[eks] [request]: Document Kubernetes CVEs and when they were fixed
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Community Note
* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
I'd like to see all Kubernetes CVEs for EKS supported versions documented with the relevant platform version required to mitigate them. This would require the platform version table to be given a release date as this is currently missing.
Based on the following quote from the version support FAQ I'd like confirmation that CVEs are actually being mitigated by backports (I can't see a commit in the EKS Distro for mitigating CVE-2021-25741 in v1.18).
>A: A Kubernetes version is fully supported for 14 months after first being available on Amazon EKS. This is true even if upstream Kubernetes is no longer supporting a version available on Amazon EKS. We backport security patches that are applicable to the Kubernetes versions supported on Amazon EKS.
**Which service(s) is this request for?**
EKS
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
EKS supports Kubernetes versions for 14 months after they are added to EKS. Even if the EKS release happens at the same time as the official release this means AWS supporting Kubernetes versions for an additional 2 months, this could realistically be 8 months or more in some cases (K8s v1.19). During this extended period Kubernetes will not patch these versions so it's up to AWS to do so, and as a cluster operator I need to know that this has happened and when.
**Are you currently working around this issue?**
n/a
**Additional context**
There are other official projects such as _Cluster Autoscaler_, _Kube State Metrics_, etc which use the Kubernetes API and will not be patched with support for deprecated Kubernetes versions. These also need to be managed by AWs and the EKS team to actually "support" deprecated Kubernetes versions.
**Attachments**
n/a
Contributor guide
Research direction
Start with the requested EKS supported-version table and the cited version-support FAQ; identify the CVE records, mitigation platform versions, and release dates that would need documentation. Done means the supported versions have documented CVEs, required mitigation versions, and release dates, with the backport question addressed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes
- Domain
- cloud, documentation
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100