kubernetes1.24

Edit Package kubernetes1.24
No description set
Refresh
Refresh
Source Files
Filename Size Changed
10-kubeadm.conf 0000001310 1.28 KB
90-kubeadm.conf 0000000168 168 Bytes
_constraints 0000000438 438 Bytes
_service 0000000711 711 Bytes
_servicedata 0000000242 242 Bytes
autoscaling-advance-v2-as-the-preferred-API-version.patch 0000004564 4.46 KB
bump-golang-org-grpc-to-v1_56_3.patch 0001739922 1.66 MB
bump-golang-protobuf-to-v1_5_4.patch 0000979213 956 KB
bump-x-net-to-v0_23_0.patch 0001035067 1010 KB
bypass-mountable-secrets-policy-imposed-by-SA-admission-plugin.patch 0000010418 10.2 KB
escape-terminal-special-characters-in-kubectl-112553.patch 0000008682 8.48 KB
expose-DisableHTTP2-flag-in-SecureServingOptions.patch 0000002840 2.77 KB
genmanpages.sh 0000003172 3.1 KB
kubeadm-opensuse-flexvolume.patch 0000000603 603 Bytes
kubeadm-opensuse-registry.patch 0000001490 1.46 KB
kubeadm.conf 0000000056 56 Bytes
kubelet.service 0000000466 466 Bytes
kubelet.sh 0000000292 292 Bytes
kubelet.tmp.conf 0000000068 68 Bytes
kubernetes-1.24.17.tar.xz 0022574124 21.5 MB
kubernetes-rpmlintrc 0000000262 262 Bytes
kubernetes-trimpath.patch 0000003504 3.42 KB
kubernetes.obsinfo 0000000101 101 Bytes
kubernetes1.24.changes 0000026271 25.7 KB
kubernetes1.24.spec 0000018359 17.9 KB
opensuse-version-checks.patch 0000000952 952 Bytes
prevent-rapid-reset-http2-DOS-on-API-server.patch 0000016872 16.5 KB
revert-coredns-image-renaming.patch 0000001373 1.34 KB
sysconfig.kubelet-kubernetes 0000000025 25 Bytes
Latest Revision
Priyanka Saggu's avatar Priyanka Saggu (psaggu) accepted request 1200790 from Priyanka Saggu's avatar Priyanka Saggu (psaggu) (revision 36)
- Security fix for bsc#1229869
  * New Patches: 
    - prevent-rapid-reset-http2-DOS-on-API-server.patch,
    - bump-golang-org-grpc-to-v1_56_3.patch,
    - expose-DisableHTTP2-flag-in-SecureServingOptions.patch
    * Mitigates http/2 DOS vulnerabilities for CVE-2023-44487 and CVE-2023-39325 for the API server when the client is unauthenticated. The mitigation may be disabled by setting the `UnauthenticatedHTTP2DOSMitigation` feature gate to `false` (it is enabled by default). An API server fronted by an L7 load balancer that already mitigates these http/2 attacks may choose to disable the kube-apiserver mitigation to avoid disrupting load balancer → kube-apiserver connections if http/2 requests from multiple clients share the same backend connection. An API server on a private network may opt to disable the kube-apiserver mitigation to prevent performance regressions for unauthenticated clients. Authenticated requests rely on the fix in golang.org/x/net v0.17.0 alone. https://issue.k8s.io/121197 tracks further mitigation of http/2 attacks by authenticated clients. 
Comments 0
openSUSE Build Service is sponsored by