-
Hello, We use a container vulnerability scanning tool called Prisma Cloud (formally known as twistlock). I've tried running this as a DaemonSet on bottle rocket, but are getting some errors. I wondered if anyone had tried to run any similar tools or can see something obviously wrong with this configuration? I have tried the following paths for DOCKER_CLIENT_ADDRESS:
In the example below, using /run/dockershim.sock - I get the following errors: With other configurations, I get file not found errors. Example Daemonset:
Thanks, |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
I think I have solved this myself, for anyone wondering the following options can be chosen when generating the deployment manifest from the prisma console. |
Beta Was this translation helpful? Give feedback.
-
@netjordan Is your Host monitoring still works in bottlerocket? We have observed a major degradation in Prisma Cloud Compute feature set after migrating. In particular, all of the Host Activity enforcement is no longer working. |
Beta Was this translation helpful? Give feedback.
I think I have solved this myself, for anyone wondering the following options can be chosen when generating the deployment manifest from the prisma console.