Skip to content

Commit 1381b93

Browse files
authored
Merge pull request #855 from swastik959/release/v1.4
feat: update CIS operator to v1.4.3 and add benchmarks for k3s and rke2 CIS 1.11
1 parent 72fef9c commit 1381b93

16 files changed

+146
-88
lines changed

chart/Chart.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,11 +12,11 @@ annotations:
1212
catalog.cattle.io/type: cluster-tool
1313
catalog.cattle.io/ui-component: rancher-cis-benchmark
1414
apiVersion: v1
15-
appVersion: v8.2.0
15+
appVersion: v8.3.0-rc.1
1616
description: The cis-operator enables running CIS benchmark security scans on a kubernetes
1717
cluster
1818
icon: https://charts.rancher.io/assets/logos/cis-kube-bench.svg
1919
keywords:
2020
- security
2121
name: rancher-cis-benchmark
22-
version: 8.2.0
22+
version: 8.3.0-rc.1

chart/templates/benchmark-cis-1.10.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,4 +5,5 @@ metadata:
55
name: cis-1.10
66
spec:
77
clusterProvider: ""
8-
minKubernetesVersion: "1.28.0"
8+
minKubernetesVersion: "1.28.0"
9+
maxKubernetesVersion: "1.28.x"
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
---
2+
apiVersion: cis.cattle.io/v1
3+
kind: ClusterScanBenchmark
4+
metadata:
5+
name: cis-1.11
6+
spec:
7+
clusterProvider: ""
8+
minKubernetesVersion: "1.29.0"

chart/templates/benchmark-k3s-cis-1.10.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,4 +5,5 @@ metadata:
55
name: k3s-cis-1.10
66
spec:
77
clusterProvider: k3s
8-
minKubernetesVersion: "1.28.0"
8+
minKubernetesVersion: "1.28.0"
9+
maxKubernetesVersion: "1.28.x"
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
---
2+
apiVersion: cis.cattle.io/v1
3+
kind: ClusterScanBenchmark
4+
metadata:
5+
name: k3s-cis-1.11
6+
spec:
7+
clusterProvider: k3s
8+
minKubernetesVersion: "1.29.0"

chart/templates/benchmark-rke2-cis-1.10.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,4 +5,5 @@ metadata:
55
name: rke2-cis-1.10
66
spec:
77
clusterProvider: rke2
8-
minKubernetesVersion: "1.28.0"
8+
minKubernetesVersion: "1.28.0"
9+
maxKubernetesVersion: "1.28.x"
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
---
2+
apiVersion: cis.cattle.io/v1
3+
kind: ClusterScanBenchmark
4+
metadata:
5+
name: rke2-cis-1.11
6+
spec:
7+
clusterProvider: rke2
8+
minKubernetesVersion: "1.29.0"

chart/templates/configmap.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,9 +10,9 @@ data:
1010
>=1.21.0: rke-profile-permissive-1.8
1111
rke2: |-
1212
<1.21.0: rke2-cis-1.20-profile-permissive
13-
>=1.21.0: rke2-cis-1.10-profile
13+
>=1.21.0: rke2-cis-1.11-profile
1414
eks: "eks-profile-1.5.0"
1515
gke: "gke-profile-1.6.0"
1616
aks: "aks-profile"
17-
k3s: "k3s-cis-1.10-profile"
18-
default: "cis-1.10-profile"
17+
k3s: "k3s-cis-1.11-profile"
18+
default: "cis-1.11-profile"
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
apiVersion: cis.cattle.io/v1
3+
kind: ClusterScanProfile
4+
metadata:
5+
name: cis-1.11-profile
6+
annotations:
7+
clusterscanprofile.cis.cattle.io/builtin: "true"
8+
spec:
9+
benchmarkVersion: cis-1.11
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
apiVersion: cis.cattle.io/v1
3+
kind: ClusterScanProfile
4+
metadata:
5+
name: k3s-cis-1.11-profile
6+
annotations:
7+
clusterscanprofile.cis.cattle.io/builtin: "true"
8+
spec:
9+
benchmarkVersion: k3s-cis-1.11

0 commit comments

Comments
 (0)