@@ -3,12 +3,15 @@ policies:
33 - ../hostIPC.yaml
44 - ../hostNetwork.yaml
55 - ../privilege-escalation.yaml
6+ - ../resources-cpu-limits.yaml
7+ - ../resources-memory-limits.yaml
68resources :
79 - test-hostIPC.yaml
810 - test-hostNetwork.yaml
911 - test-privilege-escalation.yaml
12+ - test-resources-limits.yaml
1013results :
11- # Test hostIPC
14+ # Test hostIPC
1215 - policy : disallow-host-ipc-pods
1316 rule : default
1417 resource : test-hostIPC-not-set
@@ -24,7 +27,7 @@ results:
2427 resource : test-hostIPC-set-to-true
2528 kind : Pod
2629 result : fail
27- # Test hostNetwork
30+ # Test hostNetwork
2831 - policy : disallow-host-network-pods
2932 rule : default
3033 resource : test-hostNetwork-not-set
@@ -40,7 +43,7 @@ results:
4043 resource : test-hostNetwork-set-to-true
4144 kind : Pod
4245 result : fail
43- # Test privilege escalation
46+ # Test privilege escalation
4447 - policy : disallow-privilege-escalation
4548 rule : default
4649 resource : test-privilege-escalation-not-set
@@ -56,3 +59,105 @@ results:
5659 resource : test-privilege-escalation-set-to-true
5760 kind : Pod
5861 result : fail
62+ # Test Restict CPU Limits
63+ - policy : restrict-cpu-limit
64+ rule : default
65+ resource : test-resource-limits-not-set
66+ kind : Pod
67+ result : skip
68+ - policy : restrict-cpu-limit
69+ rule : default
70+ resource : test-resource-limits-both-ok
71+ kind : Pod
72+ result : pass
73+ - policy : restrict-cpu-limit
74+ rule : default
75+ resource : test-resource-limits-cpu-too-high
76+ kind : Pod
77+ result : fail
78+ - policy : restrict-cpu-limit
79+ rule : default
80+ resource : test-resource-limits-memory-too-high
81+ kind : Pod
82+ result : pass
83+ - policy : restrict-cpu-limit
84+ rule : default
85+ resource : test-resource-limits-both-too-high
86+ kind : Pod
87+ result : fail
88+ - policy : restrict-cpu-limit
89+ rule : default
90+ resource : test-cpu-limit-ok
91+ kind : Pod
92+ result : pass
93+ - policy : restrict-cpu-limit
94+ rule : default
95+ resource : test-cpu-limit-decimal-ok
96+ kind : Pod
97+ result : pass
98+ - policy : restrict-cpu-limit
99+ rule : default
100+ resource : test-cpu-limit-millicores-ok
101+ kind : Pod
102+ result : pass
103+ - policy : restrict-cpu-limit
104+ rule : default
105+ resource : test-cpu-limit-too-high
106+ kind : Pod
107+ result : fail
108+ - policy : restrict-cpu-limit
109+ rule : default
110+ resource : test-cpu-limit-decimal-too-high
111+ kind : Pod
112+ result : fail
113+ - policy : restrict-cpu-limit
114+ rule : default
115+ resource : test-cpu-limit-millicores-too-high
116+ kind : Pod
117+ result : fail
118+ # Test Restict Memory Limits
119+ - policy : restrict-memory-limit
120+ rule : default
121+ resource : test-resource-limits-not-set
122+ kind : Pod
123+ result : skip
124+ - policy : restrict-memory-limit
125+ rule : default
126+ resource : test-resource-limits-both-ok
127+ kind : Pod
128+ result : pass
129+ - policy : restrict-memory-limit
130+ rule : default
131+ resource : test-resource-limits-cpu-too-high
132+ kind : Pod
133+ result : pass
134+ - policy : restrict-memory-limit
135+ rule : default
136+ resource : test-resource-limits-memory-too-high
137+ kind : Pod
138+ result : fail
139+ - policy : restrict-memory-limit
140+ rule : default
141+ resource : test-resource-limits-both-too-high
142+ kind : Pod
143+ result : fail
144+ - policy : restrict-memory-limit
145+ rule : default
146+ resource : test-memory-limit-ok
147+ kind : Pod
148+ result : pass
149+ - policy : restrict-memory-limit
150+ rule : default
151+ resource : test-memory-limit-mi-ok
152+ kind : Pod
153+ result : pass
154+ - policy : restrict-memory-limit
155+ rule : default
156+ resource : test-memory-limit-too-high
157+ kind : Pod
158+ result : fail
159+ - policy : restrict-memory-limit
160+ rule : default
161+ resource : test-memory-limit-mi-too-high
162+ kind : Pod
163+ result : fail
0 commit comments