update project progress documentation
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Successful in 1m3s
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Successful in 1m3s
This commit is contained in:
@@ -35,6 +35,10 @@ Traefik is disabled so later ArgoCD-managed components own add-ons explicitly.
|
|||||||
|
|
||||||
Delete the lab with `k3d cluster delete security-baseline`.
|
Delete the lab with `k3d cluster delete security-baseline`.
|
||||||
|
|
||||||
|
For repeatable CI and runtime testing, the repository also includes a Flatcar
|
||||||
|
Linux Proxmox host definition under `scripts/proxmox/`. The current test
|
||||||
|
environment runs k3d on a dedicated Flatcar VM with kernel access for Falco.
|
||||||
|
|
||||||
## Production-style option
|
## Production-style option
|
||||||
|
|
||||||
`terraform/cloud-cluster/` and `ansible/bootstrap-k3s.yml` provide an optional,
|
`terraform/cloud-cluster/` and `ansible/bootstrap-k3s.yml` provide an optional,
|
||||||
@@ -44,14 +48,44 @@ requires your own AWS credentials, an existing EC2 key pair, a Flatcar AMI ID
|
|||||||
for the chosen region, and a tightly scoped admin CIDR.
|
for the chosen region, and a tightly scoped admin CIDR.
|
||||||
It is not needed for the portfolio demo and is not run in CI.
|
It is not needed for the portfolio demo and is not run in CI.
|
||||||
|
|
||||||
|
The Proxmox scripts also create Flatcar-based hosts for a self-hosted Gitea
|
||||||
|
Actions runner and for the dedicated k3d test environment. They use Ignition
|
||||||
|
for first-boot configuration and do not contain account-specific credentials.
|
||||||
|
|
||||||
|
## GitOps and security validation
|
||||||
|
|
||||||
|
ArgoCD is bootstrapped once and then manages the platform applications through
|
||||||
|
the app-of-apps definition in `deployments/argocd/`. The managed components are
|
||||||
|
Kyverno, Falco, and the security demonstration workloads. Cilium values and an
|
||||||
|
optional Cilium Application are also stored under `deployments/` for the
|
||||||
|
kube-proxy-free profile.
|
||||||
|
|
||||||
|
The kube-bench workflow is retained in `.github/workflows/` for GitHub Actions
|
||||||
|
and uses a Gitea-compatible artifact action when run by Gitea Actions. It
|
||||||
|
creates an ephemeral k3d cluster, waits for the Kubernetes API, runs the K3s
|
||||||
|
benchmark, and uploads the report without failing the workflow solely because
|
||||||
|
the benchmark contains findings that require review.
|
||||||
|
|
||||||
|
Kyverno admission tests have verified that privileged containers, root
|
||||||
|
containers, host networking or host PID access, unapproved registries, and
|
||||||
|
application workloads in the `default` namespace are rejected. Falco runtime
|
||||||
|
testing has verified that the suspicious shell workload produces the custom
|
||||||
|
shell detection while the compliant workload does not.
|
||||||
|
|
||||||
## Build status
|
## Build status
|
||||||
|
|
||||||
- [x] Phase 1: local k3d definition and optional Terraform/Ansible path
|
- [x] Phase 1: local k3d definition and optional Terraform/Ansible path
|
||||||
- [ ] Phase 2: ArgoCD app-of-apps deployment (scaffolded; runtime verification pending)
|
- [x] Phase 2: ArgoCD app-of-apps deployment and remote Flatcar test environment
|
||||||
- [x] Phase 3: kube-bench CI scan
|
- [x] Phase 3: kube-bench CI scan
|
||||||
- [ ] Architecture revision: Flatcar hosts and Cilium kube-proxy replacement (configured; runtime verification pending)
|
- [x] Architecture revision: Flatcar hosts and Falco kernel access
|
||||||
- [ ] Phase 4: Kyverno policy set and CIS mapping (configured; runtime verification pending)
|
- [x] Phase 4: Kyverno policy set, CIS mapping, and admission tests
|
||||||
- [ ] Phase 5: Falco rules and webhook alerting
|
- [ ] Phase 5: Falco rules and webhook alerting (runtime detection verified; webhook pending)
|
||||||
- [ ] Phase 6: test workloads and evidence capture
|
- [x] Phase 6: test workloads and runtime verification
|
||||||
- [ ] Phase 7: architecture/design documentation
|
- [ ] Phase 7: architecture and design documentation (repository layout started)
|
||||||
- [ ] Phase 8: final portfolio polish
|
- [ ] Phase 8: final portfolio polish
|
||||||
|
|
||||||
|
## Remaining work
|
||||||
|
|
||||||
|
- Configure a Slack or Discord webhook through a Kubernetes Secret outside Git.
|
||||||
|
- Add the architecture diagram, CIS evidence summary, and demo capture.
|
||||||
|
- Finish the design trade-off documentation and final repository review.
|
||||||
|
|||||||
Reference in New Issue
Block a user