Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Inspec.yml #66

Merged
merged 1 commit into from
May 9, 2020
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 21 additions & 21 deletions inspec.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,100 +11,100 @@ attributes:
- name: container_user
required: false
description: 'define user within containers.'
default: 'ubuntu'
value: 'ubuntu'
type: string
- name: container_capadd
required: true
description: 'define needed capabilities for containers.'
type: string
default: NET_ADMIN,SYS_ADMIN
value: NET_ADMIN,SYS_ADMIN
- name: app_armor_profile
required: false
description: 'define apparmor profile for Docker containers.'
default: 'docker-default'
value: 'docker-default'
type: string
- name: selinux_profile
required: false
description: 'define SELinux profile for Docker containers.'
default: label:level:s0-s0:c1023
value: label:level:s0-s0:c1023
type: string
- name: trusted_user
required: false
description: 'define trusted user to control Docker daemon.'
default: vagrant
value: vagrant
type: string
- name: managable_container_number
required: true
description: 'keep number of containers on a host to a manageable total.'
default: 25
value: 25
type: numeric
- name: benchmark_version
required: true
description: 'to execute also the old controls from previous benchmarks. to execute the controls, define the value as 1.12.0'
type: string
default: 1.12.0
value: 1.12.0
- name: registry_cert_path
required: true
description: 'directory contains various Docker registry directories.'
default: '/etc/docker/certs.d'
value: '/etc/docker/certs.d'
type: string
- name: registry_name
required: true
description: 'directory contain certificate certain Docker registry.'
default: '/etc/docker/certs.d/registry_hostname:port'
value: '/etc/docker/certs.d/registry_hostname:port'
type: string
- name: registry_ca_file
required: false
description: 'directory contain certificate certain Docker registry.'
default: '/etc/docker/certs.d/registry_hostname:port/ca.crt'
value: '/etc/docker/certs.d/registry_hostname:port/ca.crt'
type: string
- name: daemon_tlscacert
required: false
description: 'Trust certs signed only by this CA'
default: '/etc/docker/ssl/ca.pem'
value: '/etc/docker/ssl/ca.pem'
type: string
- name: daemon_tlscert
required: false
description: 'Path to TLS certificate file'
default: '/etc/docker/ssl/server_cert.pem'
value: '/etc/docker/ssl/server_cert.pem'
type: string
- name: daemon_tlskey
required: false
description: 'Path to TLS key file'
default: '/etc/docker/ssl/server_key.pem'
value: '/etc/docker/ssl/server_key.pem'
type: string
- name: authorization_plugin
required: false
description: 'define authorization plugin to manage access to Docker daemon.'
default: 'authz-broker'
value: 'authz-broker'
type: string
- name: log_driver
required: false
description: 'define preferable way to store logs.'
default: 'syslog'
value: 'syslog'
type: string
- name: log_opts
required: false
description: 'define Docker daemon log-opts.'
default: syslog-address
value: syslog-address
type: string
- name: swarm_mode
required: false
description: 'define the swarm mode, `active` or `inactive`'
default: inactive
value: inactive
type: string
- name: swarm_max_manager_nodes
required: false
description: 'number of manager nodes in a swarm'
default: 3
value: 3
type: numeric
- name: swarm_port
required: false
description: 'port of the swarm node'
default: 2377
value: 2377
type: numeric
- name: seccomp_default_profile
required: false
description: 'define the default seccomp profile'
default: 'default'
type: string
value: 'default'
type: string