-
Notifications
You must be signed in to change notification settings - Fork 2k
Closed
Epic
3 / 33 of 3 issues completed
Copy link
Labels
refinedIssues that are ready to be prioritizedIssues that are ready to be prioritized
Milestone
Description
Discussed in #5156
Originally posted by brianehlert February 22, 2024
Customers use the readOnlyRootFileSystem capability to align with security policy and customers would like to also use this when NAP WAF is included with NIC.
The current implementation of readOnlyRootFileSystem does not support the NAP WAF module and thus the capability needs to be extended to support NAP WAF module behavior and paths necessary.
Notes:
- this can take the v5 work into consideration
- when originally written the focus was v4
- unknown how this impacts v5 considering new enforcer container is introduced
### Tasks
- [ ] https://github.com/nginxinc/kubernetes-ingress/issues/6562
### WAF v5 considerations
- [x] Investigate impact of `readOnlyRootFileSystem=true` now that `waf-enforcer` and `waf-config-mgr` are separated from deployments
anderius, blurpy, hafe and shaun-nx
Sub-issues
Metadata
Metadata
Assignees
Labels
refinedIssues that are ready to be prioritizedIssues that are ready to be prioritized