Prisma Cloud Defender Scan returning Error "failed to scan image failed to augment data: signal: killed"
3577
Created On 05/04/23 07:49 AM - Last Modified 07/13/23 08:25 AM
Symptom
Prisma Cloud Defender Scan returning Error "failed to scan image failed to augment data: signal: killed"
ERRO 2022-12-05T11:23:05.067 scanner.go:761 Failed to perform image scan for image "sha256:592cacdff78a794f1ed6958e5c9ddc87ef9ea4ca5f8a373f490ac4cc85c1b5ed". failed to augment data: signal: killed
Environment
- Prisma Cloud
- CRI-O / containerd environments
Cause
- Image scan for a Deployed Image fails due to memory limit in Defender Daemonset YAML
Resolution
- Increase the Memory Limit on the Defender Daemonset Yaml
Additional Information
- Memory requirement is specific to an environment and may vary depending upon your business requirements
- There are many variables determining the right amount of Memory for the Defenders including the number and complexity of packages in the image, runtime rules, custom rules, and rules scoped specifically to "prevent" or "block" action
- In most situations, increasing the memory limit to 1024M usually helps resolve the issue
- You can test an increase in memory limit and validate on the next Scan