Skip to content

chore: change kubelets exec-start to 0600 #4574

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

tzneal
Copy link
Contributor

@tzneal tzneal commented Jun 26, 2025

Issue number:

Closes #

Description of changes:

Change kubelet's exec-start file to be 0600 to meet newer CIS K8s guidance.

Testing done:

Built and tested an AMI.

Terms of contribution:

By submitting this pull request, I agree that this contribution is dual-licensed under the terms of both the Apache License, version 2.0, and the MIT license.

Copy link
Contributor

@bcressey bcressey left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, but I'd like us to fix bottlerocket-os/bottlerocket-core-kit#574 at some point to clean up the systemd warning that this causes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants