5 name: kube-bench-master
12 requiredDuringSchedulingIgnoredDuringExecution:
15 - key: node-role.kubernetes.io/control-plane
18 - key: node-role.kubernetes.io/master
21 - key: node-role.kubernetes.io/master
24 - key: node-role.kubernetes.io/control-plane
29 image: {{ dockerhub_repo }}/aquasec/kube-bench:latest
30 command: ["kube-bench", "run", "--targets", "master", "--json"]
33 mountPath: /var/lib/etcd
35 - name: var-lib-kubelet
36 mountPath: /var/lib/kubelet
38 - name: var-lib-kube-scheduler
39 mountPath: /var/lib/kube-scheduler
41 - name: var-lib-kube-controller-manager
42 mountPath: /var/lib/kube-controller-manager
45 mountPath: /etc/systemd
48 mountPath: /lib/systemd/
50 - name: srv-kubernetes
51 mountPath: /srv/kubernetes/
53 - name: etc-kubernetes
54 mountPath: /etc/kubernetes
56 # /usr/local/mount-from-host/bin is mounted to access kubectl / kubelet, for auto-detecting the Kubernetes version.
57 # You can omit this mount if you specify --version as part of the command.
59 mountPath: /usr/local/mount-from-host/bin
62 mountPath: /etc/cni/net.d/
65 mountPath: /opt/cni/bin/
68 mountPath: /etc/passwd
78 - name: var-lib-kubelet
80 path: "/var/lib/kubelet"
81 - name: var-lib-kube-scheduler
83 path: "/var/lib/kube-scheduler"
84 - name: var-lib-kube-controller-manager
86 path: "/var/lib/kube-controller-manager"
93 - name: srv-kubernetes
95 path: "/srv/kubernetes"
96 - name: etc-kubernetes
98 path: "/etc/kubernetes"
104 path: "/etc/cni/net.d/"
107 path: "/opt/cni/bin/"