Skip to main content
Version: main-dev

user-blacklist

Image must not run as root.

ProviderLevelTags
skopeoCriticalsecurity

Parameters

NameDefault ValueDescription
forbidden_userrootn/a

Messages

TypeMessage
PassImage does not run as '${rule.params.forbidden_user}'.
FailImage configured to run as '${rule.params.forbidden_user}'.

Playbook Example

rules:
- provider: skopeo
rule: user-blacklist
options:
forbidden_user: root

Condition

{
"!=": [
{
"var": "results.skopeo.platforms.0.user"
},
{
"var": "rule.params.forbidden_user"
}
]
}