diff options
Diffstat (limited to 'test/security/k8s/src/check/validators')
-rw-r--r-- | test/security/k8s/src/check/validators/master/api.go | 11 |
1 files changed, 6 insertions, 5 deletions
diff --git a/test/security/k8s/src/check/validators/master/api.go b/test/security/k8s/src/check/validators/master/api.go index ac84d8f1c..c91b77e30 100644 --- a/test/security/k8s/src/check/validators/master/api.go +++ b/test/security/k8s/src/check/validators/master/api.go @@ -40,11 +40,6 @@ func IsAnonymousAuthDisabled(params []string) bool { return hasSingleFlagArgument("--anonymous-auth=", "false", params) } -// IsKubeletHTTPSConnected validates there is single "--kubelet-https" flag and it is set to "true". -func IsKubeletHTTPSConnected(params []string) bool { - return hasSingleFlagArgument("--kubelet-https=", "true", params) -} - // IsInsecurePortUnbound validates there is single "--insecure-port" flag and it is set to "0" (disabled). func IsInsecurePortUnbound(params []string) bool { return hasSingleFlagArgument("--insecure-port=", strconv.Itoa(portDisabled), params) @@ -96,6 +91,12 @@ func splitKV(s, sep string) (string, string) { return ret[0], ret[1] } +// IsKubeletHTTPSAbsentOrEnabled validates there is single "--kubelet-https" flag and it is set to "true". +func IsKubeletHTTPSAbsentOrEnabled(params []string) bool { + return isFlagAbsent("--kubelet-https=", params) || + hasSingleFlagArgument("--kubelet-https=", "true", params) +} + // IsInsecureBindAddressAbsentOrLoopback validates there is no insecure bind address or it is loopback address. func IsInsecureBindAddressAbsentOrLoopback(params []string) bool { return isFlagAbsent("--insecure-bind-address=", params) || |