mirror of https://git.rancher.io/charts
Merge pull request #2988 from rayandas/add-cis17-124
[dev-v2.8] Add CIS 1.24 and 1.7 in dev-v2.8 and bump the chart versionpull/2990/head
commit
d9abfdd6b3
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
|
@ -7,4 +7,4 @@ apiVersion: v1
|
||||||
description: Installs the CRDs for rancher-cis-benchmark.
|
description: Installs the CRDs for rancher-cis-benchmark.
|
||||||
name: rancher-cis-benchmark-crd
|
name: rancher-cis-benchmark-crd
|
||||||
type: application
|
type: application
|
||||||
version: 5.0.0-rc1
|
version: 5.0.0-rc2
|
|
@ -12,11 +12,11 @@ annotations:
|
||||||
catalog.cattle.io/type: cluster-tool
|
catalog.cattle.io/type: cluster-tool
|
||||||
catalog.cattle.io/ui-component: rancher-cis-benchmark
|
catalog.cattle.io/ui-component: rancher-cis-benchmark
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
appVersion: v5.0.0-rc1
|
appVersion: v5.0.0-rc2
|
||||||
description: The cis-operator enables running CIS benchmark security scans on a kubernetes
|
description: The cis-operator enables running CIS benchmark security scans on a kubernetes
|
||||||
cluster
|
cluster
|
||||||
icon: https://charts.rancher.io/assets/logos/cis-kube-bench.svg
|
icon: https://charts.rancher.io/assets/logos/cis-kube-bench.svg
|
||||||
keywords:
|
keywords:
|
||||||
- security
|
- security
|
||||||
name: rancher-cis-benchmark
|
name: rancher-cis-benchmark
|
||||||
version: 5.0.0-rc1
|
version: 5.0.0-rc2
|
|
@ -6,3 +6,4 @@ metadata:
|
||||||
spec:
|
spec:
|
||||||
clusterProvider: ""
|
clusterProvider: ""
|
||||||
minKubernetesVersion: "1.22.0"
|
minKubernetesVersion: "1.22.0"
|
||||||
|
maxKubernetesVersion: "1.23.x"
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: cis-1.24
|
||||||
|
spec:
|
||||||
|
clusterProvider: ""
|
||||||
|
minKubernetesVersion: "1.24.0"
|
||||||
|
maxKubernetesVersion: "1.24.x"
|
|
@ -0,0 +1,8 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: cis-1.7
|
||||||
|
spec:
|
||||||
|
clusterProvider: ""
|
||||||
|
minKubernetesVersion: "1.25.0"
|
|
@ -2,7 +2,7 @@
|
||||||
apiVersion: cis.cattle.io/v1
|
apiVersion: cis.cattle.io/v1
|
||||||
kind: ClusterScanBenchmark
|
kind: ClusterScanBenchmark
|
||||||
metadata:
|
metadata:
|
||||||
name: gke-1.0
|
name: gke-1.2.0
|
||||||
spec:
|
spec:
|
||||||
clusterProvider: gke
|
clusterProvider: gke
|
||||||
minKubernetesVersion: "1.15.0"
|
minKubernetesVersion: "1.15.0"
|
|
@ -6,3 +6,4 @@ metadata:
|
||||||
spec:
|
spec:
|
||||||
clusterProvider: k3s
|
clusterProvider: k3s
|
||||||
minKubernetesVersion: "1.22.0"
|
minKubernetesVersion: "1.22.0"
|
||||||
|
maxKubernetesVersion: "1.23.x"
|
|
@ -6,3 +6,4 @@ metadata:
|
||||||
spec:
|
spec:
|
||||||
clusterProvider: k3s
|
clusterProvider: k3s
|
||||||
minKubernetesVersion: "1.22.0"
|
minKubernetesVersion: "1.22.0"
|
||||||
|
maxKubernetesVersion: "1.23.x"
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: k3s-cis-1.24-hardened
|
||||||
|
spec:
|
||||||
|
clusterProvider: k3s
|
||||||
|
minKubernetesVersion: "1.24.0"
|
||||||
|
maxKubernetesVersion: "1.24.x"
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: k3s-cis-1.24-permissive
|
||||||
|
spec:
|
||||||
|
clusterProvider: k3s
|
||||||
|
minKubernetesVersion: "1.24.0"
|
||||||
|
maxKubernetesVersion: "1.24.x"
|
|
@ -0,0 +1,8 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: k3s-cis-1.7-hardened
|
||||||
|
spec:
|
||||||
|
clusterProvider: k3s
|
||||||
|
minKubernetesVersion: "1.25.0"
|
|
@ -0,0 +1,8 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: k3s-cis-1.7-permissive
|
||||||
|
spec:
|
||||||
|
clusterProvider: k3s
|
||||||
|
minKubernetesVersion: "1.25.0"
|
|
@ -6,3 +6,4 @@ metadata:
|
||||||
spec:
|
spec:
|
||||||
clusterProvider: rke
|
clusterProvider: rke
|
||||||
minKubernetesVersion: "1.22.0"
|
minKubernetesVersion: "1.22.0"
|
||||||
|
maxKubernetesVersion: "1.23.x"
|
|
@ -6,3 +6,4 @@ metadata:
|
||||||
spec:
|
spec:
|
||||||
clusterProvider: rke
|
clusterProvider: rke
|
||||||
minKubernetesVersion: "1.22.0"
|
minKubernetesVersion: "1.22.0"
|
||||||
|
maxKubernetesVersion: "1.23.x"
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: rke-cis-1.24-hardened
|
||||||
|
spec:
|
||||||
|
clusterProvider: rke
|
||||||
|
minKubernetesVersion: "1.24.0"
|
||||||
|
maxKubernetesVersion: "1.24.x"
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: rke-cis-1.24-permissive
|
||||||
|
spec:
|
||||||
|
clusterProvider: rke
|
||||||
|
minKubernetesVersion: "1.24.0"
|
||||||
|
maxKubernetesVersion: "1.24.x"
|
|
@ -0,0 +1,8 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: rke-cis-1.7-hardened
|
||||||
|
spec:
|
||||||
|
clusterProvider: rke
|
||||||
|
minKubernetesVersion: "1.25.0"
|
|
@ -0,0 +1,8 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: rke-cis-1.7-permissive
|
||||||
|
spec:
|
||||||
|
clusterProvider: rke
|
||||||
|
minKubernetesVersion: "1.25.0"
|
|
@ -6,3 +6,4 @@ metadata:
|
||||||
spec:
|
spec:
|
||||||
clusterProvider: rke2
|
clusterProvider: rke2
|
||||||
minKubernetesVersion: "1.22.0"
|
minKubernetesVersion: "1.22.0"
|
||||||
|
maxKubernetesVersion: "1.23.x"
|
|
@ -6,3 +6,4 @@ metadata:
|
||||||
spec:
|
spec:
|
||||||
clusterProvider: rke2
|
clusterProvider: rke2
|
||||||
minKubernetesVersion: "1.22.0"
|
minKubernetesVersion: "1.22.0"
|
||||||
|
maxKubernetesVersion: "1.23.x"
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: rke2-cis-1.24-hardened
|
||||||
|
spec:
|
||||||
|
clusterProvider: rke2
|
||||||
|
minKubernetesVersion: "1.24.0"
|
||||||
|
maxKubernetesVersion: "1.24.x"
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: rke2-cis-1.24-permissive
|
||||||
|
spec:
|
||||||
|
clusterProvider: rke2
|
||||||
|
minKubernetesVersion: "1.24.0"
|
||||||
|
maxKubernetesVersion: "1.24.x"
|
|
@ -0,0 +1,8 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: rke2-cis-1.7-hardened
|
||||||
|
spec:
|
||||||
|
clusterProvider: rke2
|
||||||
|
minKubernetesVersion: "1.25.0"
|
|
@ -0,0 +1,8 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanBenchmark
|
||||||
|
metadata:
|
||||||
|
name: rke2-cis-1.7-permissive
|
||||||
|
spec:
|
||||||
|
clusterProvider: rke2
|
||||||
|
minKubernetesVersion: "1.25.0"
|
|
@ -7,12 +7,12 @@ data:
|
||||||
# Default ClusterScanProfiles per cluster provider type
|
# Default ClusterScanProfiles per cluster provider type
|
||||||
rke: |-
|
rke: |-
|
||||||
<1.21.0: rke-profile-permissive-1.20
|
<1.21.0: rke-profile-permissive-1.20
|
||||||
>=1.21.0: rke-profile-permissive-1.23
|
>=1.21.0: rke-profile-permissive-1.7
|
||||||
rke2: |-
|
rke2: |-
|
||||||
<1.21.0: rke2-cis-1.20-profile-permissive
|
<1.21.0: rke2-cis-1.20-profile-permissive
|
||||||
>=1.21.0: rke2-cis-1.23-profile-permissive
|
>=1.21.0: rke2-cis-1.7-profile-permissive
|
||||||
eks: "eks-profile"
|
eks: "eks-profile"
|
||||||
gke: "gke-profile"
|
gke: "gke-profile"
|
||||||
aks: "aks-profile"
|
aks: "aks-profile"
|
||||||
k3s: "k3s-cis-1.23-profile-permissive"
|
k3s: "k3s-cis-1.7-profile-permissive"
|
||||||
default: "cis-1.23-profile"
|
default: "cis-1.7-profile"
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: cis-1.24-profile
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: cis-1.24
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: cis-1.7-profile
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: cis-1.7
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: k3s-cis-1.24-profile-hardened
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: k3s-cis-1.24-hardened
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: k3s-cis-1.24-profile-permissive
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: k3s-cis-1.24-permissive
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: k3s-cis-1.7-profile-hardened
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: k3s-cis-1.7-hardened
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: k3s-cis-1.7-profile-permissive
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: k3s-cis-1.7-permissive
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: rke-profile-hardened-1.24
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: rke-cis-1.24-hardened
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: rke-profile-permissive-1.24
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: rke-cis-1.24-permissive
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: rke-profile-hardened-1.7
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: rke-cis-1.7-hardened
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: rke-profile-permissive-1.7
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: rke-cis-1.7-permissive
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: rke2-cis-1.24-profile-hardened
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: rke2-cis-1.24-hardened
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: rke2-cis-1.24-profile-permissive
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: rke2-cis-1.24-permissive
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: rke2-cis-1.7-profile-hardened
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: rke2-cis-1.7-hardened
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
apiVersion: cis.cattle.io/v1
|
||||||
|
kind: ClusterScanProfile
|
||||||
|
metadata:
|
||||||
|
name: rke2-cis-1.7-profile-permissive
|
||||||
|
annotations:
|
||||||
|
clusterscanprofile.cis.cattle.io/builtin: "true"
|
||||||
|
spec:
|
||||||
|
benchmarkVersion: rke2-cis-1.7-permissive
|
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue