Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue: default setting for tls.config is InsecureSkipVerify: true #1912

Open
KaiyiLiu1234 opened this issue Jan 19, 2025 · 0 comments
Labels
kind/bug report bug issue

Comments

@KaiyiLiu1234
Copy link
Collaborator

What happened?

According to this Instance 1 and Instance 2, we default set InsecureSkipVerify to true.

What did you expect to happen?

By default, we should not be skipping sslverification as this can lead to a security breach.

How can we reproduce it (as minimally and precisely as possible)?

Code by default has set InsecureSkipVerify to true.

Anything else we need to know?

No response

Kepler image tag

latest

Kubernetes version

$ kubectl version
# paste output here

Cloud provider or bare metal

all

OS version

# On Linux:
$ cat /etc/os-release
# paste output here
$ uname -a
# paste output here

# On Windows:
C:\> wmic os get Caption, Version, BuildNumber, OSArchitecture
# paste output here

Install tools

Kepler deployment config

For on kubernetes:

$ KEPLER_NAMESPACE=kepler

# provide kepler configmap
$ kubectl get configmap kepler-cfm -n ${KEPLER_NAMESPACE}
# paste output here

# provide kepler deployment description
$ kubectl describe deployment kepler-exporter -n ${KEPLER_NAMESPACE}

For standalone:

put your Kepler command argument here

Container runtime (CRI) and version (if applicable)

Related plugins (CNI, CSI, ...) and versions (if applicable)

@KaiyiLiu1234 KaiyiLiu1234 added the kind/bug report bug issue label Jan 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug report bug issue
Projects
None yet
Development

No branches or pull requests

1 participant