Policy DisplayName |
Policy Id |
Category |
Effect |
Roles# |
Roles |
State |
[Preview]: Cannot Edit Individual Nodes |
53a4a537-990c-495a-92e0-7c21a465442c |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
[Preview]: Kubernetes cluster container images must include the preStop hook |
1a3b9003-eac6-4d39-a184-4a567ace7645 |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
[Preview]: Kubernetes cluster container images should not include latest image tag |
021f8078-41a0-40e6-81b6-c6597da9f3ee |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
[Preview]: Kubernetes cluster containers should only pull images when image pull secrets are present |
12db3749-7e03-4b9f-b443-d37d3fb9f8d9 |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
[Preview]: Kubernetes cluster services should use unique selectors |
b0fdedee-7b9e-4a17-9f5d-5e8e912d2f01 |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
[Preview]: Kubernetes cluster should implement accurate Pod Disruption Budgets |
d9e8f2c1-4c5a-4f5c-8b5a-2abf1e9f7b4d |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
[Preview]: Must Have Anti Affinity Rules Set |
34c88cd4-5d72-4dbb-bf77-12c3cafe8791 |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
[Preview]: No AKS Specific Labels |
a22123bd-b9da-4c86-9424-24903e91fd55 |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
[Preview]: Prints a message if a mutation is applied |
e24df237-32cb-4a6c-a2f6-85b499cda9f2 |
Kubernetes |
Default Audit Allowed Audit, Disabled |
0 |
|
Preview |
[Preview]: Reserved System Pool Taints |
48940d92-ff05-449e-9111-e742d9280451 |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
Preview |
[Preview]: Restricts the CriticalAddonsOnly taint to just the system pool. |
e16d171b-bfe5-4d79-a525-19736b396e92 |
Kubernetes |
Default Mutate Allowed Mutate, Disabled |
0 |
|
Preview |
[Preview]: Sets Kubernetes cluster containers CPU limits to default values in case not present. |
42ba1d72-e90f-42f8-bf99-5a1351eed2b1 |
Kubernetes |
Default Mutate Allowed Mutate, Disabled |
0 |
|
Preview |
[Preview]: Sets Kubernetes cluster containers memory limits to default values in case not present. |
5f86d473-38a8-46c9-bdfe-d7fa3b9836bf |
Kubernetes |
Default Mutate Allowed Mutate, Disabled |
0 |
|
Preview |
[Preview]: Sets maxUnavailable pods to 1 for PodDisruptionBudget resources |
d77f191e-2338-45d0-b6d4-4ee1c586a192 |
Kubernetes |
Default Mutate Allowed Mutate, Disabled |
0 |
|
Preview |
[Preview]: Sets readOnlyRootFileSystem in the Pod spec in init containers to true if it is not set. |
2ae2f266-ecc3-4d26-82c5-8c3cb7774f45 |
Kubernetes |
Default Mutate Allowed Mutate, Disabled |
0 |
|
Preview |
[Preview]: Sets readOnlyRootFileSystem in the Pod spec to true if it is not set. |
8e875f96-2c56-40ca-86db-b9f6a0be7347 |
Kubernetes |
Default Mutate Allowed Mutate, Disabled |
0 |
|
Preview |
Ensure cluster containers have readiness or liveness probes configured |
b1a9997f-2883-4f12-bdff-2280f99b5915 |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |
Kubernetes cluster containers CPU and memory resource limits should not exceed the specified limits |
e345eecc-fa47-480f-9e88-67dcc122b164 |
Kubernetes |
Default Deny Allowed audit, Audit, deny, Deny, disabled, Disabled |
0 |
|
GA |
Kubernetes cluster containers should only use allowed images |
febd0533-8e55-448f-b837-bd0e06f16469 |
Kubernetes |
Default Deny Allowed audit, Audit, deny, Deny, disabled, Disabled |
0 |
|
GA |
Kubernetes clusters should use Container Storage Interface(CSI) driver StorageClass |
4f3823b6-6dac-4b5a-9c61-ce1afb829f17 |
Kubernetes |
Default Audit Allowed Audit, Deny, Disabled |
0 |
|
GA |