From 09dbcf8d55546a3c40a2f3bbb7698c89169081f9 Mon Sep 17 00:00:00 2001 From: Takuya Murakami Date: Sun, 28 Jan 2024 21:11:50 +0900 Subject: [PATCH] Remove GAed feature gates SecCompDefault The SecCompDefault feature gate was removed since k8s 1.29 https://github.com/kubernetes/kubernetes/pull/121246 --- docs/hardening.md | 2 +- tests/files/packet_ubuntu20-calico-all-in-one-hardening.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/hardening.md b/docs/hardening.md index fe2f3a568a8..8623bdc30e5 100644 --- a/docs/hardening.md +++ b/docs/hardening.md @@ -97,7 +97,7 @@ kubelet_event_record_qps: 1 kubelet_rotate_certificates: true kubelet_streaming_connection_idle_timeout: "5m" kubelet_make_iptables_util_chains: true -kubelet_feature_gates: ["RotateKubeletServerCertificate=true", "SeccompDefault=true"] +kubelet_feature_gates: ["RotateKubeletServerCertificate=true"] kubelet_seccomp_default: true kubelet_systemd_hardening: true # In case you have multiple interfaces in your diff --git a/tests/files/packet_ubuntu20-calico-all-in-one-hardening.yml b/tests/files/packet_ubuntu20-calico-all-in-one-hardening.yml index d8dcc1f8e6d..55cbd506374 100644 --- a/tests/files/packet_ubuntu20-calico-all-in-one-hardening.yml +++ b/tests/files/packet_ubuntu20-calico-all-in-one-hardening.yml @@ -86,7 +86,7 @@ kubelet_event_record_qps: 1 kubelet_rotate_certificates: true kubelet_streaming_connection_idle_timeout: "5m" kubelet_make_iptables_util_chains: true -kubelet_feature_gates: ["RotateKubeletServerCertificate=true", "SeccompDefault=true"] +kubelet_feature_gates: ["RotateKubeletServerCertificate=true"] kubelet_seccomp_default: true kubelet_systemd_hardening: true # In case you have multiple interfaces in your