Skip to content

Commit a0b2ae1

Browse files
committed
updating flow + screenshots
1 parent 206ccec commit a0b2ae1

8 files changed

Lines changed: 23 additions & 8 deletions

articles/defender-for-cloud/kubernetes-workload-protections.md

Lines changed: 23 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -138,21 +138,26 @@ For recommendations with parameters that need to be customized, you need to set
138138
1. Select the relevant subscription.
139139

140140
1. From the navigation menu, select **Security policies**.
141+
:::image type="content" source="media/kubernetes-workload-protections/security-policies-page.png" alt-text="Screenshot of the Security policies page.":::
141142

142-
1. Select the **Recommendations** tab.
143+
1. On the **Standards** tab, search for the appropriate security standard.
143144

144-
1. Select or search for the appropriate recommendation.
145+
1. Select the security standard's 3-dot menu and select **Manage**.
146+
:::image type="content" source="media/kubernetes-workload-protections/security-policies-select-manage.png" alt-text="Screenshot of selecting Manage from the recommendation's 3-dot menu.":::
147+
148+
1. Select the relevant policy assignment's 3-dot menu and select **Manage effect and parameters**.
149+
:::image type="content" source="media/kubernetes-workload-protections/select-manage-effect-and-parameters.png" alt-text="Screenshot of selecting the 3-dot menu and then selecting Manage effect and aparameters.":::
150+
151+
1. Modify the values as required.
145152

146-
1. Select the 3-dot menu.
147153

148154
1. Select the relevant assignment. The default assignment is `ASC default`.
149155

150156
1. Open the **Parameters** tab and modify the values as required.
157+
:::image type="content" source="media/kubernetes-workload-protections/manage-effect-and-parameters.png" alt-text="Screenshot of the paraments panel.":::
151158

152159
:::image type="content" source="media/kubernetes-workload-protections/containers-parameter-requires-configuration.png" alt-text="Screenshot showing where to modify the parameters for one of the recommendations in the Kubernetes data plane hardening protection bundle." lightbox="media/kubernetes-workload-protections/containers-parameter-requires-configuration.png":::
153160

154-
1. Select **Review + save**.
155-
156161
1. Select **Save**.
157162

158163
**To enforce any of the recommendations**:
@@ -167,11 +172,21 @@ For recommendations with parameters that need to be customized, you need to set
167172

168173
**To see which recommendations apply to your clusters**:
169174

170-
1. Open Defender for Cloud's [asset inventory](asset-inventory.md) page and set the resource type filter to **Kubernetes services**.
175+
1. Sign in to the [Azure portal](https://portal.azure.com).
176+
177+
1. Go to **Defender for Cloud** > **Inventory**.
178+
179+
1. Set the resource type filter to **Kubernetes services** and select **Apply**.
180+
:::image type="content" source="media/kubernetes-workload-protections/resource-type-kubernetes-service.png" alt-text="Screenshot of using the resource type filter to select kubernetes service.":::
181+
182+
1. Select a cluster to investigate.
171183

172-
1. Select a cluster to investigate and review the available recommendations available for it.
184+
1. Review the available recommendations for it. When you view a recommendation from the workload protection set, the number of affected pods ("Kubernetes components") is listed alongside the cluster.
185+
173186

174-
When you view a recommendation from the workload protection set, the number of affected pods ("Kubernetes components") is listed alongside the cluster. For a list of the specific pods, select the cluster and then select **Take action**.
187+
1. Optional: For a list of the specific pods, select the recommendation.
188+
:::image type="content" source="media/kubernetes-workload-protections/resource-health-recommendation.png" alt-text="Screenshot of selecting a recommendation from the Resource health page.":::
189+
1. and then select **Take action**.
175190

176191
:::image type="content" source="./media/defender-for-kubernetes-usage/view-affected-pods-for-recommendation.gif" alt-text="Screenshot showing where to view the affected pods for a Kubernetes recommendation.":::
177192

31.5 KB
Loading
51.7 KB
Loading
99 KB
Loading
100 KB
Loading
52.6 KB
Loading
95.2 KB
Loading

0 commit comments

Comments
 (0)