add environment-specific cilium profiles
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Successful in 1m3s

This commit is contained in:
2026-08-16 20:04:14 -04:00
parent 1a372b7eac
commit 6c79340d9a
14 changed files with 188 additions and 56 deletions
+10 -3
View File
@@ -36,6 +36,13 @@ The initial admin secret is for local bootstrap only. A later hardening phase
should replace this with SSO/RBAC and remove the bootstrap credential.
For a kube-proxy-free Cilium cluster, install Cilium before ArgoCD using the
profile in `local-quickstart/cilium.md` or the Flatcar cloud bootstrap. The
Cilium Application is stored under `deployments/argocd/optional-apps/` and is not watched
by the default root app until the cluster is ready for it.
profile in `local-quickstart/cilium.md` or the Flatcar bootstrap. The Cilium
Applications are stored under `deployments/argocd/optional-apps/` and are not
watched by the default root app until the cluster is ready for them.
Select `cilium-k3d.yaml` for the nested k3d profile or
`cilium-flatcar-k3s.yaml` for dedicated Flatcar K3s VMs. The profile values are
composed from `deployments/cilium/values/common.yaml` and the matching profile
overlay. Ansible owns the initial install when kube-proxy is disabled. ArgoCD
can own subsequent upgrades after bootstrap, but Ansible and ArgoCD should not
manage the same release with different values at the same time.