mirror of
https://github.com/siderolabs/talos.git
synced 2025-08-30 19:11:13 +02:00
feat(init): enable PSP admission plugin (#230)
This commit is contained in:
parent
f870acdae1
commit
d0a0d1f3a0
@ -106,11 +106,10 @@ func EnforceTLSRequirements(cfg *kubeadmapi.InitConfiguration) error {
|
||||
|
||||
// EnforceAdmissionPluginsRequirements enforces CIS requirements for admission plugins.
|
||||
// TODO(andrewrynhard): Include any extra user specified plugins.
|
||||
// TODO(andrewrynhard): Enable PodSecurityPolicy.
|
||||
// TODO(andrewrynhard): Enable EventRateLimit.
|
||||
func EnforceAdmissionPluginsRequirements(cfg *kubeadmapi.InitConfiguration) error {
|
||||
// nolint: lll
|
||||
cfg.APIServerExtraArgs["enable-admission-plugins"] = "AlwaysPullImages,SecurityContextDeny,DenyEscalatingExec,NamespaceLifecycle,ServiceAccount,NodeRestriction,LimitRanger,DefaultStorageClass,DefaultTolerationSeconds,ResourceQuota"
|
||||
cfg.APIServerExtraArgs["enable-admission-plugins"] = "AlwaysPullImages,PodSecurityPolicy,DenyEscalatingExec,NamespaceLifecycle,ServiceAccount,NodeRestriction,LimitRanger,DefaultStorageClass,DefaultTolerationSeconds,ResourceQuota"
|
||||
|
||||
return nil
|
||||
}
|
||||
|
Loading…
x
Reference in New Issue
Block a user