mirror of
https://github.com/aquasecurity/kube-bench.git
synced 2025-05-06 08:59:42 +00:00
Updating checks 4.2.1 and 4.2.3 (#1236)
Removing colon from these checks so that grep command will work with both communication method (YAML and JSON)
This commit is contained in:
parent
af7e0c0f0b
commit
7a68b38763
@ -186,7 +186,7 @@ groups:
|
|||||||
audit: |
|
audit: |
|
||||||
for node in $(oc get nodes -o jsonpath='{.items[*].metadata.name}')
|
for node in $(oc get nodes -o jsonpath='{.items[*].metadata.name}')
|
||||||
do
|
do
|
||||||
oc debug node/${node} -- chroot /host grep -B4 -A1 anonymous: /etc/kubernetes/kubelet.conf
|
oc debug node/${node} -- chroot /host grep -B4 -A1 anonymous /etc/kubernetes/kubelet.conf
|
||||||
done
|
done
|
||||||
use_multiple_values: true
|
use_multiple_values: true
|
||||||
tests:
|
tests:
|
||||||
@ -222,7 +222,7 @@ groups:
|
|||||||
audit: |
|
audit: |
|
||||||
for node in $(oc get nodes -o jsonpath='{.items[*].metadata.name}')
|
for node in $(oc get nodes -o jsonpath='{.items[*].metadata.name}')
|
||||||
do
|
do
|
||||||
oc debug node/${node} -- chroot /host grep clientCAFile: /etc/kubernetes/kubelet.conf
|
oc debug node/${node} -- chroot /host grep clientCAFile /etc/kubernetes/kubelet.conf
|
||||||
done 2> /dev/null
|
done 2> /dev/null
|
||||||
use_multiple_values: true
|
use_multiple_values: true
|
||||||
tests:
|
tests:
|
||||||
|
Loading…
Reference in New Issue
Block a user