forked from wwwil/kube-bench-gke
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathjob-gke.yaml
39 lines (39 loc) · 973 Bytes
/
job-gke.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
apiVersion: batch/v1
kind: Job
metadata:
name: kube-bench-node
spec:
template:
spec:
hostPID: true
containers:
- name: kube-bench
image: aquasec/kube-bench:latest
command:
- "kube-bench"
- "node"
- "--version"
- "1.12-gke"
volumeMounts:
- name: var-lib-kubelet
mountPath: /var/lib/kubelet
- name: etc-systemd
mountPath: /etc/systemd
- name: home-kubernetes
mountPath: /home/kubernetes
- name: kube-bench-cfg
mountPath: /opt/kube-bench/cfg/1.12-gke
restartPolicy: Never
volumes:
- name: var-lib-kubelet
hostPath:
path: "/var/lib/kubelet"
- name: etc-systemd
hostPath:
path: "/etc/systemd"
- name: home-kubernetes
hostPath:
path: "/home/kubernetes"
- name: kube-bench-cfg
configMap:
name: kube-bench-cfg-1.12-gke