add environment-specific cilium profiles
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Successful in 1m3s

This commit is contained in:
2026-08-16 20:04:14 -04:00
parent 1a372b7eac
commit 6c79340d9a
14 changed files with 188 additions and 56 deletions
@@ -0,0 +1,26 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: cilium-flatcar-k3s
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "-4"
spec:
project: default
sources:
- repoURL: https://helm.cilium.io/
chart: cilium
targetRevision: 1.20.0
helm:
valueFiles:
- $values/deployments/cilium/values/common.yaml
- $values/deployments/cilium/values/profiles/flatcar-k3s.yaml
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
targetRevision: main
ref: values
destination:
server: https://kubernetes.default.svc
namespace: kube-system
# Replace the control-plane endpoint in the profile before applying.
# Keep this Application outside the default root app-of-apps until the
# kube-proxy-free bootstrap is complete.
@@ -1,7 +1,7 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: cilium
name: cilium-k3d
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "-4"
@@ -13,12 +13,13 @@ spec:
targetRevision: 1.20.0
helm:
valueFiles:
- $values/deployments/cilium/cilium-values.yaml
- $values/deployments/cilium/values/common.yaml
- $values/deployments/cilium/values/profiles/k3d.yaml
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
targetRevision: main
ref: values
destination:
server: https://kubernetes.default.svc
namespace: kube-system
# Apply this Application manually only after bootstrapping a kube-proxy-free
# cluster and replacing the API endpoint placeholder.
# Apply only after Ansible bootstraps Cilium and confirms the endpoint values.
# This Application is intentionally outside the default root app-of-apps.