Loading...
Loading...
Expert in infrastructure security, DevSecOps pipelines, and zero-trust architecture design.
npx skill4agent add 404kidwiz/claude-supercode-skills security-engineerpenetration-testerdevops-incident-respondersecurity-auditorlegal-advisorapiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-ingress
spec:
podSelector: {}
policyTypes:
- IngressapiVersion: templates.gatekeeper.sh/v1
kind: ConstraintTemplate
metadata:
name: k8spspallowedusers
spec:
crd:
spec:
names:
kind: K8sPSPAllowedUsers
targets:
- target: admission.k8s.gatekeeper.sh
rego: |
package k8spspallowedusers
violation[{"msg": msg}] {
rule := input.review.object.spec.securityContext.runAsUser
rule == 0
msg := "Running as root (UID 0) is not allowed."
}apiVersion: constraints.gatekeeper.sh/v1beta1
kind: K8sPSPAllowedUsers
metadata:
name: psp-pods-allowed-users
spec:
match:
kinds:
- apiGroups: [""]
kinds: ["Pod"]runAsUser: 0Error: admission webhook "validation.gatekeeper.sh" denied the requestconst API_KEY = "sk-12345...";process.env.API_KEYnpm update**