37 Security Rules Available

Security Rules

Discover and deploy CEL-based security policies for Kubernetes. Protect your infrastructure with community-driven rules.

37 Rules
8 Categories
4 Severity Levels
37 rules found

RBAC Roles Allow Privilege Escalation

spotter-access-001

🔴 CRITICAL
🔑 Access Control & IAM
v1.0.0 access

Anonymous Auth Is Not Set To False

spotter-access-002

🔴 CRITICAL
🔑 Access Control & IAM
v1.0.0 access

Cluster Admin Rolebinding With Superuser Permissions

spotter-access-003

🔴 CRITICAL
🔑 Access Control & IAM
v1.0.0 access

Audit Policy Not Cover Key Security Concerns

spotter-audit-001

🟠 HIGH
📊 Audit, Logging & Compliance
v1.0.0 audit

Readiness Probe Not Set

spotter-config-001

🟡 MEDIUM
⚙️ Configuration & Resource Hygiene
v1.0.0 config

Liveness Probe Not Set

spotter-config-002

🟡 MEDIUM
⚙️ Configuration & Resource Hygiene
v1.0.0 config

CPU Limits Not Set

spotter-config-003

🟡 MEDIUM
⚙️ Configuration & Resource Hygiene
v1.0.0 config

CPU Requests Not Set

spotter-config-004

🟡 MEDIUM
⚙️ Configuration & Resource Hygiene
v1.0.0 config

Memory Limits Not Defined

spotter-config-005

🟡 MEDIUM
⚙️ Configuration & Resource Hygiene
v1.0.0 config

Memory Requests Not Defined

spotter-config-006

🟡 MEDIUM
⚙️ Configuration & Resource Hygiene
v1.0.0 config

CronJob Deadline Not Configured

spotter-config-007

🟡 MEDIUM
⚙️ Configuration & Resource Hygiene
v1.0.0 config

Metadata Label Is Invalid

spotter-config-008

🟢 LOW
⚙️ Configuration & Resource Hygiene
v1.0.0 config

Incorrect Volume Claim Access Mode ReadWriteOnce

spotter-config-009

🟢 LOW
⚙️ Configuration & Resource Hygiene
v1.0.0 config

Using Kubernetes Native Secret Management

spotter-data-001

🟢 LOW
🔒 Secrets & Data Security
v1.0.0 data

Secret Exposed as Environment Variable

spotter-data-002

🟠 HIGH
🔒 Secrets & Data Security
v1.0.0 data

Service Exposed via NodePort

service-type-is-nodeport

🟡 MEDIUM
🌐 Network & Traffic Security
v1.0.0 network

Service With External Load Balancer

spotter-network-002

🔴 CRITICAL
🌐 Network & Traffic Security
v1.0.0 network

Kubelet HTTPS Set To False

spotter-platform-001

🔴 CRITICAL
🏗️ Platform & Infrastructure Security
v1.0.0 platform

Insecure Bind Address Set

spotter-platform-002

🔴 CRITICAL
🏗️ Platform & Infrastructure Security
v1.0.0 platform

Invalid Image Tag

spotter-supply-001

🟡 MEDIUM
📦 Supply Chain & Image Security
v1.0.0 supply

Image Without Digest

spotter-supply-002

🟠 HIGH
📦 Supply Chain & Image Security
v1.0.0 supply

Image Pull Policy Missing

spotter-supply-003

🟡 MEDIUM
📦 Supply Chain & Image Security
v1.0.0 supply

Always Pull Images Admission Control Plugin Not Set

spotter-supply-004

🟠 HIGH
📦 Supply Chain & Image Security
v1.0.0 supply

Container Is Privileged

spotter-workload-001

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

Pod Uses Host Network

spotter-workload-002

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

Shared Host IPC Namespace

spotter-workload-003

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

Shared Host PID Namespace

spotter-workload-004

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

Containers With Sys Admin Capabilities

spotter-workload-005

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

Containers With Added Capabilities

spotter-workload-006

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

NET_RAW Capabilities Not Being Dropped

spotter-workload-007

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

No Drop Capabilities for Containers

spotter-workload-008

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

Volume Mount With OS Directory Write Permissions

spotter-workload-009

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

HostPorts Enabled on Containers

spotter-workload-010

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

Missing AppArmor Profile

spotter-workload-011

🟡 MEDIUM
🛡️ Workload & Runtime Security
v1.0.0 workload

Pod Without Seccomp Profile

spotter-workload-012

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

Workload Mounting With Sensitive OS Directory

spotter-workload-013

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload

HostPath Volume enabled on Containers

spotter-workload-014

🔴 CRITICAL
🛡️ Workload & Runtime Security
v1.0.0 workload