SV-253536r1051115_rule
V-253536
SRG-APP-000148-CTR-000345
CNTR-PC-000530
CAT II
10
In the root directory of the extracted release tar file, modify the twistlock.cfg file's line:
RUN_CONSOLE_AS_ROOT=false
For Kubernetes deployment, perform these additional steps:
When generating the twistlock_console.yaml deployment file, supply the --run-as-user flag.
Linux/twistcli console export kubernetes --service-type ClusterIP --run-as-user 2674
Modify the resulting twistlock_console.yaml file to include fsGroup: 2674 within the Deployment pod specification's securityContext:
securityContext: fsGroup: 2674
Add runAsGroup: 2674 to the container specification's securityContext:
securityContext: runAsUser: 2674
runAsGroup: 2674
Locate the node in which the Prisma Cloud Compute Console container is running.
Determine the process owner for "app/server".
Execute: "ps -aux | grep "/app/server"
If the process is owned by root, this is a finding.
V-253536
False
CNTR-PC-000530
Locate the node in which the Prisma Cloud Compute Console container is running.
Determine the process owner for "app/server".
Execute: "ps -aux | grep "/app/server"
If the process is owned by root, this is a finding.
M
5473