Tiller Deployment accessible within cluster 이 페이지는 아직 한국어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다. Id: kubernetes-tiller-deployment-is-accessible-from-within-the-cluster
Platform: Kubernetes
Severity: High
Category: Networking and Firewall
Learn More Description Tiller deployments must not allow access from within the cluster. Tiller containers must include the --listen argument and set it to a local address (for example localhost or 127.0.0.1). Resources lacking args or whose --listen value is not a local address are flagged.
Compliant Code Examples apiVersion : apps/v1
kind : Deployment
metadata :
name : tiller-deploy
labels :
app : helm
name : tiller
spec :
selector :
matchLabels :
app : helm
name : tiller
template :
metadata :
labels :
app : helm
name : tiller
spec :
serviceAccountName : tiller
containers :
- name : tiller
image : "tiller-image"
args : [ "--listen=127.0.0.1:44134" ]
ports :
- containerPort : 44134
name : tiller
protocol : TCP
- containerPort : 44135
name : http
protocol : TCP
Non-Compliant Code Examples ---
apiVersion : apps/v1
kind : Deployment
metadata :
labels :
app : helm
name : tiller
name : tiller-bad-args
spec :
selector :
matchLabels :
name : tiller
template :
metadata :
labels :
app : helm
name : tiller
spec :
containers :
-
args :
- "--listen=10.7.2.8:44134"
image : tiller-image
name : tiller-v2
ports :
-
containerPort : 44134
name : tiller
protocol : TCP
-
containerPort : 44135
name : http
protocol : TCP
serviceAccountName : tiller
---
apiVersion : apps/v1
kind : Deployment
metadata :
labels :
app : helm
name : tiller
name : tiller-deploy-no-args
spec :
selector :
matchLabels :
name : tiller
template :
metadata :
labels :
app : helm
name : tiller
spec :
containers :
-
name : tiller-v2
image : tiller-image
serviceAccountName : tiller