You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/kubernetes-workload-protections.md
+23-8Lines changed: 23 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -138,21 +138,26 @@ For recommendations with parameters that need to be customized, you need to set
138
138
1. Select the relevant subscription.
139
139
140
140
1. From the navigation menu, select **Security policies**.
141
+
:::image type="content" source="media/kubernetes-workload-protections/security-policies-page.png" alt-text="Screenshot of the Security policies page.":::
141
142
142
-
1.Select the **Recommendations** tab.
143
+
1.On the **Standards** tab, search for the appropriate security standard.
143
144
144
-
1. Select or search for the appropriate recommendation.
145
+
1. Select the security standard's 3-dot menu and select **Manage**.
146
+
:::image type="content" source="media/kubernetes-workload-protections/security-policies-select-manage.png" alt-text="Screenshot of selecting Manage from the recommendation's 3-dot menu.":::
147
+
148
+
1. Select the relevant policy assignment's 3-dot menu and select **Manage effect and parameters**.
149
+
:::image type="content" source="media/kubernetes-workload-protections/select-manage-effect-and-parameters.png" alt-text="Screenshot of selecting the 3-dot menu and then selecting Manage effect and aparameters.":::
150
+
151
+
1. Modify the values as required.
145
152
146
-
1. Select the 3-dot menu.
147
153
148
154
1. Select the relevant assignment. The default assignment is `ASC default`.
149
155
150
156
1. Open the **Parameters** tab and modify the values as required.
157
+
:::image type="content" source="media/kubernetes-workload-protections/manage-effect-and-parameters.png" alt-text="Screenshot of the paraments panel.":::
151
158
152
159
:::image type="content" source="media/kubernetes-workload-protections/containers-parameter-requires-configuration.png" alt-text="Screenshot showing where to modify the parameters for one of the recommendations in the Kubernetes data plane hardening protection bundle." lightbox="media/kubernetes-workload-protections/containers-parameter-requires-configuration.png":::
153
160
154
-
1. Select **Review + save**.
155
-
156
161
1. Select **Save**.
157
162
158
163
**To enforce any of the recommendations**:
@@ -167,11 +172,21 @@ For recommendations with parameters that need to be customized, you need to set
167
172
168
173
**To see which recommendations apply to your clusters**:
169
174
170
-
1. Open Defender for Cloud's [asset inventory](asset-inventory.md) page and set the resource type filter to **Kubernetes services**.
175
+
1. Sign in to the [Azure portal](https://portal.azure.com).
176
+
177
+
1. Go to **Defender for Cloud** > **Inventory**.
178
+
179
+
1. Set the resource type filter to **Kubernetes services** and select **Apply**.
180
+
:::image type="content" source="media/kubernetes-workload-protections/resource-type-kubernetes-service.png" alt-text="Screenshot of using the resource type filter to select kubernetes service.":::
181
+
182
+
1. Select a cluster to investigate.
171
183
172
-
1. Select a cluster to investigate and review the available recommendations available for it.
184
+
1. Review the available recommendations for it. When you view a recommendation from the workload protection set, the number of affected pods ("Kubernetes components") is listed alongside the cluster.
185
+
173
186
174
-
When you view a recommendation from the workload protection set, the number of affected pods ("Kubernetes components") is listed alongside the cluster. For a list of the specific pods, select the cluster and then select **Take action**.
187
+
1. Optional: For a list of the specific pods, select the recommendation.
188
+
:::image type="content" source="media/kubernetes-workload-protections/resource-health-recommendation.png" alt-text="Screenshot of selecting a recommendation from the Resource health page.":::
189
+
1. and then select **Take action**.
175
190
176
191
:::image type="content" source="./media/defender-for-kubernetes-usage/view-affected-pods-for-recommendation.gif" alt-text="Screenshot showing where to view the affected pods for a Kubernetes recommendation.":::
0 commit comments