4dd3a81bbd
INSIGHTS-475 Add 3 new checks to polaris ( #1082 )
...
* INSIGHTS-448 Add Two Polaris Checks
* Added another chec
* Added another chec
* Added another chec
* Added another chec
* Added another chec
* Added another chec
* Fixing issue
* Fixing issue
* Added another validation
* Added some tests cases
* Added some tests cases
* Update pkg/config/checks/hostProcess.yaml
* Update pkg/validator/pod_test.go
---------
Co-authored-by: Andy Suderman <andy@fairwinds.com >
2024-11-13 08:24:37 -03:00
952b6aed65
INSIGHTS-157 - PDB <> HPA check ( #1057 )
...
* fix typo
* fix failure message
* fix changelog
* fix missingPodDisruptionBudget validation
* add tests for pdbMinAvailableLessThenHPAMaxReplicas
* add simple success test
* fix typo
* lowercasing warnings
* WIP implement pdbMinAvailableLessThanHPAMaxReplicas
* change check name
* rename testes
* fix check message
* change check name
* minor fixes
* improving tests
* improve tests
* fix check name
* Update docs/checks/reliability.md
Co-authored-by: Andy Suderman <andy@fairwinds.com >
* fix/add tests
* fixes from PR
* fix error message
---------
Co-authored-by: Andy Suderman <andy@fairwinds.com >
2024-07-08 14:47:54 -03:00
Vitor Rodrigo Vezani and GitHub
2d33bf2565
INSIGHTS-90 - implement HPA minAvailable and HPA maxAvailable checks ( #1053 )
...
* implement minAvailable and maxAvailable checks
* fix tests
* update hpaMaxAvailability check
2024-06-26 17:31:35 -03:00
Vitor Rodrigo Vezani and GitHub
ac638e01ba
FWI-5820 - remove packr in favor of go:embed ( #1035 )
...
* move dashboard to embed
* use embed in favor of packr
* fix references
* Fix error creating router in dashboard.go
* create default config
* remove examples/config.yaml
2024-03-12 16:11:07 -03:00
Andrew Suderman and GitHub
e7eb079921
change kubernetes.io/ label from name to instance ( #973 )
...
* Fix #972 change label from name to instance
* Fix tests
* more references
* fix check
* Fix example config
2023-07-13 11:33:15 -06:00
Vitor Rodrigo Vezani and GitHub
4b1d6635e0
add test for required fields on builtin checks ( #965 )
2023-06-21 12:25:44 -04:00
Andrew Suderman and GitHub
a1b63ac417
Fix #547 - add a check for topologySpreadConstraint ( #879 )
2023-01-04 14:05:23 -07:00
ivanfetch-fw and GitHub
01d7a8ac00
FWI-2547: Add checks for RBAC allowing execing or attaching to a Pod ( #820 )
...
* Add `rolePodExecAttach` and `clusterrolePodExecAttach` checks
* Add schema tests
* Add clusterrolebindingPodExecAttach, rolebindingRolePodExecAttach, and rolebindingClusterRolePodExecAttach checks + schema-tests
* Add the new checks to the full example config
* Update checks' success/failure messages and add some helpful comments
* Update binding-related check messaging RE: roleRef pointing to a nonexistent resource, and add tests for this case
* Update rolebindingClusterRolePodExecAttach and rolebindingRolePodExecAttach to pass if a binding roleRef is a different kind, and schema tests to include a namespace
* Add additional schema tests, remove "ignore default ClusterRole|Role bindings" code from checks that actually have no default bindings
2022-08-23 12:09:44 -06:00
ivanfetch-fw and GitHub
742b21c6a2
FWI-2582: Add clusterrolebindingClusterAdmin, rolebindingClusterAdminRole, and rolebindingClusterAdminClusterRole checks + schema tests ( #823 )
...
* Add `clusterrolebindingClusterAdmin`, `rolebindingClusterAdminRole`, and `rolebindingClusterAdminClusterRole` checks + schema tests
* Update `rolebindingClusterAdminClusterRole` check to explicitly match the `cluster-admin` default ClusterRole, fix `...all_verbs` schema test, add schema checks for unrelated permissions
2022-08-22 09:50:58 -06:00
ivanfetch-fw and GitHub
206322271c
FWI-2509: Add sensitiveContainerEnvVar and sensitiveConfigMapContent checks ( #817 )
...
* Add sensitiveContainerEnvVar and sensitiveConfigMapContent checks
* Update full example configfile
2022-08-05 11:58:57 -04:00
ivanfetch-fw and GitHub
e5b9236268
FWI-2476: Add missingNetworkPolicy, automountServiceAccountToken, and linuxHardening checks ( #816 )
...
* Add missingNetworkPolicy, automountServiceAccountToken, and linuxHardening checks
2022-08-05 09:44:18 -06:00
bd8b2962dc
Fix license headers ( #736 )
...
* Update license headers
* Fmt
Co-authored-by: Barnabas Makonda <6409210+makoscafee@users.noreply.github.com >
2022-03-31 11:02:10 -04:00
e91b9b8824
Update serverity for polaris check ( #690 )
...
* update serverity for polaris check
* update test checks
* update changelog and fix test failure
* update tests/checks
* update replicas for webhook
* update config-full.yaml
* update tags
Co-authored-by: Robert Brennan <accounts@rbren.io >
2022-01-20 17:08:39 +03:00
Robert Brennan and GitHub
f753fc91f2
Support multi-resource templates ( #524 )
...
* able to run multi-resource tests
* start passing resource provider through
* working end-to-end
* better support for go templating
* fix tests
* delint
* add test
* add json annotations
* remove panics
* fix annotation
* fix for groupkinds
* add comment
* add docs
* change jsonSchema field to schemaString
* rename check
* add pdb to tests
* add ingress to tests
* update deps
* fix up policy import
* update go
* fix check name
* funk it up
* better docs
2021-05-06 14:01:20 -04:00