-
Notifications
You must be signed in to change notification settings - Fork 4
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
2 changed files
with
41 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -390,10 +390,14 @@ spec: | |
content: | | ||
# Restrict key exchange, cipher, and MAC algorithms, as per sshaudit.com | ||
# hardening guide. | ||
KexAlgorithms curve25519-sha256,[email protected],diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha256 | ||
KexAlgorithms [email protected],curve25519-sha256,[email protected],gss-curve25519-sha256-,diffie-hellman-group16-sha512,gss-group16-sha512-,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha256 | ||
Ciphers [email protected],[email protected],[email protected],aes256-ctr,aes192-ctr,aes128-ctr | ||
MACs [email protected],[email protected],[email protected] | ||
HostKeyAlgorithms ssh-ed25519,[email protected],[email protected],[email protected],rsa-sha2-256,rsa-sha2-512,[email protected],[email protected] | ||
HostKeyAlgorithms [email protected],[email protected],[email protected],[email protected],[email protected],ssh-ed25519,rsa-sha2-512,rsa-sha2-256 | ||
CASignatureAlgorithms [email protected],ssh-ed25519,rsa-sha2-512,rsa-sha2-256 | ||
GSSAPIKexAlgorithms gss-curve25519-sha256-,gss-group16-sha512- | ||
HostbasedAcceptedAlgorithms [email protected],[email protected],[email protected],ssh-ed25519,[email protected],rsa-sha2-512,[email protected],rsa-sha2-256 | ||
PubkeyAcceptedAlgorithms [email protected],[email protected],[email protected],ssh-ed25519,[email protected],rsa-sha2-512,[email protected],rsa-sha2-256 | ||
- path: /etc/sysctl.d/k8s.conf | ||
content: | | ||
fs.inotify.max_user_watches = 65536 | ||
|
@@ -501,6 +505,20 @@ spec: | |
kubectl --kubeconfig /etc/kubernetes/kubelet.conf | ||
patch node $(hostname) | ||
--type strategic -p '{"spec": {"providerID": "ionos://'$${system_uuid}'"}}' | ||
- rm /etc/ssh/ssh_host_* | ||
- ssh-keygen -t rsa -b 4096 -f /etc/ssh/ssh_host_rsa_key -N "" | ||
- ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key -N "" | ||
- sed -i 's/^\#HostKey \/etc\/ssh\/ssh_host_\(rsa\|ed25519\)_key$/HostKey \/etc\/ssh\/ssh_host_\1_key/g' /etc/ssh/sshd_config | ||
- awk '$5 >= 3071' /etc/ssh/moduli > /etc/ssh/moduli.safe | ||
- mv /etc/ssh/moduli.safe /etc/ssh/moduli | ||
- iptables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --set | ||
- iptables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 10 --hitcount 10 -j DROP | ||
- ip6tables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --set | ||
- ip6tables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 10 --hitcount 10 -j DROP | ||
- apt-get update | ||
- DEBIAN_FRONTEND=noninteractive apt-get install -q -y netfilter-persistent iptables-persistent | ||
- service netfilter-persistent save | ||
- systemctl restart sshd | ||
initConfiguration: | ||
localAPIEndpoint: {} | ||
nodeRegistration: | ||
|
@@ -566,10 +584,14 @@ spec: | |
content: | | ||
# Restrict key exchange, cipher, and MAC algorithms, as per sshaudit.com | ||
# hardening guide. | ||
KexAlgorithms curve25519-sha256,[email protected],diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha256 | ||
KexAlgorithms [email protected],curve25519-sha256,[email protected],gss-curve25519-sha256-,diffie-hellman-group16-sha512,gss-group16-sha512-,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha256 | ||
Ciphers [email protected],[email protected],[email protected],aes256-ctr,aes192-ctr,aes128-ctr | ||
MACs [email protected],[email protected],[email protected] | ||
HostKeyAlgorithms ssh-ed25519,[email protected],[email protected],[email protected],rsa-sha2-256,rsa-sha2-512,[email protected],[email protected] | ||
HostKeyAlgorithms [email protected],[email protected],[email protected],[email protected],[email protected],ssh-ed25519,rsa-sha2-512,rsa-sha2-256 | ||
CASignatureAlgorithms [email protected],ssh-ed25519,rsa-sha2-512,rsa-sha2-256 | ||
GSSAPIKexAlgorithms gss-curve25519-sha256-,gss-group16-sha512- | ||
HostbasedAcceptedAlgorithms [email protected],[email protected],[email protected],ssh-ed25519,[email protected],rsa-sha2-512,[email protected],rsa-sha2-256 | ||
PubkeyAcceptedAlgorithms [email protected],[email protected],[email protected],ssh-ed25519,[email protected],rsa-sha2-512,[email protected],rsa-sha2-256 | ||
- path: /etc/sysctl.d/k8s.conf | ||
content: | | ||
fs.inotify.max_user_watches = 65536 | ||
|
@@ -603,6 +625,20 @@ spec: | |
kubectl --kubeconfig /etc/kubernetes/kubelet.conf | ||
patch node $(hostname) | ||
--type strategic -p '{"spec": {"providerID": "ionos://'$${system_uuid}'"}}' | ||
- rm /etc/ssh/ssh_host_* | ||
- ssh-keygen -t rsa -b 4096 -f /etc/ssh/ssh_host_rsa_key -N "" | ||
- ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key -N "" | ||
- sed -i 's/^\#HostKey \/etc\/ssh\/ssh_host_\(rsa\|ed25519\)_key$/HostKey \/etc\/ssh\/ssh_host_\1_key/g' /etc/ssh/sshd_config | ||
- awk '$5 >= 3071' /etc/ssh/moduli > /etc/ssh/moduli.safe | ||
- mv /etc/ssh/moduli.safe /etc/ssh/moduli | ||
- iptables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --set | ||
- iptables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 10 --hitcount 10 -j DROP | ||
- ip6tables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --set | ||
- ip6tables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 10 --hitcount 10 -j DROP | ||
- apt-get update | ||
- DEBIAN_FRONTEND=noninteractive apt-get install -q -y netfilter-persistent iptables-persistent | ||
- service netfilter-persistent save | ||
- systemctl restart sshd | ||
joinConfiguration: | ||
nodeRegistration: | ||
kubeletExtraArgs: | ||
|