Skip to content

feat(misconf): add support for new allowed sysctls in AVD-KSV-0026 #8739

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
nikpivkin opened this issue Apr 16, 2025 · 3 comments
Open

feat(misconf): add support for new allowed sysctls in AVD-KSV-0026 #8739

nikpivkin opened this issue Apr 16, 2025 · 3 comments
Assignees
Labels
scan/misconfiguration Issues relating to misconfiguration scanning

Comments

@nikpivkin
Copy link
Contributor

With the release of new Kubernetes versions, the list of allowed sysctls has expanded. We need to update this in the AVD-KSV-0026 check.

Discussed in #8736

@nikpivkin
Copy link
Contributor Author

@simar7 Some allowed sysctls have a minimum Kubernetes version. Should the check be improved to take into account the k8s version from data.k8s.version?

@simar7
Copy link
Member

simar7 commented Apr 16, 2025

@simar7 Some allowed sysctls have a minimum Kubernetes version. Should the check be improved to take into account the k8s version from data.k8s.version?

Yeah sounds good to me.

@nikpivkin
Copy link
Contributor Author

I'll do it in another PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
scan/misconfiguration Issues relating to misconfiguration scanning
Projects
None yet
Development

No branches or pull requests

2 participants