Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-1015

[SC-5]: Add CaC rules for DoS protection

XMLWordPrintable

    • Product / Portfolio Work
    • 3
    • False
    • False
    • Undefined
    • CMP Sprint 38

      SC-5 protects workloads against DoS attacks. The CaC rule that would implement SC-5 would check for:

      Acceptance criteria:

      • there is a rule that checks all namespaces that do not start with openshift or kube for the existence of rate-limiting annotations on all routes in those namespaces
      • there is a rule that checks that either one clusterResourceQuota object exists of if there is a resourceQuota object per namespace for all namespaces but those that start with openshift-* or kube-*
      • e2e tests exist for the rules above

              wenshen@redhat.com Vincent Shen
              jhrozek@redhat.com Jakub Hrozek (Inactive)
              Prashant Dhamdhere Prashant Dhamdhere (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: