Skip to main content
Version: v0.19.0

env-blacklist

Image must not contain forbidden environment variables.

ProviderLevelTags
skopeoCriticalsecurity

Parameters

NameDefault ValueDescription
keys['DEBUG', 'SECRET_KEY']n/a

Messages

TypeMessage
PassNo forbidden environment variables found.
FailImage contains one or more forbidden environment variables.

Playbook Example

rules:
- provider: skopeo
rule: env-blacklist
options:
keys:
- DEBUG
- SECRET_KEY

Condition

{
"!": {
"env_contains": [
{
"var": "results.skopeo.platforms.0.env"
},
{
"var": "rule.params.keys"
}
]
}
}