mirror of
https://github.com/FairwindsOps/polaris.git
synced 2026-05-09 18:56:57 +00:00
66 lines
1.2 KiB
YAML
66 lines
1.2 KiB
YAML
resources:
|
|
cpuRequestsMissing: warning
|
|
cpuRequestRanges:
|
|
warning:
|
|
below: 50m
|
|
above: 1000m
|
|
error:
|
|
below: 500m
|
|
above: 2000m
|
|
cpuLimitsMissing: warning
|
|
cpuLimitRanges:
|
|
warning:
|
|
below: 50m
|
|
above: 1000m
|
|
error:
|
|
below: 500m
|
|
above: 2000m
|
|
memoryRequestsMissing: warning
|
|
memoryRequestRanges:
|
|
warning:
|
|
below: 50M
|
|
above: 2G
|
|
error:
|
|
below: 100M
|
|
above: 4G
|
|
memoryLimitsMissing: warning
|
|
memoryLimitRanges:
|
|
warning:
|
|
below: 50M
|
|
above: 2G
|
|
error:
|
|
below: 100M
|
|
above: 4G
|
|
images:
|
|
tagNotSpecified: error
|
|
pullPolicyNotAlways: warning
|
|
whitelist:
|
|
error:
|
|
- gcr.io/*
|
|
blacklist:
|
|
warning:
|
|
- docker.io/*
|
|
healthChecks:
|
|
readinessProbeMissing: warning
|
|
livenessProbeMissing: warning
|
|
networking:
|
|
hostNetworkSet: error
|
|
hostPortSet: error
|
|
security:
|
|
hostIPCSet: error
|
|
hostPIDSet: error
|
|
runAsRootAllowed: warning
|
|
runAsPrivileged: error
|
|
notReadOnlyRootFileSystem: warning
|
|
privilegeEscalationAllowed: error
|
|
capabilities:
|
|
error:
|
|
ifAnyAdded:
|
|
- SYS_ADMIN
|
|
- ALL
|
|
ifAnyNotDropped:
|
|
- ALL
|
|
warning:
|
|
ifAnyAddedBeyond:
|
|
- NONE
|