Slide 48
Slide 48 text
Аудит и регистрация событий
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
name: mtls-on
namespace: myns
spec:
host: *.myns.svc
trafficPolicy:
tls:
mode: ISTIO-MUTUAL
{"hostname":"demo-master-0","output":"14:17:03.188306224: Warning Crictl or docker are
executed (user= user_loginuid=1000 command=crictl ps pid=273049
parent_process=bash) k8s.ns= k8s.pod=
container=host","priority":"Warning","rule":"Crictl or docker cli are
executed","source":"syscall","tags":["host"],"time":"2023-03-14T14:17:03.188306224Z",
"output_fields":
{"container.id":"host","evt.time":1678803423188306224,"k8s.ns.name":null,"k8s.pod.name
":null,"proc.cmdline":"crictl
ps","proc.pid":273049,"proc.pname":"bash","user.loginuid":1000,"user.name":""}}
{"hostname":"demo-master-0","output":"14:43:34.760338878: Warning Crictl or docker are
executed (user= user_loginuid=1000 command=crictl stop 067bd732737af pid=307453
parent_process=bash) k8s.ns= k8s.pod=
container=host","priority":"Warning","rule":"Crictl or docker cli are
executed","source":"syscall","tags":["host"],"time":"2023-03-14T14:43:34.760338878Z",
"output_fields":
{"container.id":"host","evt.time":1678805014760338878,"k8s.ns.name":null,"k8s.pod.name
":null,"proc.cmdline":"crictl stop
067bd732737af","proc.pid":307453,"proc.pname":"bash","user.loginuid":1000,"user.name":
""}}
Вывод Falco