metal-stack / gardener-extension-provider-metal

Implementation of the gardener-extension-controller for metal-stack
MIT License
24 stars 11 forks source link

☂️-Issue reduce container capabilities #267

Open majst01 opened 2 years ago

majst01 commented 2 years ago

Reduce capabilities of our containers found by https://github.com/bridgecrewio/checkov:

CKV_K8S_15 is kept as it is because we always have semver versioning for images in place without the ability to override a already pushed image. CKV_K8S_40 is not changed because we do not write from our containers.

Gardener components

These needs to be fixed at gardener