Erikson Tung

Results 25 issues of Erikson Tung

We should update dependencies under packages prior to our next minor version update. The previous time we did this for v1.9.0: https://github.com/bottlerocket-os/bottlerocket/pull/2309, there were a few packages we didn't have...

type/enhancement
priority/p1
dependencies

glibc 2.36 is available: https://sourceware.org/pipermail/libc-alpha/2022-August/141193.html We're also bumping glibc to 2.36 as part of the bottlerocket-sdk update: https://github.com/bottlerocket-os/bottlerocket-sdk/pull/82

type/enhancement
priority/p0
core

`bottlerocket-sdk` is moving to `binutils` v2.38 in https://github.com/bottlerocket-os/bottlerocket-sdk/pull/82. We should match that version when the new SDK comes out.

type/enhancement
priority/p0
core
dependencies

This would include dependencies for packages like host-ctr and hotdog. A previous example of this is https://github.com/bottlerocket-os/bottlerocket/pull/2299

type/enhancement
priority/p0
core
dependencies

https://github.com/systemd/systemd/blob/main/NEWS Try updating systemd to either 251/252. 251.4 is latest stable version https://github.com/systemd/systemd-stable/releases/tag/v251.4

priority/p1
core
dependencies

Kubernetes 1.24 was released in May 2022: https://kubernetes.io/blog/2022/05/03/kubernetes-1-24-release-announcement/ [CHANGELOG since 1.23.0](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.24.md#changelog-since-v1230) - [ ] aws-k8s variant - [ ] vmware-k8s variant - [ ] metal-k8s - [ ] aws-k8s nvidia...

type/enhancement
eks
priority/p0

**What I'd like:** When launching special bottlerocket variants that depends on special hardware, it's hard to debug if the host fail to boot properly. It would be nice to have...

type/enhancement
priority/p1

**What I'd like:** `pluto` to not block settings generation for 30 minutes when retrying requests to the EKS API when retrieving the cluster's network configuration. Currently, a Bottlerocket host running...

type/enhancement
eks
priority/p1
rust
good first issue

### What is the problem you're trying to solve I would like a way to disable masked paths and read-only paths for `/proc` without needing to specify `--privileged`. ### Describe...

kind/feature

We should evaluate disabling some default SSH cipher suites and key algorithms that might trigger vulnerability scanning tools

enhancement