Commit Graph

214 Commits (68c2ee2ebf9aa727302b9eca44185872b997d8a8)

Author SHA1 Message Date
Huang Huang 4a07f87e6f Fix remediations about file permission (#534)
5 years ago
Mateus Caruccio 6e1c39237a Openshift configs (#526)
5 years ago
Roberto Rojas af976e6f50
Fixes Issue #494 - add tests for CIS 1.5 (#530)
5 years ago
Huang Huang 7015f4b4b5 Fix remediation of 2.2.3 (#527)
5 years ago
Roberto Rojas 9c6d4de860 Issue #421: Merges PR #422 with master (#523)
5 years ago
Liz Rice d7b5422e8a Fix detection of encryption-provider-config (#513)
5 years ago
Roberto Rojas 7ca438b618
Fixes Issue 269 - Numbering to use CIS Versions (#511)
5 years ago
mwwolters 8276e521d4 Changed 1.3.3 to check that --use-service-account-credentials isn't set to false, but the flag is set (#442)
5 years ago
Roberto Rojas 13fe1cdfb8 Fixes issue #501: specifying absolute path for both ps and cat (#508)
5 years ago
Kevin W Monroe 04946a48fb add snap component paths to default config (#414)
5 years ago
Prem Kumar 01ee110ac4 Fix repetitive flags in some ocp-3.11 tests (#462)
5 years ago
Arpit Pandey ce0137a31a Fix few typos (#469)
5 years ago
Simarpreet Singh d77eab2234
master.yaml: Add --audit-policy-file check for 1.1.37. (#440)
5 years ago
Simarpreet Singh d12a45bba9 Properly initialize viper library when checking for master components (#434)
5 years ago
Roberto Rojas a6ee61fd08
Fixes issue #289: removed versions prior to 1.11 (#429)
5 years ago
Roberto Rojas 3aa41db166
Issue #353: Merges JSON and Exec Params files (#426)
5 years ago
Roberto Rojas c22f81610d
removes federated (#431)
5 years ago
yoavrotems 89afda1f63 Add [Manual test] to remediation in all the manual tests (#435)
5 years ago
Simarpreet Singh 37f626dce6 cfg: Make proxy checks optional (#436)
5 years ago
Roberto Rojas 41e0ae77de changes to use the "op: valid_elements" operation to manage list of items (#402)
5 years ago
yoavrotems ea9089bd42 update the yaml according (#410)
5 years ago
Roberto Rojas ec3b1076c0 Fixes issue #407 (#409)
5 years ago
Roberto Rojas 13dfa15ad6 Fixes Issue #396 - Replaces $kubeletconf for $kubeletsvc (#399)
5 years ago
Liz Rice a2466da4b0
Correct 1.1.13 to match CIS spec (#406)
5 years ago
Roberto Rojas 7a53806863 fixes issue #346 by explicitly only checking read-only property (#404)
5 years ago
yoavrotems 4b5a877f1f Remove some tests from been manual (#398)
5 years ago
Roberto Rojas f343d36862 hyperkube v1.15 renamed "proxy" to "kube-proxy" (#400)
5 years ago
Roberto Rojas 3e5d02e920 fixes issue #386 (#397)
5 years ago
Abubakr-Sadik Nii Nai Davis a3b8ba58ad Fix error converting from string to integer (#392)
5 years ago
Patrick Lieberg 0d81ef10d5 Update config.yaml to add Azure AKS file locations for kubelet (#383)
5 years ago
mwwolters 787bf6ca4d Updated check to pass if flag isn't set (#379)
5 years ago
Liz Rice f8b2f6c841
Correct 1.4.21 text (#356)
5 years ago
yoavrotems 136e9cd731 Remove federated from ocp (#381)
5 years ago
Efrat Levitan b8a463f051 Correction to 1.13 and 1.13-json test 2.1.5 (#380)
5 years ago
yoavrotems 22b971a633 fixes-according-kube-cis1.4.1 (#376)
5 years ago
Roberto Rojas 0422368615 issue #369: fixes RotateKubeletServerCertificate tests in 1.13-json (#371)
5 years ago
mwwolters 893aa3588c Updated check to pass if flag isn't set (#375)
5 years ago
Roberto Rojas 937bfc7b2e issue #344: Adds support for array comparison. Every element in the s… (#367)
5 years ago
Roberto Rojas c87c5cfb51 Fixes bugs on tests 2.1.4 and 2.1.5 - 1.13-json (#365)
5 years ago
Roberto Rojas 3926ba3977 issue #337: Adds comment for properties detected thru parsing command line. Fixed Audit for test 2.1.8 (#354)
5 years ago
Roberto Rojas d127512ab9 issue #349: changes test 2.2.8 (#351)
5 years ago
Roberto Rojas 336ca84998 fixes substitution variable (kubeletconf -> kubeletsvc). (#350)
5 years ago
zilard d8528a1ec8 issue #234: implement test 2.2.8 (#343)
5 years ago
Roberto Rojas a0bed18054 Adds json version of config for k8s 1.13 (#342)
5 years ago
Manuel Rüger 5e6cdfdb0e Detect kube-controller in CMD (#326)
5 years ago
Simarpreet Singh dddc42f046
cfg: remove erroneous whitespaces in yaml
5 years ago
pthomson 2275eea93f Adding OCP 3.11
5 years ago
Simarpreet Singh 5df39eed02
ocp-3.10: Fix malformed yaml and improve TestControls_RunChecks
5 years ago
Liz Rice bab1237a44
Merge branch 'master' into add_kubelet_config_path
5 years ago
Daniel Sagi 43caaab00a added another kubelet config file to paths, in the main config yaml file. default location for gke cluster
5 years ago
Liz Rice 9d577d94b4
Update openshift executables
5 years ago
Liz Rice 12e48297a6 Config file improvements
5 years ago
Liz Rice 02d5654cc1
Correct 1.1.14 in 1.13/master.yaml
5 years ago
Liz Rice caf3fbd0a0
Moving more config into master config file
5 years ago
daniellohausen 22e835f0f5 Reverted kubelet conf to original value
5 years ago
daniellohausen 7ec10211a5 Added KOPS-specific paths
5 years ago
Abubakr-Sadik Nii Nai Davis fbbf6b37c7 Change test_items in 1.11 master.yaml check 1.5.2 to fix issue with
5 years ago
Liz Rice 91c6ef2155
Merge branch 'master' into json-config
5 years ago
Liz Rice 7e8dfbc6ea
Fix invalid YAML
5 years ago
Liz Rice b4419e810f
Tiny typo
5 years ago
Liz Rice d05d71553f
Tiny typo
5 years ago
yoavrotems e70f50b2b5 update files
5 years ago
Liz Rice 27dc75fefa No need for unused master config file.
5 years ago
Liz Rice 902a10f1c7
Just have one path for both json and yaml
5 years ago
Liz Rice c887794807
Merge branch 'master' into feature/json-config
5 years ago
Liz Rice b1ce0a9a75
Merge branch 'master' into yoavrotems-patch-2
5 years ago
yoavrotems d059196b71
Update master.yaml
5 years ago
yoavrotems a85e5a7759
Update master.yaml
5 years ago
Florent Delannoy 4d3144ca21 Support JSON and YAML configuration
5 years ago
Liz Rice 9b3628e76a
Update openshift executable config for #236
5 years ago
Liz Rice 1ead9e1d71
Merge branch 'master' into clean-ocp-configs
5 years ago
Abubakr-Sadik Nii Nai Davis 53ed68a0b2 Clean up OCP benchmark config.
5 years ago
yoavrotems c6102f0a1b
Fix the files
5 years ago
yoavrotems e534392525
Delete node.yaml
5 years ago
yoavrotems 5f09ecef44
Delete master.yaml
5 years ago
yoavrotems a7d9e06c1b
Delete config.yaml
5 years ago
yoavrotems 50f22e7f13
Merge branch 'master' into add-new-cfg-version1.4
5 years ago
Liz Rice dd8e7ec874
Merge branch 'master' into fix-208
5 years ago
Abubakr-Sadik Nii Nai Davis d255b49d4b Revert 1.8 config file.
5 years ago
Abubakr-Sadik Nii Nai Davis a88b0703d8 Add kubeconfig variable substitution for kubelet and proxy.
5 years ago
Abubakr-Sadik Nii Nai Davis 3f98c1def2 Fix wrong reference to kubelet.config in node checks.
5 years ago
Liz Rice d712db47a2
Only find flags on the process we really want
5 years ago
yoavrotems 82150fdc63
add new config files from the new CIS Kubernetes Benchmark
5 years ago
Abubakr-Sadik Nii Nai Davis e899e941f7 Add OCP 3.10 benchmarks.
5 years ago
Maximilian Bischoff 791fbba9e7
Changed 1.1.14 to not fail when flag is not set
6 years ago
Liz Rice 2d721ed4ad
Merge branch 'master' into rm-space-tls-cipher
6 years ago
Colin GILLE ffe7ffb3d3
Type: trailing whitespace for rule text
6 years ago
Martin Mosegaard Amdisen fd120d0adf Remove spaces in remediation command for tls-cipher-suites
6 years ago
Liz Rice 26e28b8897
Merge branch 'master' into master
6 years ago
Maximilian Bischoff e81b785bf8
Added missing "=" to master.yaml
6 years ago
Vladimir Dimov 645d23e1ec
fixing typos 2.1.15
6 years ago
Liz Rice 6e80b6477a
Merge branch 'master' into fix-2.1.8
6 years ago
Abubakr-Sadik Nii Nai Davis 0a5358665e By default --make-iptables-util-chain is true, so PASS if this flag is not set.
6 years ago
Abubakr-Sadik Nii Nai Davis 4f40a11e84 Change binary op from and to or.
6 years ago
Abubakr-Sadik Nii Nai Davis c0f56e966a Fix check 1.1.37.
6 years ago
Nick Perry e083c8f0a3 Fixes https://github.com/aquasecurity/kube-bench/issues/170
6 years ago
Liz Rice 48489637c5
Merge branch 'master' into fix-1.3.7
6 years ago
Michal Jankowski 9988503223 Fixing 1.3.7 on 1.11 master.
6 years ago
Michal Jankowski 5f254de415 Fixing checks 2.2.9 and 2.2.10 on 1.11 nodes.
6 years ago
Abubakr-Sadik Nii Nai Davis 97623aea05 Update kubernetes node benchmark to check kubelet systemd unitfile.
6 years ago