mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-08-03 09:22:44 +00:00
Rename to capabilities_restricted
This commit is contained in:
parent
08608a24f1
commit
250f47a45c
@ -33,25 +33,25 @@ const (
|
|||||||
)
|
)
|
||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
addCheck(CheckDropCapabilities)
|
addCheck(CheckCapabilitiesRestricted)
|
||||||
}
|
}
|
||||||
|
|
||||||
// CheckDropCapabilities returns a restricted level check
|
// CheckCapabilitiesRestricted returns a restricted level check
|
||||||
// that ensures all capabilities are dropped in 1.22+
|
// that ensures ALL capabilities are dropped in 1.22+
|
||||||
func CheckDropCapabilities() Check {
|
func CheckCapabilitiesRestricted() Check {
|
||||||
return Check{
|
return Check{
|
||||||
ID: "dropCapabilities",
|
ID: "capabilities_restricted",
|
||||||
Level: api.LevelRestricted,
|
Level: api.LevelRestricted,
|
||||||
Versions: []VersionedCheck{
|
Versions: []VersionedCheck{
|
||||||
{
|
{
|
||||||
MinimumVersion: api.MajorMinorVersion(1, 22),
|
MinimumVersion: api.MajorMinorVersion(1, 22),
|
||||||
CheckPod: dropCapabilities_1_22,
|
CheckPod: capabilitiesRestricted_1_22,
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func dropCapabilities_1_22(podMetadata *metav1.ObjectMeta, podSpec *corev1.PodSpec) CheckResult {
|
func capabilitiesRestricted_1_22(podMetadata *metav1.ObjectMeta, podSpec *corev1.PodSpec) CheckResult {
|
||||||
var (
|
var (
|
||||||
containersMissingDropAll []string
|
containersMissingDropAll []string
|
||||||
containersAddingForbidden []string
|
containersAddingForbidden []string
|
@ -90,7 +90,7 @@ func init() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
registerFixtureGenerator(
|
registerFixtureGenerator(
|
||||||
fixtureKey{level: api.LevelRestricted, version: api.MajorMinorVersion(1, 22), check: "dropCapabilities"},
|
fixtureKey{level: api.LevelRestricted, version: api.MajorMinorVersion(1, 22), check: "capabilities_restricted"},
|
||||||
fixtureData_1_22,
|
fixtureData_1_22,
|
||||||
)
|
)
|
||||||
}
|
}
|
Loading…
Reference in New Issue
Block a user