Azure / acs-engine

WE HAVE MOVED: Please join us at Azure/aks-engine!
https://github.com/Azure/aks-engine
MIT License
1.03k stars 560 forks source link

New version of K8S required due to CVE-2018-1002105 #4336

Closed zentron closed 5 years ago

zentron commented 5 years ago

According to Kubernetes Version Support there won't be new kubernetes releases provided unless there is a compelling business need

Due to the Major security flaw revealed recently in CVE-2018-1002105 it feels like there is a pretty compelling business need. :) Patches are baing made available for kubernetes v1.10.11+ however according to the ACS feature status support is currently only available in ACS up to v1.6.6

What are to official plans for the ACS engine in response to this incident? Ideally an updated K8S version should be made available.