[EKS] [Audit log]: Allow to custom audit-log policy
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
**Tell us about your request**
Currently, we could only enable audit log with the default policy. Is it possible to ship audit-log-policy to config map for customization?
**Which service(s) is this request for?**
EKS
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
Currently, EKS use audit-log with default policy (log all request via kube-api), it causes a huge log to process on our system (most of these logs come from trusted local service). Could we custom audit policy to reduce unnecessary logs?
Contributor guide
Research direction
The request concerns EKS audit logging and asks for a customizable audit-log policy instead of the default policy. Start by reviewing how EKS exposes audit-log configuration and how the requested policy would be supplied through a config map. Done means users can customize the policy and reduce unnecessary audit-log volume.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- kubernetes
- Domain
- cloud, observability, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100