Skip to content

Add hardened example #1132

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 4 commits into
base: main
Choose a base branch
from
Open

Conversation

WinsonSou
Copy link

What problem does this PR solve?:
CIS Level 1 + 2 Benchmarks for Control Planes and Workers
Which issue(s) this PR fixes:
N/A

How Has This Been Tested?:
Create NKP 2.14.0 Cluster
Clone and Patch kubeadmcontrolplanetemplate and kubeadmconfigtemplate
Patch ClusterClass to reference new kubeadmcontrolplanetemplate and kubeadmconfigtemplate
Perform Tenable CIS Benchmark Scan
Upgrade Cluster to NKP 2.15.0
Clone and Patch upgraded kubeadmcontrolplanetemplate and kubeadmconfigtemplate
Patch Upgraded ClusterClass to reference new kubeadmcontrolplanetemplate and kubeadmconfigtemplate
Perform Tenable CIS Benchmark Scan

@WinsonSou
Copy link
Author

Commit edited for simplified hardening + support for 2.14.0 and 2.15.0

jimmidyson added a commit that referenced this pull request May 29, 2025
Pulling in most of the changes from #1132.

This commit does not include Kubelet CSR Approver because that requires
more invasive changes (e.g. deploying the `kubelet-csr-approver` service
and reconfiguring kubelet after initial startup.
jimmidyson added a commit that referenced this pull request May 29, 2025
Pulling in most of the changes from #1132.

This commit does not include Kubelet CSR Approver because that requires
more invasive changes (e.g. deploying the `kubelet-csr-approver` service
and reconfiguring kubelet after initial startup.
jimmidyson added a commit that referenced this pull request Jun 2, 2025
Pulling in most of the changes from #1132.

This commit does not include Kubelet CSR Approver because that requires
more invasive changes (e.g. deploying the `kubelet-csr-approver` service
and reconfiguring kubelet after initial startup.
jimmidyson added a commit that referenced this pull request Jun 3, 2025
Pulling in most of the changes from #1132.

This commit does not include Kubelet CSR Approver because that requires
more invasive changes (e.g. deploying the `kubelet-csr-approver` service
and reconfiguring kubelet after initial startup.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant