We tried to harden the gke optimized image (gke-1.15.11) for our cluster. We took an ssh into the node instance and made the cis porposed changes in the /home/kubernetes/kubelet-config.yaml
file and ran kubebench to check if all the conditions have passed around 8 condtions failed these where the exact conditions we changed in the file. But, then we made the exact argument changes in /etc/default/kubernetes
and ran kubebench
again the conditions passed. But, when we restarted the instance we all the changes we made in the /ect/default/kubernetes
file where gone. Can someone let me know where we are going wrong or is there any other path where we have to make the cis benchmark suggested entries
Regarding GKE optimised image hardening
128 Views Asked by Hariharan Chandrasekar At
1
There are 1 best solutions below
Related Questions in KUBERNETES
- Is card-swipe hardware payment system-specific?
- Flipkart or Snapdeal like Payment Method in nopCommerce 3.5
- Any way to accept Credit Card swipes with a reader from a non-native Web App?
- Stripe: card holder name verification
- Google Play can't sell apps
- PayMill subscription interval regularity
- Fiserv/OSI DNA and ACH Origination job
- Checking for a successful charge using Stripe for rails
- Moneris Vault check if card exist
- ICICI payment integration with php.?? where to set redirect URL.?
Related Questions in GOOGLE-CLOUD-PLATFORM
- Is card-swipe hardware payment system-specific?
- Flipkart or Snapdeal like Payment Method in nopCommerce 3.5
- Any way to accept Credit Card swipes with a reader from a non-native Web App?
- Stripe: card holder name verification
- Google Play can't sell apps
- PayMill subscription interval regularity
- Fiserv/OSI DNA and ACH Origination job
- Checking for a successful charge using Stripe for rails
- Moneris Vault check if card exist
- ICICI payment integration with php.?? where to set redirect URL.?
Related Questions in GOOGLE-KUBERNETES-ENGINE
- Is card-swipe hardware payment system-specific?
- Flipkart or Snapdeal like Payment Method in nopCommerce 3.5
- Any way to accept Credit Card swipes with a reader from a non-native Web App?
- Stripe: card holder name verification
- Google Play can't sell apps
- PayMill subscription interval regularity
- Fiserv/OSI DNA and ACH Origination job
- Checking for a successful charge using Stripe for rails
- Moneris Vault check if card exist
- ICICI payment integration with php.?? where to set redirect URL.?
Related Questions in HARDENING
- Is card-swipe hardware payment system-specific?
- Flipkart or Snapdeal like Payment Method in nopCommerce 3.5
- Any way to accept Credit Card swipes with a reader from a non-native Web App?
- Stripe: card holder name verification
- Google Play can't sell apps
- PayMill subscription interval regularity
- Fiserv/OSI DNA and ACH Origination job
- Checking for a successful charge using Stripe for rails
- Moneris Vault check if card exist
- ICICI payment integration with php.?? where to set redirect URL.?
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular # Hahtags
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
GKE doesn't support user-provided node images as of April 2020. Recommended option is to create your own
DaemonSet
with host filesystem writes and/or host services restart to propagate all the required changes.