1
0
mirror of https://github.com/aquasecurity/kube-bench.git synced 2024-11-22 08:08:07 +00:00

release: prepare v0.6.16-rc (#1476)

* release: prepare v0.6.16-rc

Signed-off-by: chenk <hen.keinan@gmail.com>

* release: prepare v0.6.16-rc

Signed-off-by: chenk <hen.keinan@gmail.com>

---------

Signed-off-by: chenk <hen.keinan@gmail.com>
This commit is contained in:
chenk 2023-07-24 11:01:43 +03:00 committed by GitHub
parent b29ed6b6ed
commit 9363cdf8ef
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

120
job.yaml
View File

@ -9,79 +9,77 @@ spec:
labels: labels:
app: kube-bench app: kube-bench
spec: spec:
hostPID: true
containers: containers:
- name: kube-bench - command: ["kube-bench"]
image: docker.io/aquasec/kube-bench:v0.6.15 image: docker.io/aquasec/kube-bench:vv0.6.16-rc
command: ["kube-bench"] name: kube-bench
volumeMounts: volumeMounts:
- name: var-lib-etcd - mountPath: /var/lib/etcd
mountPath: /var/lib/etcd name: var-lib-etcd
readOnly: true readOnly: true
- name: var-lib-kubelet - mountPath: /var/lib/kubelet
mountPath: /var/lib/kubelet name: var-lib-kubelet
readOnly: true readOnly: true
- name: var-lib-kube-scheduler - mountPath: /var/lib/kube-scheduler
mountPath: /var/lib/kube-scheduler name: var-lib-kube-scheduler
readOnly: true readOnly: true
- name: var-lib-kube-controller-manager - mountPath: /var/lib/kube-controller-manager
mountPath: /var/lib/kube-controller-manager name: var-lib-kube-controller-manager
readOnly: true readOnly: true
- name: etc-systemd - mountPath: /etc/systemd
mountPath: /etc/systemd name: etc-systemd
readOnly: true readOnly: true
- name: lib-systemd - mountPath: /lib/systemd/
mountPath: /lib/systemd/ name: lib-systemd
readOnly: true readOnly: true
- name: srv-kubernetes - mountPath: /srv/kubernetes/
mountPath: /srv/kubernetes/ name: srv-kubernetes
readOnly: true readOnly: true
- name: etc-kubernetes - mountPath: /etc/kubernetes
mountPath: /etc/kubernetes name: etc-kubernetes
readOnly: true readOnly: true
# /usr/local/mount-from-host/bin is mounted to access kubectl / kubelet, for auto-detecting the Kubernetes version. - mountPath: /usr/local/mount-from-host/bin
# You can omit this mount if you specify --version as part of the command. name: usr-bin
- name: usr-bin
mountPath: /usr/local/mount-from-host/bin
readOnly: true readOnly: true
- name: etc-cni-netd - mountPath: /etc/cni/net.d/
mountPath: /etc/cni/net.d/ name: etc-cni-netd
readOnly: true readOnly: true
- name: opt-cni-bin - mountPath: /opt/cni/bin/
mountPath: /opt/cni/bin/ name: opt-cni-bin
readOnly: true readOnly: true
hostPID: true
restartPolicy: Never restartPolicy: Never
volumes: volumes:
- name: var-lib-etcd - hostPath:
hostPath: path: /var/lib/etcd
path: "/var/lib/etcd" name: var-lib-etcd
- name: var-lib-kubelet - hostPath:
hostPath: path: /var/lib/kubelet
path: "/var/lib/kubelet" name: var-lib-kubelet
- name: var-lib-kube-scheduler - hostPath:
hostPath: path: /var/lib/kube-scheduler
path: "/var/lib/kube-scheduler" name: var-lib-kube-scheduler
- name: var-lib-kube-controller-manager - hostPath:
hostPath: path: /var/lib/kube-controller-manager
path: "/var/lib/kube-controller-manager" name: var-lib-kube-controller-manager
- name: etc-systemd - hostPath:
hostPath: path: /etc/systemd
path: "/etc/systemd" name: etc-systemd
- name: lib-systemd - hostPath:
hostPath: path: /lib/systemd
path: "/lib/systemd" name: lib-systemd
- name: srv-kubernetes - hostPath:
hostPath: path: /srv/kubernetes
path: "/srv/kubernetes" name: srv-kubernetes
- name: etc-kubernetes - hostPath:
hostPath: path: /etc/kubernetes
path: "/etc/kubernetes" name: etc-kubernetes
- name: usr-bin - hostPath:
hostPath: path: /usr/bin
path: "/usr/bin" name: usr-bin
- name: etc-cni-netd - hostPath:
hostPath: path: /etc/cni/net.d/
path: "/etc/cni/net.d/" name: etc-cni-netd
- name: opt-cni-bin - hostPath:
hostPath: path: /opt/cni/bin/
path: "/opt/cni/bin/" name: opt-cni-bin