This the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

  • 1:
    • 2:

      Benchmarks and Compliance

      Note: Sysdig follows the Prometheus-compabtible naming convention for both metrics and labels as opposed to the previous statsd-compatible one. However, this page still shows metrics in the legacy Sysdig naming convention. Until this page is updated, see Metrics and Label Mapping for the mapping between legacy Sysdig and Prometheus naming conventions.

      Compliance metrics are generated from scheduled CIS Benchmark scans that occur in Sysdig Secure. These metrics cover aggregate results of the various CIS Benchmark sections, as well as granular details about how many running containers are failing specific run-time compliance checks.

      Contents

      1 -

      Docker/CIS Benchmarks

      compliance.docker-bench.container-images-and-build-file.pass_pct

      The percentage of successful Docker benchmark tests run on the container images and build files.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.container-images-and-build-file.tests_fail

      The number of failed Docker benchmark tests run against the container images and build file.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.container-images-and-build-file.tests_pass

      The number of successful Docker benchmark tests run against the container images and build file.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.container-images-and-build-file.tests_total

      The total number of tests run against the container images and build file.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.container-runtime.pass_pct

      The percentage of successful container runtime Docker benchmark tests.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.container-runtime.tests_fail

      The number of failed container runtime benchmark tests.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.container-runtime.tests_pass

      The number of successful container runtime Docker benchmark tests.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.container-runtime.tests_total

      The total number of Docker benchmark tests run against container runtimes.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-caps-added

      The number of containers running without kernel restrictions in place.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-maxretry-not-set

      The number of containers configured to not limit installation retries if the initial attempt fails.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-mount-prop-shared

      The number of containers that use mount propagation.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-networking-host

      The number of containers that share the host’s network namespace.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-no-apparmor

      The number of containers running without an AppArmor profile.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-no-cpu-limits

      The number of containers running with no CPU limits configured.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-no-health-check

      The number of containers that have no HEALTHCHECK instruction configured.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-no-mem-limits

      The number of containers configured to run without memory limitations.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-no-pids-cgroup-limit

      The number of containers that do not use a cgroup for PIDs.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-no-restricted-privs

      The number of containers running that can have additional privileges configured.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-no-seccomp

      The number of containers that disable the default seccomp profile.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-no-securityopts

      The number of containers running without SELinux options configured.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-no-ulimit-override

      The number of containers running that override the default ulimit.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-privileged-ports

      The number of containers that have privileged ports mapped into them.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-root-mounted-rw

      The number of containers that mount the host’s root filesystem with read/write privileges.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-running-privileged

      The number of containers running with the --privileged configuration option set.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-sensitive-dirs

      The number of containers that have mounted a sensitive directory from the host.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-sharing-docker-sock

      The number of containers that share the host’s docker socket.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-sharing-host-devs

      The number of containers that share one or more host devices.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-sharing-host-ipc-ns

      The number of containers that share the host’s IPC namespace.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-sharing-host-pid-ns

      The number of containers that share the host’s PID namespace.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-sharing-host-user-ns

      The number of containers that share the host’s user namespace.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-sharing-host-uts-ns

      The number of containers that share the host’s UTS namespace.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-sshd-docker-exec-failures

      The number of containers running an SSH daemon.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-unexpected-cgroup

      The number of containers running without a dedicated cgroup configured.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-using-docker0-net

      The number of containers using the default docker bridge network docker0.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.c-wildcard-bound-port

      The number of containers that do not bind incoming traffic to a specific interface.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-daemon-configuration.pass_pct

      The percentage of successful Docker benchmark tests run against the Docker daemon configuration.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-daemon-configuration.tests_fail

      The number of benchmark tests run against the Docker daemon configuration that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-daemon-configuration.tests_pass

      The number of benchmark tests run against the Docker daemon configuration that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-daemon-configuration.tests_total

      The total number of benchmark tests run against the Docker daemon configuration.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-daemon-configuration-files.pass_pct

      The percentage of successful Docker benchmark tests run against the Docker daemon configuration files.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-daemon-configuration-files.tests_fail

      The number of benchmark tests run against the Docker daemon configuration files that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-daemon-configuration-files.tests_pass

      The number of benchmark tests run against the Docker daemon configuration files that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-daemon-configuration-files.tests_total

      The total number of benchmark tests run against the Docker daemon configuration files.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-security-operations.pass_pct

      The percentage of benchmark tests run against Docker security operations that were successful.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-security-operations.tests_fail

      The number of benchmark tests run against Docker security operations that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-security-operations.tests_pass

      The number of benchmark tests run against Docker security operations that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-security-operations.tests_total

      The total number of benchmark tests run against Docker security operations.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-swarm-configuration.pass_pct

      The percentage of benchmark tests run against the Docker swarm configuration that were successful.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-swarm-configuration.tests_fail

      The number of benchmark tests run against the Docker swarm configuration that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Maxv

      compliance.docker-bench.docker-swarm-configuration.tests_pass

      The number of benchmark tests run against the Docker swarm configuration that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-swarm-configuration.tests_total

      The total number of benchmark tests run against the Docker swarm configuration.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.docker-users

      The number of user accounts with permission to access the Docker daemon socket.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.host-configuration.pass_pct

      The percentage of benchmark tests run against the host configuration that were successful.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.host-configuration.tests_fail

      The number of benchmark tests run against the host configuration that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.host-configuration.tests_pass

      The number of benchmark tests run against the host configuration that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.host-configuration.tests_total

      The total number of benchmark tests run against the host configuration.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.img-images-using-add

      The number of images that use the COPY function rather than the ADD function in Dockerfile.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.img-no-healthcheck

      The number of images with no HEALTHCHECK instruction configured.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.img-running-root

      The number of images that use the root user.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.img-update-insts-found

      The number of images that run a package update step without a package installation step.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.pass_pct

      The percentage of Docker benchmark tests run that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.score

      The current pass/fail score for Docker benchmark tests run. The value of this metric is calculated by starting at zero, and incrementing once for every successful test, and decrementing once for every test that returns a WARN result or worse.

      MetadataDescription
      Metric TypeCounter
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.tests_fail

      The total number of Docker benchmark tests that have failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.tests_pass

      The total number of Docker benchmark tests that have passed

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.docker-bench.tests_total

      The total number of Docker benchmark tests that have been run.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      2 -

      Kubernetes Benchmarks

      compliance.k8s-bench.api-server.pass_pct

      The percentage of Kubernetes benchmark tests run on the API server that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.api-server.tests_fail

      The number of Kubernetes benchmark tests run on the API server that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.api-server.tests_pass

      The number of Kubernetes benchmark tests run on the API server that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.api-server.tests_total

      The total number of Kubernetes benchmark tests run on the API server.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.api-server.tests_warn

      The number of Kubernetes benchmark tests run on the API server that returned a result of WARN.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configuration-files.pass_pct

      The percentage of Kubernetes benchmark tests run on the configuration files of non-master nodes that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configuration-files.tests_fail

      The number of Kubernetes benchmark tests run on the configuration files of non-master nodes that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configuration-files.tests_pass

      The number of Kubernetes benchmark tests run on the configuration files that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configuration-files.tests_total

      The total number of Kubernetes benchmark tests run on the configuration files of non-master nodes.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configuration-files.tests_warn

      The number of Kubernetes benchmark tests run on the configuration files of non-master nodes that returned a result of WARN.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configure-files.pass_pct

      The percentage of Kubernetes benchmark tests run on the master node configuration files that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configure-files.tests_fail

      The number of Kubernetes benchmark tests run on the master node configuration files that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configure-files.tests_pass

      The number of Kubernetes benchmark tests run on the master node configuration files that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configure-files.tests_total

      The total number of Kubernetes benchmark tests run on the master node configuration files.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.configure-files.tests_warn

      The number of Kubernetes benchmark tests run on the master node configuration files that returned a result of WARN.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.controller-manager.pass_pct

      The percentage of Kubernetes benchmark tests run on the controller manager that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.controller-manager.tests_fail

      The number of Kubernetes benchmark tests run on the controller manager that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.controller-manager.tests_pass

      The number of Kubernetes benchmark tests run on the controller manager that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.controller-manager.tests_total

      The total number of Kubernetes benchmark tests run on the controller manager.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.controller-manager.tests_warn

      The number of Kubernetes benchmark tests run on the controller manager that returned a result of WARN.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.etcd.pass_pct

      The percentage of Kubernetes benchmark tests run on the etcd key value store that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.etcd.tests_fail

      The number of Kubernetes benchmark tests run on the etcd key value store that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.etcd.tests_pass

      The number of Kubernetes benchmark tests run on the etcd key value store that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.etcd.tests_total

      The total number of Kubernetes benchmark tests run on the etcd key value store.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.etcd.tests_warn

      The number of Kubernetes benchmark tests run on the etcd key value store that returned a result of WARN.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.general-security-primitives.pass_pct

      The percentage of Kubernetes benchmark tests run on the security primitives that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.general-security-primitives.tests_fail

      The number of Kubernetes benchmark tests run on the security primitives that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.general-security-primitives.tests_pass

      The number of Kubernetes benchmark tests run on the security primitives that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.general-security-primitives.tests_total

      The total number of Kubernetes benchmark tests run on the security primitives.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.general-security-primitives.tests_warn

      The number of Kubernetes benchmark tests run on the security primitives that returned a result of WARN.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.kubelet.pass_pct

      The percentage of Kubernetes benchmark tests run on the non-master node Kubernetes agent that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.kubelet.tests_fail

      The number of Kubernetes benchmark tests run on the non-master node Kubernetes agent that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.kubelet.tests_pass

      The number of Kubernetes benchmark tests run on the non-master node Kubernetes agent that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.kubelet.tests_total

      The total number of Kubernetes benchmark tests run on the non-master node Kubernetes agent.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.kubelet.tests_warn

      The number of Kubernetes benchmark tests run on the non-master node Kubernetes agent that returned a result of WARN.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.pass_pct

      The percentage of Kubernetes benchmark tests that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.scheduler.pass_pct

      The percentage of Kubernetes benchmark tests run on the scheduler that passed.

      MetadataDescription
      Metric TypeGauge
      Value Type%
      Segment ByContainer
      Default Time AggregationAverage
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationAverage
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.scheduler.tests_fail

      The number of Kubernetes benchmark tests run on the scheduler that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.scheduler.tests_pass

      The number of Kubernetes benchmark tests run on the scheduler that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.scheduler.tests_total

      The total number of Kubernetes benchmark tests run on the scheduler.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.scheduler.tests_warn

      The number of Kubernetes benchmark tests run on the scheduler that returned a result of WARN.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.tests_fail

      The number of Kubernetes benchmark tests that failed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.tests_pass

      The number of Kubernetes benchmark tests that passed.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.tests_total

      The total number of Kubernetes benchmark tests run.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max

      compliance.k8s-bench.tests_warn

      The number of Kubernetes benchmark tests that returned a result of WARN.

      MetadataDescription
      Metric TypeGauge
      Value TypeInteger
      Segment ByContainer
      Default Time AggregationRate
      Available Time Aggregation FormatsAvg, Rate, Sum, Min, Max
      Default Group AggregationSum
      Available Group Aggregation FormatsAvg, Sum, Min, Max