Skip to content
Snippets Groups Projects
Unverified Commit 81f0d9c6 authored by Liz Rice's avatar Liz Rice Committed by GitHub
Browse files

Merge branch 'master' into Config-doc

parents df357751 312cdb1c
No related branches found
No related tags found
No related merge requests found
...@@ -5,7 +5,9 @@ ...@@ -5,7 +5,9 @@
<img src="images/kube-bench.png" width="200" alt="kube-bench logo"> <img src="images/kube-bench.png" width="200" alt="kube-bench logo">
kube-bench is a Go application that checks whether Kubernetes is deployed securely by running the checks documented in the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/). kube-bench is a Go application that checks whether Kubernetes is deployed securely by running the checks documented in the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/).
Note that it is impossible to inspect the master nodes of managed clusters, e.g. GKE, EKS and AKS, using kube-bench as one does not have access to such nodes, although it is still possible to use kube-bench to check worker node configuration in these environments.
Tests are configured with YAML files, making this tool easy to update as test specifications evolve. Tests are configured with YAML files, making this tool easy to update as test specifications evolve.
......
...@@ -4,7 +4,18 @@ ...@@ -4,7 +4,18 @@
master: master:
apiserver: apiserver:
bins: bins:
- openshift start master api
- hypershift openshift-kube-apiserver - hypershift openshift-kube-apiserver
scheduler:
bins:
- "openshift start master controllers"
confs:
- /etc/origin/master/scheduler.json
controllermanager:
bins:
- "openshift start master controllers"
etcd: etcd:
bins: bins:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment