mirror of
https://github.com/aquasecurity/kube-bench.git
synced 2024-12-01 12:28:18 +00:00
af976e6f50
* Initial commit. * Add master and node config. * Add section 5 of CIS 1.5.1. * Split sections into section files * Fix YAML issues. * adds target translation * adds target translation * adds cis-1.5 mapping * fixed tests * fixes are per PR * fixed intergration test * integration kind test file to appropriate ks8 version * fixed etcd text * fixed README * fixed text * etcd: fixed grep path * etcd: fixes * fixed error message bug * Update README.md Co-Authored-By: Liz Rice <liz@lizrice.com> * Update README.md Co-Authored-By: Liz Rice <liz@lizrice.com> * fixes as per PR review
99 lines
2.9 KiB
Go
99 lines
2.9 KiB
Go
package cmd
|
|
|
|
import (
|
|
"fmt"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
|
|
"github.com/aquasecurity/kube-bench/check"
|
|
"github.com/golang/glog"
|
|
"github.com/spf13/cobra"
|
|
"github.com/spf13/viper"
|
|
)
|
|
|
|
func init() {
|
|
RootCmd.AddCommand(runCmd)
|
|
runCmd.Flags().StringSliceP("targets", "s", []string{},
|
|
`Specify targets of the benchmark to run. These names need to match the filenames in the cfg/<version> directory.
|
|
For example, to run the tests specified in master.yaml and etcd.yaml, specify --targets=master,etcd
|
|
If no targets are specified, run tests from all files in the cfg/<version> directory.
|
|
`)
|
|
}
|
|
|
|
// runCmd represents the run command
|
|
var runCmd = &cobra.Command{
|
|
Use: "run",
|
|
Short: "Run tests",
|
|
Long: `Run tests. If no arguments are specified, runs tests from all files`,
|
|
Run: func(cmd *cobra.Command, args []string) {
|
|
targets, err := cmd.Flags().GetStringSlice("targets")
|
|
if err != nil {
|
|
exitWithError(err)
|
|
}
|
|
|
|
benchmarkVersion, err := getBenchmarkVersion(kubeVersion, benchmarkVersion, viper.GetViper())
|
|
if err != nil {
|
|
exitWithError(err)
|
|
}
|
|
|
|
glog.V(2).Infof("Checking targets %v for %v", targets, benchmarkVersion)
|
|
if len(targets) > 0 && !validTargets(benchmarkVersion, targets) {
|
|
exitWithError(fmt.Errorf(fmt.Sprintf(`The specified --targets "%s" does not apply to the CIS Benchmark %s \n Valid targets %v`, strings.Join(targets, ","), benchmarkVersion, benchmarkVersionToTargetsMap[benchmarkVersion])))
|
|
}
|
|
|
|
// Merge version-specific config if any.
|
|
path := filepath.Join(cfgDir, benchmarkVersion)
|
|
mergeConfig(path)
|
|
|
|
err = run(targets, benchmarkVersion)
|
|
if err != nil {
|
|
fmt.Printf("Error in run: %v\n", err)
|
|
}
|
|
},
|
|
}
|
|
|
|
func run(targets []string, benchmarkVersion string) (err error) {
|
|
yamlFiles, err := getTestYamlFiles(targets, benchmarkVersion)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
glog.V(3).Infof("Running tests from files %v\n", yamlFiles)
|
|
|
|
for _, yamlFile := range yamlFiles {
|
|
_, name := filepath.Split(yamlFile)
|
|
testType := check.NodeType(strings.Split(name, ".")[0])
|
|
runChecks(testType, yamlFile)
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
func getTestYamlFiles(targets []string, benchmarkVersion string) (yamlFiles []string, err error) {
|
|
// Check that the specified targets have corresponding YAML files in the config directory
|
|
configFileDirectory := filepath.Join(cfgDir, benchmarkVersion)
|
|
for _, target := range targets {
|
|
filename := translate(target) + ".yaml"
|
|
file := filepath.Join(configFileDirectory, filename)
|
|
if _, err := os.Stat(file); err != nil {
|
|
return nil, fmt.Errorf("file %s not found for version %s", filename, benchmarkVersion)
|
|
}
|
|
yamlFiles = append(yamlFiles, file)
|
|
}
|
|
|
|
// If no targets were specified, we will run tests from all the files in the directory
|
|
if len(yamlFiles) == 0 {
|
|
yamlFiles, err = getYamlFilesFromDir(configFileDirectory)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
}
|
|
|
|
return yamlFiles, err
|
|
}
|
|
|
|
func translate(target string) string {
|
|
return strings.Replace(strings.ToLower(target), "worker", "node", -1)
|
|
}
|