# KESL 12.4 standalone policy decisions for HAN Chat VM1. # # REFERENCE ONLY: this is deliberately not a complete kesl-control import file. # Export the settings from the installed build, review the diff, and apply # individual values by the commands in RUNBOOK.KESL.ru.md. Importing a partial # or version-mismatched file can reset settings that are not listed here. # # This file contains no license, activation code, proxy credentials, hostname, # IP address, secret or environment value. [deployment] product_major_minor=12.4 mode=standard_standalone gui=disabled update_source=KLServers interceptor=fanotify network_features=disabled ksn= [resource_budget] # Choose from measured host capacity; see runbook section 4. scan_memory_limit_mb=<1024_OR_APPROVED_VALUE> max_memory=<2048MB_OR_APPROVED_VALUE> use_on_demand_cpu_limit=Yes on_demand_cpu_limit_percent=25 [constrained_test_vm_override] # Explicitly approved only for the 4 GB non-production VM. Never copy this # profile to production without new sizing and baseline. scan_memory_limit_mb=512 max_memory=1024MB use_on_demand_cpu_limit=Yes on_demand_cpu_limit_percent=15 full_filesystem_scan=forbidden scan_archived=No parallel_ods_and_container_scan=forbidden stop_available_memory_mb=512 [update_task_6] rule_type=Hourly required_result=completed_successfully required_bases_loaded=Yes stale_bases_alert= [file_threat_protection_task_1] steady_state=Started interceptor_protection_mode=Block action_on_threat=DisinfectDeleteIfNotPossible scan_archived=No [file_threat_exclusions] # Replace placeholders only with mountpoints returned by docker volume inspect. # Do not guess the Compose project prefix. item_0000= item_0001= item_0002= [forbidden_broad_exclusions] item_0000=/var/lib/docker item_0001=/var/lib/docker/overlay2 item_0002=/opt/han-chat item_0003=/var/lib/han-deploy/incoming item_0004=/etc/han item_0005=/run/han-chat item_0006=/tmp item_0007=/ [on_demand_scan] initial_scope=/opt/han-chat/current/backend initial_action=Inform steady_schedule= [container_scan_task_18] initial_schedule=Manual steady_schedule= post_deploy=after_smoke_only # Review before enabling: the vendor default can stop a container when scan # fails technically. container_scan_action= [evidence] application_info=required license_valid=required bases_loaded_and_fresh=required file_threat_task_started=required update_schedule_hourly=required eicar_block_or_remediation_event=required application_smoke_after_each_stage=required firewall_unchanged=required resource_comparison_24h=required