Viewing runtime autoprofile settings

To view autoprofile parameters:

  1. In Policies โ†’ Runtime policies โ†’ Autoprofiles section, click the name of the autoprofile in the list of created container runtime autoprofiles.
  2. In the displayed sidebar, General and Building parameters tabs contain information about the parameters of the selected autoprofile.

    The General tab displays the following:

    • Autoprofile status.
    • Name of the runtime autoprofile.
    • Description of the runtime autoprofile, if it was specified manually. By default, no description is added when autoprofiling.
    • Under Usage in containers, you can find the following information:
      • Depending on the configuration of the solution, pod labels or digest and a link to the image for which the solution applies the runtime autoprofile.
      • Namespace name.
      • Cluster name.
    • In the Restrict events section, the solution also displays the values โ€‹โ€‹of the following parameters:
      • Container processes. The solution can display the list of blocked operations and the list of exceptions, or indicate that all executable files in containers are blocked.
      • Ingress connections. The solution displays exception statuses for the network reputation of ingress connections.
      • Egress connections. The solution displays exception statuses for the network reputation of egress connections.
      • File threat protection. The solution shows the component status (Enabled or Disabled).
      • File operations. The solution shows the file operation monitoring status (Enabled or Disabled).
      • Listening on ports. The solution displays the setting for the monitoring of the opening of ports: Disabled, All ports, or All ports except specified (a list of exceptions for ports is provided).

    If necessary, you can make changes to the autoprofile parameters.

    The Building parameters tab displays the following data:

    • Name of the runtime autoprofile.
    • Date and time of the last modification of the autoprofile.
    • Name of the user that initiated the creation of the autoprofile.
    • Image digest, namespace, and cluster the autoprofile was based on.
    • Name of the image whose digest the autoprofile was based on. You can view the scan results for this image by clicking the image name.
Page top