You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Overview
I just upgraded my AWS EKS cluster to Kubernetes 1.29 - afterwards kube-bench reports 3 new findings that haven't been reported in 1.28:
[FAIL] 3.2.1 Ensure that the Anonymous Auth is Not Enabled (Automated)
[FAIL] 3.2.2 Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
[FAIL] 3.2.6 Ensure that the --protect-kernel-defaults argument is set to true (Automated)
What happened?
It alerts although the configuration is correct (=>false positive).
What did you expect to happen:
It should return [PASS] for the checks mentioned above.
Environment
[What is your version of kube-bench? (run kube-bench version)]
kube-bench version: docker.io/aquasec/kube-bench:v0.7.3
Kubernetes version: AWS EKS 1.29, almost "default configuration"
(almost skipping this one, as the problem is, that the file is not found), here is one snippet for the Findings above:
"protectKernelDefaults": true,
Anything else you would like to add:
I debugged it by comparing the staging and prod clusters (compared old vs. new).
My resolution was that the kubelet config path has changed in the 1.29 version of AWS EKS and this path is not included in the list of kube-bench.
The text was updated successfully, but these errors were encountered:
Overview
I just upgraded my AWS EKS cluster to Kubernetes 1.29 - afterwards kube-bench reports 3 new findings that haven't been reported in 1.28:
How did you run kube-bench?
What happened?
It alerts although the configuration is correct (=>false positive).
What did you expect to happen:
It should return
[PASS]
for the checks mentioned above.Environment
[What is your version of kube-bench? (run
kube-bench version
)]kube-bench version:
docker.io/aquasec/kube-bench:v0.7.3
Kubernetes version: AWS EKS 1.29, almost "default configuration"
Running processes
Configuration files
(almost skipping this one, as the problem is, that the file is not found), here is one snippet for the Findings above:
Anything else you would like to add:
I debugged it by comparing the staging and prod clusters (compared old vs. new).
My resolution was that the kubelet config path has changed in the 1.29 version of AWS EKS and this path is not included in the list of kube-bench.
The text was updated successfully, but these errors were encountered: