Andrew Rynhard 09fbe2d9ad feat: add security hardening settings
This pulls in an update from our bootkube fork that adds security
hardening to the control plane. The following was changed:

- API server now uses an EncryptionConfig for encrypting secrets
- API server now has an audit policy
- Profiling was disabled on all control plane components
- PodSecurityPolicy is enabled
- API server TLS cipher suites were set to the recommended ciphers by CIS

Signed-off-by: Andrew Rynhard <andrew@andrewrynhard.com>
2019-12-09 15:26:26 -08:00
..
2019-12-09 15:26:26 -08:00