add environment-specific cilium profiles
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Successful in 1m3s
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Successful in 1m3s
This commit is contained in:
@@ -36,6 +36,13 @@ The initial admin secret is for local bootstrap only. A later hardening phase
|
||||
should replace this with SSO/RBAC and remove the bootstrap credential.
|
||||
|
||||
For a kube-proxy-free Cilium cluster, install Cilium before ArgoCD using the
|
||||
profile in `local-quickstart/cilium.md` or the Flatcar cloud bootstrap. The
|
||||
Cilium Application is stored under `deployments/argocd/optional-apps/` and is not watched
|
||||
by the default root app until the cluster is ready for it.
|
||||
profile in `local-quickstart/cilium.md` or the Flatcar bootstrap. The Cilium
|
||||
Applications are stored under `deployments/argocd/optional-apps/` and are not
|
||||
watched by the default root app until the cluster is ready for them.
|
||||
|
||||
Select `cilium-k3d.yaml` for the nested k3d profile or
|
||||
`cilium-flatcar-k3s.yaml` for dedicated Flatcar K3s VMs. The profile values are
|
||||
composed from `deployments/cilium/values/common.yaml` and the matching profile
|
||||
overlay. Ansible owns the initial install when kube-proxy is disabled. ArgoCD
|
||||
can own subsequent upgrades after bootstrap, but Ansible and ArgoCD should not
|
||||
manage the same release with different values at the same time.
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: cilium-flatcar-k3s
|
||||
namespace: argocd
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-4"
|
||||
spec:
|
||||
project: default
|
||||
sources:
|
||||
- repoURL: https://helm.cilium.io/
|
||||
chart: cilium
|
||||
targetRevision: 1.20.0
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/deployments/cilium/values/common.yaml
|
||||
- $values/deployments/cilium/values/profiles/flatcar-k3s.yaml
|
||||
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
|
||||
targetRevision: main
|
||||
ref: values
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: kube-system
|
||||
# Replace the control-plane endpoint in the profile before applying.
|
||||
# Keep this Application outside the default root app-of-apps until the
|
||||
# kube-proxy-free bootstrap is complete.
|
||||
+5
-4
@@ -1,7 +1,7 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: cilium
|
||||
name: cilium-k3d
|
||||
namespace: argocd
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-4"
|
||||
@@ -13,12 +13,13 @@ spec:
|
||||
targetRevision: 1.20.0
|
||||
helm:
|
||||
valueFiles:
|
||||
- $values/deployments/cilium/cilium-values.yaml
|
||||
- $values/deployments/cilium/values/common.yaml
|
||||
- $values/deployments/cilium/values/profiles/k3d.yaml
|
||||
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
|
||||
targetRevision: main
|
||||
ref: values
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: kube-system
|
||||
# Apply this Application manually only after bootstrapping a kube-proxy-free
|
||||
# cluster and replacing the API endpoint placeholder.
|
||||
# Apply only after Ansible bootstraps Cilium and confirms the endpoint values.
|
||||
# This Application is intentionally outside the default root app-of-apps.
|
||||
Reference in New Issue
Block a user