From 21441f0ba0d107d115f0310e0d82e01a56517585 Mon Sep 17 00:00:00 2001 From: yiscah Date: Tue, 14 Sep 2021 17:38:01 +0300 Subject: [PATCH] gets wlKnownNames as input from config --- rules/rule-name-similarity/raw.rego | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/rules/rule-name-similarity/raw.rego b/rules/rule-name-similarity/raw.rego index fe30e2f97..8f0100d0e 100644 --- a/rules/rule-name-similarity/raw.rego +++ b/rules/rule-name-similarity/raw.rego @@ -1,6 +1,7 @@ package armo_builtins # import data.cautils as cautils # import data.kubernetes.api.client as client +import data # input: pods # apiversion: v1 @@ -11,10 +12,7 @@ deny[msga] { wanted_kinds := {"Pod", "ReplicaSet", "Job"} wanted_kinds[object.kind] - wl_known_names := {"coredns", "kube-proxy", - "event-exporter-gke", "kube-dns", "17-default-backend", "metrics-server", - "ca-audit", "ca-dashboard-aggregator","ca-notification-server", "ca-ocimage","ca-oracle", - "ca-posture", "ca-rbac", "ca-vuln-scan", "ca-webhook", "ca-websocket", "clair-clair"} + wl_known_names := data.postureControlInputs.wlKnownNames wl_name := wl_known_names[_] contains(object.metadata.name, wl_name)