Skip to content

Instantly share code, notes, and snippets.

View ihcsim's full-sized avatar

Ivan Sim ihcsim

  • SUSE
  • BC, Canada
  • 21:01 (UTC -07:00)
View GitHub Profile
@ihcsim
ihcsim / gomod-vex-report.txt
Created August 3, 2026 04:44
gomod-vex image report for docker.io/rancher/klipper-helm:v0.11.1-build20260615,docker.io/rancher/klipper-lb:v0.4.17,docker.io/rancher/local-path-provisioner:v0.0.36,docker.io/rancher/mirrored-coredns-coredns:1.14.4,docker.io/rancher/mirrored-library-busybox:1.37.0,docker.io/rancher/mirrored-library-traefik:3.7.4,docker.io/rancher/mirrored-metri…
gomod-vex report (image) for docker.io/rancher/klipper-helm:v0.11.1-build20260615
module: golang.org/x/crypto
summary: 42 not_present, 0 not_in_execute_path, 0 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.47.0
cve: GO-2026-5005
binary: /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
@ihcsim
ihcsim / gomod-vex-report.json
Created August 3, 2026 04:34
gomod-vex image report for docker.io/rancher/rke2-runtime:v1.36.3-rc5-rke2r1,docker.io/rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723,docker.io/rancher/hardened-coredns:v1.14.6-build20260722,docker.io/rancher/hardened-cluster-autoscaler:v1.10.3-build20260717,docker.io/rancher/hardened-dns-node-cache:1.26.8-build20260722,docker.io/ranch…
[
{
"target": "docker.io/rancher/rke2-runtime:v1.36.3-rc5-rke2r1",
"mode": "image",
"module": "golang.org/x/crypto",
"findings": [
{
"binary": "/bin/containerd",
"module": "golang.org/x/crypto",
"version": "v0.53.0",
@ihcsim
ihcsim / gomod-vex-report.txt
Created August 3, 2026 04:28
gomod-vex image report for docker.io/rancher/rke2-runtime:v1.36.3-rc5-rke2r1,docker.io/rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723,docker.io/rancher/hardened-coredns:v1.14.6-build20260722,docker.io/rancher/hardened-cluster-autoscaler:v1.10.3-build20260717,docker.io/rancher/hardened-dns-node-cache:1.26.8-build20260722,docker.io/ranch…
gomod-vex report (image) for docker.io/rancher/rke2-runtime:v1.36.3-rc5-rke2r1
module: golang.org/x/crypto
summary: 1 not_present, 0 not_in_execute_path, 1 linked, 0 reachable, 0 undetermined
[LINKED] golang.org/x/crypto@v0.53.0
cve: GO-2026-5932
binary: /bin/containerd (stripped)
packages: golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package)
@ihcsim
ihcsim / gomod-vex-report.json
Created August 3, 2026 04:13
gomod-vex image report for rancher/rancher:latest,rancher/rancher:head (module golang.org/x/crypto)
[
{
"target": "rancher/rancher:latest",
"mode": "image",
"module": "golang.org/x/crypto",
"findings": [
{
"binary": "/opt/drivers/management-state/bin/docker-machine-driver-harvester",
"module": "golang.org/x/crypto",
"version": "v0.40.0",
@ihcsim
ihcsim / gomod-vex-report.txt
Created August 3, 2026 04:06
gomod-vex image report for rancher/rancher:latest,rancher/rancher:head (module golang.org/x/crypto)
gomod-vex report (image) for rancher/rancher:latest
module: golang.org/x/crypto
summary: 87 not_present, 0 not_in_execute_path, 31 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.40.0
cve: GO-2025-4116
binary: /opt/drivers/management-state/bin/docker-machine-driver-harvester (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
@ihcsim
ihcsim / gomod-vex-report.txt
Created August 3, 2026 03:42
gomod-vex image report for rancher/rancher:head (module golang.org/x/crypto)
gomod-vex report (image) for rancher/rancher:head
module: golang.org/x/crypto
summary: 77 not_present, 0 not_in_execute_path, 12 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.40.0
cve: GO-2025-4116
binary: /opt/drivers/management-state/bin/docker-machine-driver-harvester (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
@ihcsim
ihcsim / gomod-vex-report.txt
Created August 3, 2026 03:39
gomod-vex image report for rancher/rancher:latest (module golang.org/x/crypto)
gomod-vex report (image) for rancher/rancher:latest
module: golang.org/x/crypto
summary: 87 not_present, 0 not_in_execute_path, 31 linked, 0 reachable, 0 undetermined
[NOT PRESENT] golang.org/x/crypto@v0.40.0
cve: GO-2025-4116
binary: /opt/drivers/management-state/bin/docker-machine-driver-harvester (stripped)
packages: golang.org/x/crypto/ssh/agent (package)
vex: vulnerable_code_not_present [pclntab]
@ihcsim
ihcsim / config.toml
Last active April 8, 2026 22:14
version = 2
disabled_plugins = ["io.containerd.grpc.v1.cri"]
root = "/var/lib/firecracker-containerd/containerd"
state = "/run/firecracker-containerd"
[grpc]
address = "/run/firecracker-containerd/containerd.sock"
[plugins]
[plugins."io.containerd.snapshotter.v1.devmapper"]
pool_name = "fc-dev-thinpool"
base_image_size = "10GB"

To view etcd logs using crictl:

$ sudo /var/lib/rancher/rke2/bin/crictl --runtime-endpoint /run/k3s/containerd/containerd.sock ps -a | grep -i etcd
bf290fb65f79c       405516f27f18a       3 minutes ago       Running             etcd                                  8                   e720a5d2a0f71       etcd-isim-dev                                           kube-system

$ sudo /var/lib/rancher/rke2/bin/crictl --runtime-endpoint /run/k3s/containerd/containerd.sock logs bf290fb65f79c

RKE2 kubelet logs located at /var/lib/rancher/rke2/agent/logs/kubelet.log.

@ihcsim
ihcsim / add_cluster_network.md
Last active July 18, 2025 21:02
Add cluster network to Harvester

To create a new cluster network using the Harvester UI, navigate to Networks > Cluster Network Configuration.

Use the Create a Cluster Network option to create the new cluster network. E.g., name it cluznet.

Once the network is created, configure its uplink NIC via the Create Network Configuration option.

To configure the uplink link, a new NIC device must be made available to the Harvester host by performing the following steps using the Linux VMM:

  • create a new virtual network
  • use the new virtual network as the source of the NIC