Pin latest versions from security tools 83/70783/2
authorCédric Ollivier <cedric.ollivier@orange.com>
Fri, 14 Aug 2020 09:32:07 +0000 (11:32 +0200)
committerCédric Ollivier <cedric.ollivier@orange.com>
Fri, 14 Aug 2020 09:32:07 +0000 (11:32 +0200)
It selects kube-bench and kube-hunter 0.3.1.

Change-Id: Icb85f3d0d88056370500ec827ef77c215740e5e4
Signed-off-by: Cédric Ollivier <cedric.ollivier@orange.com>
(cherry picked from commit 6b8384b57a0bfc200c15ed9ded71544c33a27e81)

functest_kubernetes/security/kube-bench.yaml
functest_kubernetes/security/kube-hunter.yaml

index ec42ba1..38a2ef6 100644 (file)
@@ -12,7 +12,7 @@ spec:
       hostPID: true
       containers:
         - name: kube-bench
-          image: aquasec/kube-bench:latest
+          image: aquasec/kube-bench:0.3.1
           command: ["kube-bench"]
           volumeMounts:
             - name: var-lib-etcd
index ce88c06..b4452a5 100644 (file)
@@ -1,3 +1,4 @@
+---
 apiVersion: batch/v1
 kind: Job
 metadata:
@@ -7,7 +8,7 @@ spec:
     spec:
       containers:
       - name: kube-hunter
-        image: aquasec/kube-hunter
+        image: aquasec/kube-hunter:0.3.1
         command: ["python", "kube-hunter.py"]
         args: ["--pod"]
       restartPolicy: Never