mirror of
https://github.com/siderolabs/talos.git
synced 2025-08-23 15:41:10 +02:00
fix(hack): add /etc/kubernetes to CIS benchmark jobs (#199)
This commit is contained in:
parent
d662791ae4
commit
fc84b6218d
@ -19,5 +19,13 @@ spec:
|
||||
- master
|
||||
- --json
|
||||
- --version=1.11
|
||||
volumeMounts:
|
||||
- name: etc-kubernetes
|
||||
mountPath: /etc/kubernetes
|
||||
volumes:
|
||||
- name: etc-kubernetes
|
||||
hostPath:
|
||||
path: /etc/kubernetes
|
||||
type: Directory
|
||||
restartPolicy: Never
|
||||
backoffLimit: 0
|
||||
|
@ -13,5 +13,13 @@ spec:
|
||||
- node
|
||||
- --json
|
||||
- --version=1.11
|
||||
volumeMounts:
|
||||
- name: etc-kubernetes
|
||||
mountPath: /etc/kubernetes
|
||||
volumes:
|
||||
- name: etc-kubernetes
|
||||
hostPath:
|
||||
path: /etc/kubernetes
|
||||
type: Directory
|
||||
restartPolicy: Never
|
||||
backoffLimit: 0
|
||||
|
@ -14,14 +14,14 @@ run_master_benchmark() {
|
||||
JOB_NAME=kube-bench-master
|
||||
kubectl apply -f cis-kube-bench-master.yaml -n ${NAMESPACE}
|
||||
kubectl wait --timeout=60s --for=condition=complete job/${JOB_NAME} -n ${NAMESPACE} > /dev/null
|
||||
kubectl logs job/${JOB_NAME} -n ${NAMESPACE} | jq . >../build/cis-${JOB_NAME}.log
|
||||
kubectl logs job/${JOB_NAME} -n ${NAMESPACE} | jq . >../build/cis-${JOB_NAME}.json
|
||||
}
|
||||
|
||||
run_node_benchmark() {
|
||||
JOB_NAME=kube-bench-node
|
||||
kubectl apply -f cis-kube-bench-node.yaml -n ${NAMESPACE}
|
||||
kubectl wait --timeout=60s --for=condition=complete job/${JOB_NAME} -n ${NAMESPACE} > /dev/null
|
||||
kubectl logs job/${JOB_NAME} -n ${NAMESPACE} | jq . >../build/cis-${JOB_NAME}.log
|
||||
kubectl logs job/${JOB_NAME} -n ${NAMESPACE} | jq . >../build/cis-${JOB_NAME}.json
|
||||
}
|
||||
|
||||
kubectl create ns ${NAMESPACE}
|
||||
|
Loading…
x
Reference in New Issue
Block a user