Merge pull request #539 from andypitcher/fix-k3s-cis-1.11-node-4.2.4-readonlyport
Andy Pitcher
2025-10-15 11:32:32 +0200
31fb100e6bfix: 4.2.4 (read-only-port) change test and remediation to reflect k3s' new default --- K3s enforces by default --read-only-port to 0, so we only verify the presence of --read-only-port=0.
Andy Pitcher
2025-10-13 21:28:41 +0200
2f2bdc0475fix: 4.2.4 (read-only-port) change test and remediation to reflect k3s' new default --- K3s enforces by default --read-only-port to 0, so we only verify the presence of --read-only-port=0.
Andy Pitcher
2025-10-13 21:28:41 +0200
41cc4f7237fix: 4.2.4 (read-only-port) change test and remediation to reflect k3s' new default --- K3s enforces by default --read-only-port to 0, so we only verify the presence of --read-only-port=0.
Andy Pitcher
2025-10-13 21:28:41 +0200
fix: 4.2.4 (read-only-port) change test and remediation to reflect k3s' new default --- K3s enforces by default --read-only-port to 0, so we only verify the presence of --read-only-port=0.
Andy Pitcher
2025-10-13 21:28:41 +0200
7efd22d30ck3s-cis-1.11 - Generate placeholder files - add target mapping and versions - master: 1.2.30 Ensure that the --service-account-extend-token-expiration parameter is set to false - master: 1.2.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual) - Changed from 600 to 644 - Changed from Manual to Automated - node: 4.2.14 Ensure that the --seccomp-default parameter is set to true (Manual) - node: 4.2.4 Verify that if defined, the --read-only-port argument is set to 0 (Automated) - Add 'if defined' - policies: 5.1.1 to 5.1.6 from (Automated) to (Manual) - policies: section titled 'General Policies' was renumbered from 5.7 in v1.10 to 5.6
Andy Pitcher
2025-09-10 12:08:16 +0200
c43539d2f6rke2-cis-1.11 - Generate placeholder files - master: 1.2.30 Ensure that the --service-account-extend-token-expiration parameter is set to false - master: 1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Automated) - Changed from 600 to 644 - Changed from Manual to Automated - node: 4.2.14 Ensure that the --seccomp-default parameter is set to true (Manual) - node: 4.2.4 Verify that if defined, the --read-only-port argument is set to 0 (Automated) - Add 'if defined' - policies: 5.1.1 to 5.1.6 from (Automated) to (Manual) - policies: section titled 'General Policies' was renumbered from 5.7 in v1.10 to 5.6
Andy Pitcher
2025-09-12 19:57:06 +0200
7e0a81015ck3s-cis-1.11 - Generate placeholder files - add target mapping and versions - master: 1.2.30 Ensure that the --service-account-extend-token-expiration parameter is set to false - master: 1.2.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual) - Changed from 600 to 644 - Changed from Manual to Automated - node: 4.2.14 Ensure that the --seccomp-default parameter is set to true (Manual) - node: 4.2.4 Verify that if defined, the --read-only-port argument is set to 0 (Automated) - Add 'if defined' - policies: 5.1.1 to 5.1.6 from (Automated) to (Manual) - policies: section titled 'General Policies' was renumbered from 5.7 in v1.10 to 5.6
Andy Pitcher
2025-09-10 12:08:16 +0200
386f95ac24rke2-cis-1.11 - Generate placeholder files - master: 1.2.30 Ensure that the --service-account-extend-token-expiration parameter is set to false - master: 1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Automated) - Changed from 600 to 644 - Changed from Manual to Automated - node: 4.2.14 Ensure that the --seccomp-default parameter is set to true (Manual) - node: 4.2.4 Verify that if defined, the --read-only-port argument is set to 0 (Automated) - Add 'if defined' - policies: 5.1.1 to 5.1.6 from (Automated) to (Manual) - policies: section titled 'General Policies' was renumbered from 5.7 in v1.10 to 5.6
Andy Pitcher
2025-09-12 19:57:06 +0200
Merge pull request #525 from rancher/renovate/github-actions
Paulo Gomes
2025-09-23 09:04:25 +0100
58e536f9cdrke2-cis-1.11 - Generate placeholder files - master: 1.2.30 Ensure that the --service-account-extend-token-expiration parameter is set to false - master: 1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Automated) - Changed from 600 to 644 - Changed from Manual to Automated - node: 4.2.14 Ensure that the --seccomp-default parameter is set to true (Manual) - node: 4.2.4 Verify that if defined, the --read-only-port argument is set to 0 (Automated) - Add 'if defined' - policies: 5.1.1 to 5.1.6 from (Automated) to (Manual) - policies: section titled 'General Policies' was renumbered from 5.7 in v1.10 to 5.6
Andy Pitcher
2025-09-12 19:57:06 +0200
39e70f901bk3s-cis-1.11 - Generate placeholder files - add target mapping and versions - master: 1.2.30 Ensure that the --service-account-extend-token-expiration parameter is set to false - master: 1.2.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual) - Changed from 600 to 644 - Changed from Manual to Automated - node: 4.2.14 Ensure that the --seccomp-default parameter is set to true (Manual) - node: 4.2.4 Verify that if defined, the --read-only-port argument is set to 0 (Automated) - Add 'if defined' - policies: 5.1.1 to 5.1.6 from (Automated) to (Manual) - policies: section titled 'General Policies' was renumbered from 5.7 in v1.10 to 5.6
Andy Pitcher
2025-09-10 12:08:16 +0200
rke2-cis-1.11 - Generate placeholder files - master: 1.2.30 Ensure that the --service-account-extend-token-expiration parameter is set to false - master: 1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Automated) - Changed from 600 to 644 - Changed from Manual to Automated - node: 4.2.14 Ensure that the --seccomp-default parameter is set to true (Manual) - node: 4.2.4 Verify that if defined, the --read-only-port argument is set to 0 (Automated) - Add 'if defined' - policies: 5.1.1 to 5.1.6 from (Automated) to (Manual) - policies: section titled 'General Policies' was renumbered from 5.7 in v1.10 to 5.6
Andy Pitcher
2025-09-12 19:57:06 +0200
k3s-cis-1.11 - Generate placeholder files - add target mapping and versions - master: 1.2.30 Ensure that the --service-account-extend-token-expiration parameter is set to false - master: 1.2.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual) - Changed from 600 to 644 - Changed from Manual to Automated - node: 4.2.14 Ensure that the --seccomp-default parameter is set to true (Manual) - node: 4.2.4 Verify that if defined, the --read-only-port argument is set to 0 (Automated) - Add 'if defined' - policies: 5.1.1 to 5.1.6 from (Automated) to (Manual) - policies: section titled 'General Policies' was renumbered from 5.7 in v1.10 to 5.6
Andy Pitcher
2025-09-10 12:08:16 +0200
renovate: Use preset to align with Rancher Manager versions This aligns with the configuration applied to the operator. The matchBaseBranches has been updated so that it uses regex as opposed to literal names.
Paulo Gomes
2025-09-04 12:42:53 +0100