Auditing commands run inside Pods' containers on OCP
Issue
-
Is there some way to audit activities inside Pods' containers?
-
I would like to audit what commands (authorized) users run after they get into Pods' containers using oc subcommands, such like:
-
oc rsh -
oc exec -
oc debug
-
-
API Audit logging and worker nodes are attached to an audit system, but I still can't audit what is going on inside Pods' containers
Environment
- Red Hat Openshift Container Platform (RHOCP)
- 4
- Running commands via debug, exec and rsh to modify running pods
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.