12 image: {{ dockerhub_repo }}/aquasec/kube-bench:latest
13 command: ["kube-bench", "run", "--targets", "node", "--json"]
16 mountPath: /var/lib/etcd
18 - name: var-lib-kubelet
19 mountPath: /var/lib/kubelet
21 - name: var-lib-kube-scheduler
22 mountPath: /var/lib/kube-scheduler
24 - name: var-lib-kube-controller-manager
25 mountPath: /var/lib/kube-controller-manager
28 mountPath: /etc/systemd
31 mountPath: /lib/systemd/
33 - name: srv-kubernetes
34 mountPath: /srv/kubernetes/
36 - name: etc-kubernetes
37 mountPath: /etc/kubernetes
39 # /usr/local/mount-from-host/bin is mounted to access kubectl / kubelet, for auto-detecting the Kubernetes version.
40 # You can omit this mount if you specify --version as part of the command.
42 mountPath: /usr/local/mount-from-host/bin
45 mountPath: /etc/cni/net.d/
48 mountPath: /opt/cni/bin/
55 - name: var-lib-kubelet
57 path: "/var/lib/kubelet"
58 - name: var-lib-kube-scheduler
60 path: "/var/lib/kube-scheduler"
61 - name: var-lib-kube-controller-manager
63 path: "/var/lib/kube-controller-manager"
70 - name: srv-kubernetes
72 path: "/srv/kubernetes"
73 - name: etc-kubernetes
75 path: "/etc/kubernetes"
81 path: "/etc/cni/net.d/"