Merge pull request #2988 from rayandas/add-cis17-124

[dev-v2.8] Add CIS 1.24 and 1.7 in dev-v2.8 and bump the chart version
pull/2990/head
Rayan Das 2023-09-16 00:29:50 +05:30 committed by GitHub
commit d9abfdd6b3
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
149 changed files with 535 additions and 31 deletions

View File

@ -7,4 +7,4 @@ apiVersion: v1
description: Installs the CRDs for rancher-cis-benchmark. description: Installs the CRDs for rancher-cis-benchmark.
name: rancher-cis-benchmark-crd name: rancher-cis-benchmark-crd
type: application type: application
version: 5.0.0-rc1 version: 5.0.0-rc2

View File

@ -12,11 +12,11 @@ annotations:
catalog.cattle.io/type: cluster-tool catalog.cattle.io/type: cluster-tool
catalog.cattle.io/ui-component: rancher-cis-benchmark catalog.cattle.io/ui-component: rancher-cis-benchmark
apiVersion: v1 apiVersion: v1
appVersion: v5.0.0-rc1 appVersion: v5.0.0-rc2
description: The cis-operator enables running CIS benchmark security scans on a kubernetes description: The cis-operator enables running CIS benchmark security scans on a kubernetes
cluster cluster
icon: https://charts.rancher.io/assets/logos/cis-kube-bench.svg icon: https://charts.rancher.io/assets/logos/cis-kube-bench.svg
keywords: keywords:
- security - security
name: rancher-cis-benchmark name: rancher-cis-benchmark
version: 5.0.0-rc1 version: 5.0.0-rc2

View File

@ -6,3 +6,4 @@ metadata:
spec: spec:
clusterProvider: "" clusterProvider: ""
minKubernetesVersion: "1.22.0" minKubernetesVersion: "1.22.0"
maxKubernetesVersion: "1.23.x"

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: cis-1.24
spec:
clusterProvider: ""
minKubernetesVersion: "1.24.0"
maxKubernetesVersion: "1.24.x"

View File

@ -0,0 +1,8 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: cis-1.7
spec:
clusterProvider: ""
minKubernetesVersion: "1.25.0"

View File

@ -2,7 +2,7 @@
apiVersion: cis.cattle.io/v1 apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark kind: ClusterScanBenchmark
metadata: metadata:
name: gke-1.0 name: gke-1.2.0
spec: spec:
clusterProvider: gke clusterProvider: gke
minKubernetesVersion: "1.15.0" minKubernetesVersion: "1.15.0"

View File

@ -6,3 +6,4 @@ metadata:
spec: spec:
clusterProvider: k3s clusterProvider: k3s
minKubernetesVersion: "1.22.0" minKubernetesVersion: "1.22.0"
maxKubernetesVersion: "1.23.x"

View File

@ -6,3 +6,4 @@ metadata:
spec: spec:
clusterProvider: k3s clusterProvider: k3s
minKubernetesVersion: "1.22.0" minKubernetesVersion: "1.22.0"
maxKubernetesVersion: "1.23.x"

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: k3s-cis-1.24-hardened
spec:
clusterProvider: k3s
minKubernetesVersion: "1.24.0"
maxKubernetesVersion: "1.24.x"

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: k3s-cis-1.24-permissive
spec:
clusterProvider: k3s
minKubernetesVersion: "1.24.0"
maxKubernetesVersion: "1.24.x"

View File

@ -0,0 +1,8 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: k3s-cis-1.7-hardened
spec:
clusterProvider: k3s
minKubernetesVersion: "1.25.0"

View File

@ -0,0 +1,8 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: k3s-cis-1.7-permissive
spec:
clusterProvider: k3s
minKubernetesVersion: "1.25.0"

View File

@ -6,3 +6,4 @@ metadata:
spec: spec:
clusterProvider: rke clusterProvider: rke
minKubernetesVersion: "1.22.0" minKubernetesVersion: "1.22.0"
maxKubernetesVersion: "1.23.x"

View File

@ -6,3 +6,4 @@ metadata:
spec: spec:
clusterProvider: rke clusterProvider: rke
minKubernetesVersion: "1.22.0" minKubernetesVersion: "1.22.0"
maxKubernetesVersion: "1.23.x"

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: rke-cis-1.24-hardened
spec:
clusterProvider: rke
minKubernetesVersion: "1.24.0"
maxKubernetesVersion: "1.24.x"

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: rke-cis-1.24-permissive
spec:
clusterProvider: rke
minKubernetesVersion: "1.24.0"
maxKubernetesVersion: "1.24.x"

View File

@ -0,0 +1,8 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: rke-cis-1.7-hardened
spec:
clusterProvider: rke
minKubernetesVersion: "1.25.0"

View File

@ -0,0 +1,8 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: rke-cis-1.7-permissive
spec:
clusterProvider: rke
minKubernetesVersion: "1.25.0"

View File

@ -6,3 +6,4 @@ metadata:
spec: spec:
clusterProvider: rke2 clusterProvider: rke2
minKubernetesVersion: "1.22.0" minKubernetesVersion: "1.22.0"
maxKubernetesVersion: "1.23.x"

View File

@ -6,3 +6,4 @@ metadata:
spec: spec:
clusterProvider: rke2 clusterProvider: rke2
minKubernetesVersion: "1.22.0" minKubernetesVersion: "1.22.0"
maxKubernetesVersion: "1.23.x"

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: rke2-cis-1.24-hardened
spec:
clusterProvider: rke2
minKubernetesVersion: "1.24.0"
maxKubernetesVersion: "1.24.x"

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: rke2-cis-1.24-permissive
spec:
clusterProvider: rke2
minKubernetesVersion: "1.24.0"
maxKubernetesVersion: "1.24.x"

View File

@ -0,0 +1,8 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: rke2-cis-1.7-hardened
spec:
clusterProvider: rke2
minKubernetesVersion: "1.25.0"

View File

@ -0,0 +1,8 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanBenchmark
metadata:
name: rke2-cis-1.7-permissive
spec:
clusterProvider: rke2
minKubernetesVersion: "1.25.0"

View File

@ -7,12 +7,12 @@ data:
# Default ClusterScanProfiles per cluster provider type # Default ClusterScanProfiles per cluster provider type
rke: |- rke: |-
<1.21.0: rke-profile-permissive-1.20 <1.21.0: rke-profile-permissive-1.20
>=1.21.0: rke-profile-permissive-1.23 >=1.21.0: rke-profile-permissive-1.7
rke2: |- rke2: |-
<1.21.0: rke2-cis-1.20-profile-permissive <1.21.0: rke2-cis-1.20-profile-permissive
>=1.21.0: rke2-cis-1.23-profile-permissive >=1.21.0: rke2-cis-1.7-profile-permissive
eks: "eks-profile" eks: "eks-profile"
gke: "gke-profile" gke: "gke-profile"
aks: "aks-profile" aks: "aks-profile"
k3s: "k3s-cis-1.23-profile-permissive" k3s: "k3s-cis-1.7-profile-permissive"
default: "cis-1.23-profile" default: "cis-1.7-profile"

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: cis-1.24-profile
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: cis-1.24

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: cis-1.7-profile
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: cis-1.7

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: k3s-cis-1.24-profile-hardened
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: k3s-cis-1.24-hardened

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: k3s-cis-1.24-profile-permissive
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: k3s-cis-1.24-permissive

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: k3s-cis-1.7-profile-hardened
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: k3s-cis-1.7-hardened

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: k3s-cis-1.7-profile-permissive
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: k3s-cis-1.7-permissive

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: rke-profile-hardened-1.24
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: rke-cis-1.24-hardened

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: rke-profile-permissive-1.24
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: rke-cis-1.24-permissive

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: rke-profile-hardened-1.7
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: rke-cis-1.7-hardened

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: rke-profile-permissive-1.7
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: rke-cis-1.7-permissive

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: rke2-cis-1.24-profile-hardened
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: rke2-cis-1.24-hardened

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: rke2-cis-1.24-profile-permissive
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: rke2-cis-1.24-permissive

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: rke2-cis-1.7-profile-hardened
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: rke2-cis-1.7-hardened

View File

@ -0,0 +1,9 @@
---
apiVersion: cis.cattle.io/v1
kind: ClusterScanProfile
metadata:
name: rke2-cis-1.7-profile-permissive
annotations:
clusterscanprofile.cis.cattle.io/builtin: "true"
spec:
benchmarkVersion: rke2-cis-1.7-permissive

Some files were not shown because too many files have changed in this diff Show More