-
Notifications
You must be signed in to change notification settings - Fork 15.1k
Security hardening guide for scheduler configuration #45080
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security hardening guide for scheduler configuration #45080
Conversation
|
|
|
Welcome @AnshumanTripathi! |
✅ Pull request preview available for checkingBuilt without sensitive environment variables
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
/sig security |
|
@kubernetes/sig-security-pr-reviews please take a look |
0728e98 to
2cae0ed
Compare
5958b41 to
90fb6d6
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Some more feedback.
beca647 to
2aa72f3
Compare
19972a5 to
ab53e96
Compare
37e8ff3 to
767eb20
Compare
767eb20 to
c1a7095
Compare
|
/remove-area localization |
c1a7095 to
54dcea7
Compare
As mentioned, could you wrap all your lines so that's it's easier to make suggestions and edits? |
5d7b524 to
3c15880
Compare
Wrapped long lines. LMK more is needed. |
Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> [WIP] Security hardening guide for scheduler configurations Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Updates after passing through hemmingway.app Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Update scheduling configurations Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Apply suggestions from code review Co-authored-by: Tim Bannister <tim@scalefactory.com> Co-authored-by: Daniel Register <jedion9@yahoo.com> Updates based on PR feedback Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Update bind-address definition Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Update phrasing of permit-address-sharing Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Add -- to args Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Sentence case in table title Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Reword and correct grammer based on feedback Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Remove verbatim argument description Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> More updates Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Update custom scheduler heading and description Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Remove dashes on args Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Apply suggestions from code review Co-authored-by: Tim Bannister <tim@scalefactory.com> Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Update table title Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Update based on feedback Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> node selector Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Feedback Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Update authentication and TLS configuration Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> profiling Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Replace tables with bullets Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Fix custom scheduler directive and link Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> style Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> Update based on feedback Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com> fix: custom scheduler profile Signed-off-by: Anshuman Tripathi <anshuman.tripathi305@gmail.com>
3c15880 to
b0d8a8c
Compare
|
/lgtm |
|
LGTM label has been added. Git tree hash: 7450a0d530136c46aa8f2457c3b8c6e514ed1ffe
|
|
/approve Happy to see the content reorganized where needed, along with existing content. |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: lmktfy The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
hey folks – i'm seeing a hold on this PR but it's not clear why its the case. are we ready to unhold and merge? we have several reviews from Security and Docs – thanks for clarifying! @tabbysable @raesene @lmktfy |
|
If we really need to revert, we can. /hold cancel |
Creating a scheduler hardening guide as a part of kubernetes/sig-security#30.
Page preview - https://deploy-preview-45080--kubernetes-io-main-staging.netlify.app/docs/concepts/security/hardening-guide/scheduler/