Question 26

A container image scanner is set up on the cluster.
Given an incomplete configuration in the directory
/etc/Kubernetes/confcontrol and a functional container image scanner with HTTPS endpoint https://acme.local.8081/image_policy
  • Question 27

    Create a PSP that will only allow the persistentvolumeclaim as the volume type in the namespace restricted.
    Create a new PodSecurityPolicy named prevent-volume-policy which prevents the pods which is having different volumes mount apart from persistentvolumeclaim.
    Create a new ServiceAccount named psp-sa in the namespace restricted.
    Create a new ClusterRole named psp-role, which uses the newly created Pod Security Policy prevent-volume-policy
    Create a new ClusterRoleBinding named psp-role-binding, which binds the created ClusterRole psp-role to the created SA psp-sa.
    Hint:
    Also, Check the Configuration is working or not by trying to Mount a Secret in the pod maifest, it should get failed.
    POD Manifest:
    apiVersion: v1
    kind: Pod
    metadata:
    name:
    spec:
    containers:
    - name:
    image:
    volumeMounts:
    - name:
    mountPath:
    volumes:
    - name:
    secret:
    secretName:

    Question 28

    SIMULATION
    use the Trivy to scan the following images,
    1. amazonlinux:1
    2. k8s.gcr.io/kube-controller-manager:v1.18.6
    Look for images with HIGH or CRITICAL severity vulnerabilities and store the output of the same in /opt/trivy-vulnerable.txt
  • Question 29

    SIMULATION
    a. Retrieve the content of the existing secret named default-token-xxxxx in the testing namespace.
    Store the value of the token in the token.txt
    b. Create a new secret named test-db-secret in the DB namespace with the following content:
    username: mysql
    password: password@123
    Create the Pod name test-db-pod of image nginx in the namespace db that can access test-db-secret via a volume at path /etc/mysql-credentials

    Question 30

    Service is running on port 389 inside the system, find the process-id of the process, and stores the names of all the open-files inside the /candidate/KH77539/files.txt, and also delete the binary.