Skip to content

Commit 0b5c5bd

Browse files
authored
webhook server use TLS 1.2 as minimum version (#2394)
1 parent f25c48f commit 0b5c5bd

File tree

2 files changed

+4
-3
lines changed

2 files changed

+4
-3
lines changed

main.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ func main() {
9191
setupLog.Error(err, "unable to start manager")
9292
os.Exit(1)
9393
}
94-
config.ConfigureWebhookServerCert(controllerCFG.RuntimeConfig, mgr)
94+
config.ConfigureWebhookServer(controllerCFG.RuntimeConfig, mgr)
9595
clientSet, err := kubernetes.NewForConfig(mgr.GetConfig())
9696
if err != nil {
9797
setupLog.Error(err, "unable to obtain clientSet")

pkg/config/runtime_config.go

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -124,8 +124,9 @@ func BuildRuntimeOptions(rtCfg RuntimeConfig, scheme *runtime.Scheme) ctrl.Optio
124124
}
125125
}
126126

127-
// ConfigureWebhookServerCert set up the server cert for the webhook server.
128-
func ConfigureWebhookServerCert(rtCfg RuntimeConfig, mgr ctrl.Manager) {
127+
// ConfigureWebhookServer set up the server cert for the webhook server.
128+
func ConfigureWebhookServer(rtCfg RuntimeConfig, mgr ctrl.Manager) {
129129
mgr.GetWebhookServer().CertName = rtCfg.WebhookCertName
130130
mgr.GetWebhookServer().KeyName = rtCfg.WebhookKeyName
131+
mgr.GetWebhookServer().TLSMinVersion = "1.2"
131132
}

0 commit comments

Comments
 (0)