Über Open CoDE Software Wiki Diskussionen GitLab

Skip to content
Snippets Groups Projects

Draft: added sysctl net.ipv4.ip_unprivileged_port_start (since 1.22 included )

Closed Rainer Molitor requested to merge feature/cs-add-sysctl into master
3 unresolved threads
1 file
+ 5
0
Compare changes
  • Side-by-side
  • Inline
@@ -38,5 +38,10 @@ spec:
spec:
=(securityContext):
=(sysctls):
(minorversion) >= 2
- name: "kernel.shm_rmid_forced | net.ipv4.ip_local_port_range | net.ipv4.tcp_syncookies | net.ipv4.ping_group_range | net.ipv4.ip_unprivileged_port_start"
    • Comment on lines +41 to +42

      failed to process /builds/ig-bvc/policy-entwicklung/richtlinien-umsetzung-kyverno/policies/restrict-sysctls.yaml: failed to convert to JSON: yaml: line 42: mapping values are not allowed in this context

Please register or sign in to reply
(minorversion) < 2
- name: "kernel.shm_rmid_forced | net.ipv4.ip_local_port_range | net.ipv4.tcp_syncookies | net.ipv4.ping_group_range "
    • Suggested change
      44 - name: "kernel.shm_rmid_forced | net.ipv4.ip_local_port_range | net.ipv4.tcp_syncookies | net.ipv4.ping_group_range "
      44 - name: "kernel.shm_rmid_forced | net.ipv4.ip_local_port_range | net.ipv4.tcp_syncookies | net.ipv4.ping_group_range"
Please register or sign in to reply
X(minorversion)
- name: "kernel.shm_rmid_forced | net.ipv4.ip_local_port_range | net.ipv4.tcp_syncookies | net.ipv4.ping_group_range"
value: "?*"
Loading