Skip to content

Expand validate-yaml to kube-bench cfgs #503

@andypitcher

Description

@andypitcher

Context: In the current CI we are validating yamls (lint, kube-bench run and check type correctness) for our own cfgs only, the ones that located in security-scan/package/cfgs. It's not the case for the upstream (kube-bench) profiles that we download during the build of security-scan.

The goal of this issue is to improve this by:

  1. Adding a the validate-yaml step in the Dockerfile (right after the kube-bench's cfgs download)
  2. Improving the comments in validate-yaml to mention that only the local cfgs are tested.

cc @pjbgf

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions