mirror of
https://github.com/aquasecurity/kube-bench.git
synced 2024-12-20 05:38:13 +00:00
Fix 1.1.7 1.1.8 (#798)
Signed-off-by: Dmytro Oboznyi <dmytro.oboznyi@syncier.com>
This commit is contained in:
parent
9782bee80c
commit
ebcb742931
@ -91,7 +91,8 @@ groups:
|
|||||||
|
|
||||||
- id: 1.1.7
|
- id: 1.1.7
|
||||||
text: "Ensure that the etcd pod specification file permissions are set to 644 or more restrictive (Automated)"
|
text: "Ensure that the etcd pod specification file permissions are set to 644 or more restrictive (Automated)"
|
||||||
audit: "/bin/sh -c 'if test -e $etcdconf; then stat -c permissions=%a $etcdconf; fi'"
|
audit: "/bin/sh -c 'if test -e $etcdconf; then find $etcdconf -name '*etcd*' | xargs stat -c permissions=%a; fi'"
|
||||||
|
use_multiple_values: true
|
||||||
tests:
|
tests:
|
||||||
test_items:
|
test_items:
|
||||||
- flag: "permissions"
|
- flag: "permissions"
|
||||||
@ -106,7 +107,8 @@ groups:
|
|||||||
|
|
||||||
- id: 1.1.8
|
- id: 1.1.8
|
||||||
text: "Ensure that the etcd pod specification file ownership is set to root:root (Automated)"
|
text: "Ensure that the etcd pod specification file ownership is set to root:root (Automated)"
|
||||||
audit: "/bin/sh -c 'if test -e $etcdconf; then stat -c %U:%G $etcdconf; fi'"
|
audit: "/bin/sh -c 'if test -e $etcdconf; then find $etcdconf -name '*etcd*' | xargs stat -c %U:%G; fi'"
|
||||||
|
use_multiple_values: true
|
||||||
tests:
|
tests:
|
||||||
test_items:
|
test_items:
|
||||||
- flag: "root:root"
|
- flag: "root:root"
|
||||||
|
@ -81,6 +81,7 @@ master:
|
|||||||
- /var/snap/etcd/common/etcd.conf.yaml
|
- /var/snap/etcd/common/etcd.conf.yaml
|
||||||
- /var/snap/microk8s/current/args/etcd
|
- /var/snap/microk8s/current/args/etcd
|
||||||
- /usr/lib/systemd/system/etcd.service
|
- /usr/lib/systemd/system/etcd.service
|
||||||
|
- /etc/kubernetes/manifests
|
||||||
defaultconf: /etc/kubernetes/manifests/etcd.yaml
|
defaultconf: /etc/kubernetes/manifests/etcd.yaml
|
||||||
|
|
||||||
flanneld:
|
flanneld:
|
||||||
|
Loading…
Reference in New Issue
Block a user