kubermatic / docs

Documentation for Kubermatic projects
https://docs.kubermatic.com/
Other
15 stars 105 forks source link

Add CIS Benchmark documentation to KubeOne #1637

Closed koksay closed 7 months ago

koksay commented 7 months ago

This PR adds CIS Benchmark 1.8 documentation for KubeOne 1.7.3 and Kubernetes 1.27.

It especially requires a review for:

  1. Formatting in general
  2. Details section for Not Applicable controls
  3. Warn and Fail controls, if they should be changed to Not Applicable
koksay commented 7 months ago

@embik I believe I covered all the items except --anonymous-auth parameter setting. To be honest, I have no idea why we don't set it at all (other than it does not cause issues because or our RBAC settings)

embik commented 7 months ago

@embik I believe I covered all the items except --anonymous-auth parameter setting. To be honest, I have no idea why we don't set it at all (other than it does not cause issues because or our RBAC settings)

I think this document will need another review from @xmudrii and @kron4eg to figure out things like that.

koksay commented 7 months ago

@xmudrii Thanks again for the review. I updated the document based on your feedback.

I also added my doc generation python script to the hack directory, so it would be used later.

koksay commented 7 months ago

@xmudrii I put it on the main documentation, should it also be under 1.7?

xmudrii commented 7 months ago

@koksay Adding it to 1.7 makes sense, do you want to do that before we merge this PR?

kubermatic-bot commented 7 months ago

LGTM label has been added.

Git tree hash: 933182b385cb85e8dd8c4c27a0cbe00f28f5df51

kubermatic-bot commented 7 months ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: xmudrii

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/kubermatic/docs/blob/master/OWNERS)~~ [xmudrii] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment