attributes":{"overlay":{"id":"941755"}},"id":"941751","type":"BoxZoomTool"},{"attributes":{"formatter":{"id":"941814"},"major_label_policy":{"id":"941812"},"ticker":{"id":"941742"}},"id":"941741","type":"LinearAxis"},{"attributes":{},"id":"941774","type":"MultiLine"},{"attributes":{},"id":"941830","type":"UnionRenderers"},{"attributes":{"axis":{"id":"941745"},"dimension":1,"ticker":null},"id":"941748","type":"Grid"},{"attributes":{"active_multi":null,"tools":[{"id":"941749"},{"id":"941750"},{"id":"941751"},{"id":"941752"},{"id":"941753"},{"id":"941754"},{"id":"941763"},{"id":"941764"},{"id":"941765"}]},"id":"941756","type":"Toolbar"},{"attributes":{"factors":["root","checkov","chart","helmResource","CVE","image"],"palette":["#3288bd","#66c2a5","#abdda4","#e6f598","#fee08b","#fdae61","#f46d43","#d53e4f"]},"id":"941799","type":"CategoricalColorMapper"},{"attributes":{},"id":"941814","type":"BasicTickFormatter"},{"attributes":{},"id":"941746","type":"BasicTicker"},{"attributes":{},"id":"941753","type":"ResetTool"},{"attributes":{"axis":{"id":"941741"},"ticker":null},"id":"941744","type":"Grid"},{"attributes":{},"id":"941737","type":"LinearScale"},{"attributes":{"formatter":{"id":"941817"},"major_label_policy":{"id":"941815"},"ticker":{"id":"941746"}},"id":"941745","type":"LinearAxis"},{"attributes":{},"id":"941822","type":"NodesOnly"},{"attributes":{"data":{"cvssScore":[null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,8.1,5.5,9.8,9.1,8.1,8.1,7.8,7.8,7.5,7.5,7.5,7.5,7,7,6.5,6.3,5.9,5.9,5.9,5.5,5.5,5.3,5.3,null,9.8,7.4],"description":["rlex/parca",null,"Ensure that Service Account Tokens are only mounted where necessary","Deployment.RELEASE-NAME-parca.default (container 0) - parca-server","Containers should run as a high UID to avoid host conflict","Minimize the admission of root containers","Ensure that the seccomp profile is set to docker/default or runtime/default","Image should use digest","Use read-only filesystem for containers where possible","Minimize the admission of containers with the NET_RAW capability","Containers should not run with allowPrivilegeEscalation"

View BlastRadius Graph