Skip to content

Commit e9d999d

Browse files
committed
add PSA testdata 1.32
1 parent 97108d5 commit e9d999d

File tree

130 files changed

+3199
-18
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

130 files changed

+3199
-18
lines changed

staging/src/k8s.io/pod-security-admission/policy/check_sysctls.go

Lines changed: 6 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -90,30 +90,19 @@ var (
9090
"net.ipv4.ping_group_range",
9191
"net.ipv4.ip_unprivileged_port_start",
9292
)
93-
sysctlsAllowedV1Dot27 = sets.NewString(
94-
"kernel.shm_rmid_forced",
95-
"net.ipv4.ip_local_port_range",
96-
"net.ipv4.tcp_syncookies",
97-
"net.ipv4.ping_group_range",
98-
"net.ipv4.ip_unprivileged_port_start",
99-
"net.ipv4.ip_local_reserved_ports",
100-
)
101-
sysctlsAllowedV1Dot29 = sets.NewString(
102-
"kernel.shm_rmid_forced",
103-
"net.ipv4.ip_local_port_range",
104-
"net.ipv4.tcp_syncookies",
105-
"net.ipv4.ping_group_range",
106-
"net.ipv4.ip_unprivileged_port_start",
93+
sysctlsAllowedV1Dot27 = sysctlsAllowedV1Dot0.Union(sets.NewString(
10794
"net.ipv4.ip_local_reserved_ports",
95+
))
96+
sysctlsAllowedV1Dot29 = sysctlsAllowedV1Dot27.Union(sets.NewString(
10897
"net.ipv4.tcp_keepalive_time",
10998
"net.ipv4.tcp_fin_timeout",
11099
"net.ipv4.tcp_keepalive_intvl",
111100
"net.ipv4.tcp_keepalive_probes",
112-
)
113-
sysctlsAllowedV1Dot32 = sets.NewString(
101+
))
102+
sysctlsAllowedV1Dot32 = sysctlsAllowedV1Dot29.Union(sets.NewString(
114103
"net.ipv4.tcp_rmem",
115104
"net.ipv4.tcp_wmem",
116-
)
105+
))
117106
)
118107

119108
func sysctlsV1Dot0(podMetadata *metav1.ObjectMeta, podSpec *corev1.PodSpec) CheckResult {

staging/src/k8s.io/pod-security-admission/test/run.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ import (
3737
)
3838

3939
const (
40-
newestMinorVersionToTest = 31
40+
newestMinorVersionToTest = 32
4141
podOSBasedRestrictionEnabledVersion = 29
4242
)
4343

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
apiVersion: v1
2+
kind: Pod
3+
metadata:
4+
annotations:
5+
container.apparmor.security.beta.kubernetes.io/container1: unconfined
6+
name: apparmorprofile0
7+
spec:
8+
containers:
9+
- image: registry.k8s.io/pause
10+
name: container1
11+
initContainers:
12+
- image: registry.k8s.io/pause
13+
name: initcontainer1
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
apiVersion: v1
2+
kind: Pod
3+
metadata:
4+
annotations:
5+
container.apparmor.security.beta.kubernetes.io/initcontainer1: unconfined
6+
name: apparmorprofile1
7+
spec:
8+
containers:
9+
- image: registry.k8s.io/pause
10+
name: container1
11+
initContainers:
12+
- image: registry.k8s.io/pause
13+
name: initcontainer1
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
apiVersion: v1
2+
kind: Pod
3+
metadata:
4+
name: capabilities_baseline0
5+
spec:
6+
containers:
7+
- image: registry.k8s.io/pause
8+
name: container1
9+
securityContext:
10+
capabilities:
11+
add:
12+
- NET_RAW
13+
initContainers:
14+
- image: registry.k8s.io/pause
15+
name: initcontainer1
16+
securityContext:
17+
capabilities: {}
18+
securityContext: {}
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
apiVersion: v1
2+
kind: Pod
3+
metadata:
4+
name: capabilities_baseline1
5+
spec:
6+
containers:
7+
- image: registry.k8s.io/pause
8+
name: container1
9+
securityContext:
10+
capabilities: {}
11+
initContainers:
12+
- image: registry.k8s.io/pause
13+
name: initcontainer1
14+
securityContext:
15+
capabilities:
16+
add:
17+
- NET_RAW
18+
securityContext: {}
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
apiVersion: v1
2+
kind: Pod
3+
metadata:
4+
name: capabilities_baseline2
5+
spec:
6+
containers:
7+
- image: registry.k8s.io/pause
8+
name: container1
9+
securityContext:
10+
capabilities:
11+
add:
12+
- chown
13+
initContainers:
14+
- image: registry.k8s.io/pause
15+
name: initcontainer1
16+
securityContext:
17+
capabilities: {}
18+
securityContext: {}
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
apiVersion: v1
2+
kind: Pod
3+
metadata:
4+
name: capabilities_baseline3
5+
spec:
6+
containers:
7+
- image: registry.k8s.io/pause
8+
name: container1
9+
securityContext:
10+
capabilities:
11+
add:
12+
- CAP_CHOWN
13+
initContainers:
14+
- image: registry.k8s.io/pause
15+
name: initcontainer1
16+
securityContext:
17+
capabilities: {}
18+
securityContext: {}
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: v1
2+
kind: Pod
3+
metadata:
4+
name: hostnamespaces0
5+
spec:
6+
containers:
7+
- image: registry.k8s.io/pause
8+
name: container1
9+
hostIPC: true
10+
initContainers:
11+
- image: registry.k8s.io/pause
12+
name: initcontainer1
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: v1
2+
kind: Pod
3+
metadata:
4+
name: hostnamespaces1
5+
spec:
6+
containers:
7+
- image: registry.k8s.io/pause
8+
name: container1
9+
hostNetwork: true
10+
initContainers:
11+
- image: registry.k8s.io/pause
12+
name: initcontainer1

0 commit comments

Comments
 (0)