Introduction

What is a Policy Violation?

Alauda Security Service lets you view, investigate, and address policy violations in your clusters. Violations are the practical output of policy evaluation and show where a build, deployment, or runtime action matches an enabled rule.

How Violations Are Detected

Alauda Security Service policies detect a wide range of security issues, including:

  • Vulnerabilities (CVEs)
  • Violations of DevOps best practices
  • High-risk build and deployment activities
  • Suspicious runtime behaviors

You can use the default security policies or define your own custom policies. When an enabled policy is violated, Alauda Security Service reports it as a violation for your review and remediation.