Adjust default kubeconfig file permissions #7978
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Signed-off-by: Derek Nola [email protected]
Proposed Changes
cis-1.24 and newer (the upcoming cis-1.7, yes the name is weird) have moved to a more restrictive kubeconfig default. As the folder
var/lib/rancher/k3s/server/cred
containing these files is restricted to root users only, further restricting the files to read only for root does not present a huge change in file access.Types of Changes
Verification
All
.kubeconfig
files should be 600 permissionsTesting
Linked Issues
#7975
User-Facing Change
Further Comments