github.com/khulnasoft-lab/defsec@v1.0.5-0.20230827010352-5e9f46893d95/rules/kubernetes/policies/cisbenchmarks/apiserver/service_account_lookup_test.rego (about) 1 package builtin.kubernetes.KCV0024 2 3 test_service_account_lookup_is_false { 4 r := deny with input as { 5 "apiVersion": "v1", 6 "kind": "Pod", 7 "metadata": { 8 "name": "apiserver", 9 "labels": { 10 "component": "kube-apiserver", 11 "tier": "control-plane", 12 }, 13 }, 14 "spec": {"containers": [{ 15 "command": ["kube-apiserver", "--authorization-mode=AlwaysAllow", "--service-account-lookup=false", "--anonymous-auth=false"], 16 "image": "busybox", 17 "name": "hello", 18 }]}, 19 } 20 21 count(r) == 1 22 r[_].msg == "Ensure that the --service-account-lookup argument is set to true" 23 } 24 25 test_service_account_lookup_is_true { 26 r := deny with input as { 27 "apiVersion": "v1", 28 "kind": "Pod", 29 "metadata": { 30 "name": "apiserver", 31 "labels": { 32 "component": "kube-apiserver", 33 "tier": "control-plane", 34 }, 35 }, 36 "spec": {"containers": [{ 37 "command": ["kube-apiserver", "--authorization-mode=AlwaysAllow", "--service-account-lookup=true", "--anonymous-auth=false"], 38 "image": "busybox", 39 "name": "hello", 40 }]}, 41 } 42 43 count(r) == 0 44 } 45 46 test_service_account_lookup_is_not_configured { 47 r := deny with input as { 48 "apiVersion": "v1", 49 "kind": "Pod", 50 "metadata": { 51 "name": "apiserver", 52 "labels": { 53 "component": "kube-apiserver", 54 "tier": "control-plane", 55 }, 56 }, 57 "spec": {"containers": [{ 58 "command": ["kube-apiserver", "--authorization-mode=RBAC", "--anonymous-auth=false"], 59 "image": "busybox", 60 "name": "hello", 61 }]}, 62 } 63 64 count(r) == 0 65 }