|
| 1 | +misconfigurations: |
| 2 | + - id: AVD-KSV-0121 |
| 3 | + statement: Some plugins require access to various host paths |
| 4 | + paths: |
| 5 | + - dlb_plugin/base/intel-dlb-plugin.yaml |
| 6 | + - fpga_plugin/base/intel-fpga-plugin-daemonset.yaml |
| 7 | + - qat_plugin/base/intel-qat-kernel-plugin.yaml |
| 8 | + - qat_plugin/overlays/qat_initcontainer/qat_initcontainer.yaml |
| 9 | + |
| 10 | + - id: AVD-KSV-0017 |
| 11 | + statement: initcontainers require privileged access |
| 12 | + paths: |
| 13 | + - dlb_plugin/overlays/dlb_initcontainer/dlb_initcontainer.yaml |
| 14 | + - dsa_plugin/overlays/dsa_initcontainer/dsa_initcontainer.yaml |
| 15 | + - qat_dpdk_app/patches/crypto-perf/env_replace_testcmd.yaml |
| 16 | + - iaa_plugin/overlays/iaa_initcontainer/iaa_initcontainer.yaml |
| 17 | + - qat_plugin/base/intel-qat-kernel-plugin.yaml |
| 18 | + - qat_plugin/overlays/qat_initcontainer/qat_initcontainer.yaml |
| 19 | + |
| 20 | + - id: AVD-KSV-0047 |
| 21 | + statement: gpu plugin in kubelet mode requires "nodes/proxy" resource access |
| 22 | + paths: |
| 23 | + - gpu_plugin/overlays/fractional_resources/gpu-manager-role.yaml |
| 24 | + - operator/rbac/gpu_manager_role.yaml |
| 25 | + - operator/rbac/role.yaml |
| 26 | + |
| 27 | + - id: AVD-KSV-0014 |
| 28 | + statement: These are false detections for not setting "readOnlyFilesystem" |
| 29 | + paths: |
| 30 | + - fpga_plugin/overlays/region/mode-region.yaml |
| 31 | + - gpu_plugin/overlays/fractional_resources/add-mounts.yaml |
| 32 | + - gpu_plugin/overlays/fractional_resources/add-args.yaml |
| 33 | + - gpu_plugin/overlays/fractional_resources/gpu-manager-role.yaml |
| 34 | + - gpu_plugin/overlays/monitoring_shared-dev_nfd/add-args.yaml |
| 35 | + - gpu_plugin/overlays/nfd_labeled_nodes/add-args.yaml |
| 36 | + - iaa_plugin/overlays/iaa_initcontainer/iaa_initcontainer.yaml |
| 37 | + - fpga_admissionwebhook/base/manager_webhook_patch.yaml |
| 38 | + - operator/device/dlb/dlb.yaml |
| 39 | + - operator/device/dsa/dsa.yaml |
| 40 | + - operator/device/fpga/fpga.yaml |
| 41 | + - operator/device/gpu/gpu.yaml |
| 42 | + - operator/device/qat/qat.yaml |
| 43 | + - operator/device/sgx/sgx.yaml |
| 44 | + - gpu_tensorflow_test/deployment.yaml |
| 45 | + - sgx_enclave_apps/overlays/sgx_ecdsa_inproc_quote/add_sgx_default_qcnl_conf.yaml |
| 46 | + - xpumanager_sidecar/kustom/kustom_xpumanager.yaml |
| 47 | + - operator/default/manager_auth_proxy_patch.yaml |
| 48 | + - operator/default/manager_webhook_patch.yaml |
| 49 | + - qat_dpdk_app/patches/compress-perf/env_replace_testcmd.yaml |
| 50 | + - qat_dpdk_app/patches/compress-perf/volume_add_configmap.yaml |
| 51 | + - qat_plugin/overlays/debug/add-args.yaml |
| 52 | + - qat_plugin/overlays/e2e/add-args.yaml |
| 53 | + - qat_plugin/overlays/debug/add-args.yaml |
| 54 | + - qat_dpdk_app/patches/crypto-perf/env_replace_testcmd.yaml |
| 55 | + - sgx_admissionwebhook/base/manager_webhook_patch.yaml |
0 commit comments