Comments (2)
This feature gate is actually enabled by default since Kubernetes 1.12. So there wasn't really a reason to ever have it present in the config file with any of the versions Bottlerocket supports.
Yes thanks - that was my suspicion
I was a bit confused though because this config seems to have appeared in bottlerocket for k8s 1.23 - then went away again now for 1.28 - and that didn't seem like it lined up with this feature gate becoming a default.
I think the correct thing in my case is probably to make a PR to kube-bench so it can understand this default correctly, just like bloodhound does here https://github.com/bottlerocket-os/bottlerocket/blob/develop/sources/bloodhound/src/bin/kubernetes-checks/checks.rs#L596-L599
from bottlerocket.
Hi @errm - sorry, that should maybe have been called out more clearly than just passing comments.
This feature gate is actually enabled by default since Kubernetes 1.12. So there wasn't really a reason to ever have it present in the config file with any of the versions Bottlerocket supports.
The reference you found in Bloodhound may actually be very interesting to you if you are trying to run the CIS Benchmarks. I'm sure you've seen a few other things that are just a little bit different in Bottlerocket that causes problems trying to use some of the tools designed for general purpose OSs. Bloodhound is an internal tool that was added and exposed through apiclient
for running the Bottlerocket or Kubernetes CIS benchmarks. They provide either a nicely formatted human-readable format or a JSON formatted report that can be convenient for piping in to other programmatic reporting tools.
You can get a little more background context with the Bottlerocket CIS report and Kubernetes CIS report PRs.
Just let me know if you have any questions.
from bottlerocket.
Related Issues (20)
- Bottlerocket merging bootstrap_extra_args are adding extra quotes when using the official eks terraform module HOT 7
- New setting under `settings.container-runtime` for configuring (`stargz`/`soci`) snapshotter for lazy image pulling HOT 2
- Add additional ECS configuration values to `settings.ecs` HOT 3
- ecr-credential-provider: use custom AWS_PROFILE HOT 4
- Bottlerocket node intermittently fails to start with "[FAILED] Failed to start Wait for Network to be Configured." HOT 11
- v1.19.0 update CHANGELOG
- Remove metal and vmware k8s 1.24 variants by Feb 2024
- v1.19.0 🦍 Tracking Issue HOT 1
- NodePort services inaccessible/blocked by iptables HOT 21
- Missing cAdvisor metrics HOT 2
- Setting to control bottlerocket host cgroup cpu allocation HOT 1
- v1.19.0 update eni-max-pods mapping file
- v1.19.0 Host container updates HOT 1
- v1.19.0 Go dependency updates
- Sandbox container image being GC'd in 1.29 HOT 8
- Specify autoloaded kernel module options via settings. HOT 4
- Update ECS agent to v1.81.0 and Docker to v25
- update to glibc 2.39
- v1.19.1 💘 Tracking Issue HOT 2
- Issue with Bottlerocket image HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from bottlerocket.