mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-08-05 10:19:50 +00:00
Disallow local loopback for volume hosts
Change-Id: Ic356c3f859057153cfad97327f1938792a1a512c
This commit is contained in:
parent
4fc184f383
commit
9a7dcd36c1
@ -1999,6 +1999,7 @@ function start-kube-controller-manager {
|
|||||||
params+=("--kubeconfig=${config_path}" "--authentication-kubeconfig=${config_path}" "--authorization-kubeconfig=${config_path}")
|
params+=("--kubeconfig=${config_path}" "--authentication-kubeconfig=${config_path}" "--authorization-kubeconfig=${config_path}")
|
||||||
params+=("--root-ca-file=${CA_CERT_BUNDLE_PATH}")
|
params+=("--root-ca-file=${CA_CERT_BUNDLE_PATH}")
|
||||||
params+=("--service-account-private-key-file=${SERVICEACCOUNT_KEY_PATH}")
|
params+=("--service-account-private-key-file=${SERVICEACCOUNT_KEY_PATH}")
|
||||||
|
params+=("--volume-host-allow-local-loopback=false")
|
||||||
if [[ -n "${ENABLE_GARBAGE_COLLECTOR:-}" ]]; then
|
if [[ -n "${ENABLE_GARBAGE_COLLECTOR:-}" ]]; then
|
||||||
params+=("--enable-garbage-collector=${ENABLE_GARBAGE_COLLECTOR}")
|
params+=("--enable-garbage-collector=${ENABLE_GARBAGE_COLLECTOR}")
|
||||||
fi
|
fi
|
||||||
|
Loading…
Reference in New Issue
Block a user