Skip to content

Instantly share code, notes, and snippets.

View igorGevaerd's full-sized avatar
:octocat:

Igor Gevaerd igorGevaerd

:octocat:
  • Clevertech
  • Brazil
View GitHub Profile
@igorGevaerd
igorGevaerd / debian_9_hardening.md
Last active January 7, 2020 14:30
Process used to keep Debian 9 more secure

Debian 9 Hardening

TL;DR: Some security improvements that was necessary for using Debian inside a kubernetes cluster, under more restrict secure rules

The image used follows what was stated on kops documentation , which in this case is:

kope.io/k8s-1.14-debian-stretch-amd64-hvm-ebs-2019-08-16

Hardening phases:

  1. Update Docker to be protected against the CVE-2019-5736:
  • Let the package repository up to date: