Created
January 23, 2025 10:06
-
-
Save Knappek/97df9bcb763db6746dc83315609129be to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| kind: Policy | |
| rules: | |
| # The following requests were manually identified as high-volume and low-risk, | |
| # so drop them. | |
| - level: None | |
| users: ["system:serviceaccount:kube-system:kube-proxy"] | |
| verbs: ["watch"] | |
| resources: | |
| - group: "" # core | |
| resources: ["endpoints", "services", "services/status"] | |
| - level: None | |
| userGroups: ["system:nodes"] | |
| verbs: ["get"] | |
| resources: | |
| - group: "" # core | |
| resources: ["nodes", "nodes/status"] | |
| - level: None | |
| users: | |
| - system:kube-controller-manager | |
| - system:kube-scheduler | |
| - system:serviceaccount:kube-system:endpoint-controller | |
| verbs: ["get", "update"] | |
| namespaces: ["kube-system"] | |
| resources: | |
| - group: "" # core | |
| resources: ["endpoints"] | |
| - level: None | |
| users: ["system:apiserver"] | |
| verbs: ["get"] | |
| resources: | |
| - group: "" # core | |
| resources: ["namespaces", "namespaces/status", "namespaces/finalize"] | |
| # Don't log HPA fetching metrics. | |
| - level: None | |
| users: | |
| - system:kube-controller-manager | |
| verbs: ["get", "list"] | |
| resources: | |
| - group: "metrics.k8s.io" | |
| # Don't log these read-only URLs. | |
| - level: None | |
| nonResourceURLs: | |
| - /healthz* | |
| - /version | |
| - /swagger* | |
| # Don't log events requests. | |
| - level: None | |
| resources: | |
| - group: "" # core | |
| resources: ["events"] | |
| # Don't log TMC service account performing read operations because they are high-volume. | |
| - level: None | |
| userGroups: ["system:serviceaccounts:vmware-system-tmc"] | |
| verbs: ["get", "list", "watch"] | |
| # Don't log read requests from garbage collector because they are high-volume. | |
| - level: None | |
| users: ["system:serviceaccount:kube-system:generic-garbage-collector"] | |
| verbs: ["get", "list", "watch"] | |
| # node and pod status calls from nodes are high-volume and can be large, don't log responses for expected updates from nodes | |
| - level: Request | |
| userGroups: ["system:nodes"] | |
| verbs: ["update","patch"] | |
| resources: | |
| - group: "" # core | |
| resources: ["nodes/status", "pods/status"] | |
| omitStages: | |
| - "RequestReceived" | |
| # deletecollection calls can be large, don't log responses for expected namespace deletions | |
| - level: Request | |
| users: ["system:serviceaccount:kube-system:namespace-controller"] | |
| verbs: ["deletecollection"] | |
| omitStages: | |
| - "RequestReceived" | |
| # Secrets, ConfigMaps, and TokenReviews can contain sensitive & binary data, | |
| # so only log at the Metadata level. | |
| - level: Metadata | |
| resources: | |
| - group: "" # core | |
| resources: ["secrets", "configmaps"] | |
| - group: authentication.k8s.io | |
| resources: ["tokenreviews"] | |
| omitStages: | |
| - "RequestReceived" | |
| # Get responses can be large; skip them. | |
| - level: Request | |
| verbs: ["get", "list", "watch"] | |
| resources: | |
| - group: "" # core | |
| - group: "admissionregistration.k8s.io" | |
| - group: "apiextensions.k8s.io" | |
| - group: "apiregistration.k8s.io" | |
| - group: "apps" | |
| - group: "authentication.k8s.io" | |
| - group: "authorization.k8s.io" | |
| - group: "autoscaling" | |
| - group: "batch" | |
| - group: "certificates.k8s.io" | |
| - group: "extensions" | |
| - group: "metrics.k8s.io" | |
| - group: "networking.k8s.io" | |
| - group: "policy" | |
| - group: "rbac.authorization.k8s.io" | |
| - group: "settings.k8s.io" | |
| - group: "storage.k8s.io" | |
| omitStages: | |
| - "RequestReceived" | |
| # Default level for known APIs | |
| - level: RequestResponse | |
| resources: | |
| - group: "" # core | |
| - group: "admissionregistration.k8s.io" | |
| - group: "apiextensions.k8s.io" | |
| - group: "apiregistration.k8s.io" | |
| - group: "apps" | |
| - group: "authentication.k8s.io" | |
| - group: "authorization.k8s.io" | |
| - group: "autoscaling" | |
| - group: "batch" | |
| - group: "certificates.k8s.io" | |
| - group: "extensions" | |
| - group: "metrics.k8s.io" | |
| - group: "networking.k8s.io" | |
| - group: "policy" | |
| - group: "rbac.authorization.k8s.io" | |
| - group: "settings.k8s.io" | |
| - group: "storage.k8s.io" | |
| omitStages: | |
| - "RequestReceived" | |
| # Default level for all other requests. | |
| - level: Metadata | |
| omitStages: | |
| - "RequestReceived" |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment