[rke2] - enable cis-profile, add configuration for CIS hardening #263
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What type of PR is this?
/kind feature
What this PR does / why we need it: Enables the CIS profile for the RKE2 flavor and adds some extra configuration for CIS hardening. Unfortunately we can't use "cis" for RKE2 1.29 due to a CRD validation issue where that is not present in the enum. I've opened a PR upstream for that in the meantime.
With an RKE2 cluster provisioned by CAPL with these changes, I ran a scan on it after installing the
rancher-cis-benchmark
helm chart:Which issue(s) this PR fixes (optional, in
fixes #<issue number>(, fixes #<issue_number>, ...)
format, will close the issue(s) when PR gets merged):Fixes #
Special notes for your reviewer:
TODOs: