16.4. Viewing violation details


When you select a violation in the Violations view, a window opens with more information about the violation. It provides detailed information grouped by multiple tabs.

16.4.1. Violation tab

The Violation tab of the Violation Details panel explains how the policy was violated. If the policy targets deploy-phase attributes, you can view the specific values that violated the policies, such as violation names. If the policy targets runtime activity, you can view detailed information about the process that violated the policy, including its arguments and the ancestor processes that created it.

16.4.2. Deployment tab

The Deployment tab of the Details panel displays details of the deployment to which the violation applies.

16.4.2.1. Overview section

The Deployment overview section lists the following information:

  • Deployment ID: The alphanumeric identifier for the deployment.
  • Deployment name: The name of the deployment.
  • Deployment type: The type of the deployment.
  • Cluster: The name of the cluster where the container is deployed.
  • Namespace: The unique identifier for the deployed cluster.
  • Replicas: The number of the replicated deployments.
  • Created: The time and date when the deployment was created.
  • Updated: The time and date when the deployment was updated.
  • Labels: The labels that apply to the selected deployment.
  • Annotations: The annotations that apply to the selected deployment.
  • Service Account: The name of the service account for the selected deployment.

16.4.2.2. Container configuration section

The Container configuration section lists the following information:

  • containers: For each container, provides the following information:

    • Image name: The name of the image for the selected deployment. Click the name to view more information about the image.
    • Resources: This section provides information for the following fields:

      • CPU request (cores): The number of cores requested by the container.
      • CPU limit (cores): The maximum number of cores that can be requested by the container.
      • Memory request (MB): The memory size requested by the container.
      • Memory limit (MB): The maximum memory that can be requested by the container.
    • volumes: Volumes mounted in the container, if any.
    • secrets: Secrets associated with the selected deployment. For each secret, provides information for the following fields:

      • Name: Name of the secret.
      • Container path: Location where the secret is stored.
    • Name: The name of the location where the service will be mounted.
    • Source: The data source path.
    • Destination: The path where the data is stored.
    • Type: The type of the volume.

16.4.2.3. Port configuration section

The Port configuration section provides information about the ports in the deployment, including the following fields:

  • ports: All ports exposed by the deployment and any Kubernetes services associated with this deployment and port if they exist. For each port, the following fields are listed:

    • containerPort: The port number exposed by the deployment.
    • protocol: Protocol, such as, TCP or UDP, that is used by the port.
    • exposure: Exposure method of the service, for example, load balancer or node port.
    • exposureInfo: This section provides information for the following fields:

      • level: Indicates if the service exposing the port internally or externally.
      • serviceName: Name of the Kubernetes service.
      • serviceID: ID of the Kubernetes service as stored in RHACS.
      • serviceClusterIp: The IP address that another deployment or service within the cluster can use to reach the service. This is not the external IP address.
      • servicePort: The port used by the service.
      • nodePort: The port on the node where external traffic comes into the node.
      • externalIps: The IP addresses that can be used to access the service externally, from outside the cluster, if any exist. This field is not available for an internal service.

16.4.2.4. Security context section

The Security context section lists whether the container is running as a privileged container.

  • Privileged:

    • true if it is privileged.
    • false if it is not privileged.

16.4.2.5. Network policy section

The Network policy section lists the namespace and all network policies in the namespace containing the violation. Click on a network policy name to view the full YAML file of the network policy.

16.4.3. Policy tab

The Policy tab of the Details panel displays details of the policy that caused the violation.

16.4.3.1. Policy overview section

The Policy overview section lists the following information:

  • Severity: A ranking of the policy (critical, high, medium, or low) for the amount of attention required.
  • Categories: The policy category of the policy. Policy categories are listed in Platform Configuration Policy Management in the Policy categories tab.
  • Type: Whether the policy is user generated (policies created by a user) or a system policy (policies built into RHACS by default).
  • Description: A detailed explanation of what the policy alert is about.
  • Rationale: Information about the reasoning behind the establishment of the policy and why it matters.
  • Guidance: Suggestions on how to address the violation.
  • MITRE ATT&CK: Indicates if there are MITRE tactics and techniques that apply to this policy.

16.4.3.2. Policy behavior

The Policy behavior section provides the following information:

  • Lifecycle Stage: Lifecycle stages that the policy belongs to, Build, Deploy, or Runtime.
  • Event source: This field is only applicable if the lifecycle stage is Runtime. It can be one of the following:

    • Deployment: RHACS triggers policy violations when event sources include process and network activity, pod execution, and pod port forwarding.
    • Audit logs: RHACS triggers policy violations when event sources match Kubernetes audit log records.
  • Response: The response can be one of the following:

    • Inform: Policy violations generate a violation in the violations list.
    • Inform and enforce: The violation is enforced.
  • Enforcement: If the response is set to Inform and enforce, lists the type of enforcement that is set for the following stages:

    • Build: RHACS fails your continuous integration (CI) builds when images match the criteria of the policy.
    • Deploy: For the Deploy stage, RHACS blocks the creation and update of deployments that match the conditions of the policy if the RHACS admission controller is configured and running.

      • In clusters with admission controller enforcement, the Kubernetes or OpenShift Container Platform API server blocks all noncompliant deployments. In other clusters, RHACS edits noncompliant deployments to prevent pods from being scheduled.
      • For existing deployments, policy changes only result in enforcement at the next detection of the criteria, when a Kubernetes event occurs. For more information about enforcement, see "Security policy enforcement for the deploy stage".
    • Runtime: RHACS deletes all pods when an event in the pods matches the criteria of the policy.

16.4.3.3. Policy criteria section

The Policy criteria section lists the policy criteria for the policy.

16.4.3.4. Security policy enforcement for the deploy stage

Red Hat Advanced Cluster Security for Kubernetes supports two forms of security policy enforcement for deploy-time policies: hard enforcement through the admission controller and soft enforcement by RHACS Sensor. The admission controller blocks creation or updating of deployments that violate policy. If the admission controller is disabled or unavailable, Sensor can perform enforcement by scaling down replicas for deployments that violate policy to 0.

주의

Policy enforcement can impact running applications or development processes. Before you enable enforcement options, inform all stakeholders and plan how to respond to the automated enforcement actions.

16.4.4. Network policies tab

The Network policies section lists the network policies associated with a namespace.

Red Hat logoGithubredditYoutubeTwitter

자세한 정보

평가판, 구매 및 판매

커뮤니티

Red Hat 소개

Red Hat은 기업이 핵심 데이터 센터에서 네트워크 에지에 이르기까지 플랫폼과 환경 전반에서 더 쉽게 작업할 수 있도록 강화된 솔루션을 제공합니다.

보다 포괄적 수용을 위한 오픈 소스 용어 교체

Red Hat은 코드, 문서, 웹 속성에서 문제가 있는 언어를 교체하기 위해 최선을 다하고 있습니다. 자세한 내용은 다음을 참조하세요.Red Hat 블로그.

Red Hat 문서 정보

Legal Notice

Theme

© 2026 Red Hat
맨 위로 이동