mirror of
https://github.com/aquasecurity/kube-bench.git
synced 2025-01-12 00:30:58 +00:00
4d3144ca21
Support new configuration options besides --flags: - JSON file through `jsonpath` - YAML file through `yamlpath` These new options are fully backwards-compatible with the existing tests. Added a new profile, 1.11-json, that expects a JSON kubelet configuration file and scores accordingly. This profile is compatible with EKS.
31 lines
766 B
YAML
31 lines
766 B
YAML
---
|
|
## Controls Files.
|
|
# These are YAML files that hold all the details for running checks.
|
|
#
|
|
## Uncomment to use different control file paths.
|
|
# masterControls: ./cfg/master.yaml
|
|
# nodeControls: ./cfg/node.yaml
|
|
# federatedControls: ./cfg/federated.yaml
|
|
|
|
# Master nodes are controlled by EKS and not user-accessible
|
|
master:
|
|
components: []
|
|
|
|
node:
|
|
kubernetes:
|
|
confs:
|
|
- "/var/lib/kubelet/kubeconfig"
|
|
kubeconfig:
|
|
- "/var/lib/kubelet/kubeconfig"
|
|
|
|
kubelet:
|
|
bins:
|
|
- "hyperkube kubelet"
|
|
- "kubelet"
|
|
defaultconf: "/etc/kubernetes/kubelet/kubelet-config.json"
|
|
defaultsvc: "/etc/systemd/system/kubelet.service"
|
|
defaultkubeconfig: "/var/lib/kubelet/kubeconfig"
|
|
|
|
proxy:
|
|
defaultkubeconfig: "/var/lib/kubelet/kubeconfig"
|