mirror of
https://github.com/siderolabs/talos.git
synced 2025-08-23 15:41:10 +02:00
fix(hack): add /etc/kubernetes to CIS benchmark jobs (#199)
This commit is contained in:
parent
d662791ae4
commit
fc84b6218d
@ -19,5 +19,13 @@ spec:
|
|||||||
- master
|
- master
|
||||||
- --json
|
- --json
|
||||||
- --version=1.11
|
- --version=1.11
|
||||||
|
volumeMounts:
|
||||||
|
- name: etc-kubernetes
|
||||||
|
mountPath: /etc/kubernetes
|
||||||
|
volumes:
|
||||||
|
- name: etc-kubernetes
|
||||||
|
hostPath:
|
||||||
|
path: /etc/kubernetes
|
||||||
|
type: Directory
|
||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
backoffLimit: 0
|
backoffLimit: 0
|
||||||
|
@ -13,5 +13,13 @@ spec:
|
|||||||
- node
|
- node
|
||||||
- --json
|
- --json
|
||||||
- --version=1.11
|
- --version=1.11
|
||||||
|
volumeMounts:
|
||||||
|
- name: etc-kubernetes
|
||||||
|
mountPath: /etc/kubernetes
|
||||||
|
volumes:
|
||||||
|
- name: etc-kubernetes
|
||||||
|
hostPath:
|
||||||
|
path: /etc/kubernetes
|
||||||
|
type: Directory
|
||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
backoffLimit: 0
|
backoffLimit: 0
|
||||||
|
@ -14,14 +14,14 @@ run_master_benchmark() {
|
|||||||
JOB_NAME=kube-bench-master
|
JOB_NAME=kube-bench-master
|
||||||
kubectl apply -f cis-kube-bench-master.yaml -n ${NAMESPACE}
|
kubectl apply -f cis-kube-bench-master.yaml -n ${NAMESPACE}
|
||||||
kubectl wait --timeout=60s --for=condition=complete job/${JOB_NAME} -n ${NAMESPACE} > /dev/null
|
kubectl wait --timeout=60s --for=condition=complete job/${JOB_NAME} -n ${NAMESPACE} > /dev/null
|
||||||
kubectl logs job/${JOB_NAME} -n ${NAMESPACE} | jq . >../build/cis-${JOB_NAME}.log
|
kubectl logs job/${JOB_NAME} -n ${NAMESPACE} | jq . >../build/cis-${JOB_NAME}.json
|
||||||
}
|
}
|
||||||
|
|
||||||
run_node_benchmark() {
|
run_node_benchmark() {
|
||||||
JOB_NAME=kube-bench-node
|
JOB_NAME=kube-bench-node
|
||||||
kubectl apply -f cis-kube-bench-node.yaml -n ${NAMESPACE}
|
kubectl apply -f cis-kube-bench-node.yaml -n ${NAMESPACE}
|
||||||
kubectl wait --timeout=60s --for=condition=complete job/${JOB_NAME} -n ${NAMESPACE} > /dev/null
|
kubectl wait --timeout=60s --for=condition=complete job/${JOB_NAME} -n ${NAMESPACE} > /dev/null
|
||||||
kubectl logs job/${JOB_NAME} -n ${NAMESPACE} | jq . >../build/cis-${JOB_NAME}.log
|
kubectl logs job/${JOB_NAME} -n ${NAMESPACE} | jq . >../build/cis-${JOB_NAME}.json
|
||||||
}
|
}
|
||||||
|
|
||||||
kubectl create ns ${NAMESPACE}
|
kubectl create ns ${NAMESPACE}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user