Skip to content
Notifications
Clear all

What's the best way to handle exceptions in Aqua without disabling rules?

1 Posts
1 Users
0 Reactions
25 Views
(@jameson)
Trusted Member
Joined: 3 months ago
Posts: 44
Topic starter   [#13637]

I've been using Aqua Security across a few containerized environments for about six months now, and the policy engine is powerful. However, I keep hitting a common snag: legitimate exceptions.

For example, we have a legacy app that needs to run a specific binary that Aqua flags correctly by its base rule set. Disabling the entire rule feels like a security regression, but adding the container to an "exclusion list" sometimes seems too broad. I want to maintain the security posture but allow for necessary, reviewed deviations.

What are the most precise methods you've found to handle these one-off or situational exceptions? I'm particularly interested in approaches that:

* Scope the exception as narrowly as possible (e.g., by image, by resource, for a specific finding).
* Can be tied to a ticket or approval for audit purposes.
* Don't involve turning off a rule for the entire environment.

Are you using Aqua's built-in exception features a certain way, or have you built external workflows (maybe via API) to manage and log these overrides? I'm trying to avoid the "set it and forget it" danger of broad exclusions.



   
Quote