migrate falco deployment to operator
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s
This commit is contained in:
@@ -9,21 +9,25 @@ spec:
|
|||||||
project: default
|
project: default
|
||||||
sources:
|
sources:
|
||||||
- repoURL: https://falcosecurity.github.io/charts
|
- repoURL: https://falcosecurity.github.io/charts
|
||||||
chart: falco
|
chart: falco-operator
|
||||||
# Chart 9.1.0 deploys Falco app version 0.44.1.
|
# Operator chart 0.3.1 deploys Falco Operator 0.4.1.
|
||||||
targetRevision: 9.1.0
|
targetRevision: 0.3.1
|
||||||
helm:
|
helm:
|
||||||
valueFiles:
|
valueFiles:
|
||||||
- $values/falco/falco-values.yaml
|
- $values/falco/falco-operator-values.yaml
|
||||||
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
|
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
|
||||||
targetRevision: main
|
targetRevision: main
|
||||||
ref: values
|
ref: values
|
||||||
|
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
|
||||||
|
targetRevision: main
|
||||||
|
path: falco/operator-resources
|
||||||
destination:
|
destination:
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
namespace: falco
|
namespace: falco-operator
|
||||||
syncPolicy:
|
syncPolicy:
|
||||||
automated:
|
automated:
|
||||||
prune: true
|
prune: true
|
||||||
selfHeal: true
|
selfHeal: true
|
||||||
syncOptions:
|
syncOptions:
|
||||||
- CreateNamespace=true
|
- CreateNamespace=true
|
||||||
|
- ServerSideApply=true
|
||||||
|
|||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# Falco Operator settings. Falco instances and their artifacts are managed by
|
||||||
|
# the CRs under falco/operator-resources.
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
# Keep ArgoCD tracking labels on the operator itself, not on resources created
|
||||||
|
# by the operator from Falco, Config, Plugin, or Rulesfile resources.
|
||||||
|
excludedLabels:
|
||||||
|
- argocd.argoproj.io/instance
|
||||||
|
- argocd.argoproj.io/tracking-id
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 64Mi
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 128Mi
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
# Phase 2 placeholder values. Runtime rules and webhook output are added in
|
|
||||||
# phase 5; keeping values in Git now establishes the ArgoCD ownership boundary.
|
|
||||||
falco:
|
|
||||||
json_output: true
|
|
||||||
json_include_output_property: true
|
|
||||||
|
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
apiVersion: artifact.falcosecurity.dev/v1alpha1
|
||||||
|
kind: Config
|
||||||
|
metadata:
|
||||||
|
name: falco-output
|
||||||
|
namespace: falco
|
||||||
|
annotations:
|
||||||
|
argocd.argoproj.io/sync-wave: "1"
|
||||||
|
spec:
|
||||||
|
priority: 50
|
||||||
|
config:
|
||||||
|
json_output: true
|
||||||
|
json_include_output_property: true
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: instance.falcosecurity.dev/v1alpha1
|
||||||
|
kind: Falco
|
||||||
|
metadata:
|
||||||
|
name: falco
|
||||||
|
namespace: falco
|
||||||
|
annotations:
|
||||||
|
# Apply the instance after the Operator chart has installed its CRDs.
|
||||||
|
argocd.argoproj.io/sync-wave: "1"
|
||||||
|
spec: {}
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- falco-instance.yaml
|
||||||
|
- falco-config.yaml
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: falco
|
||||||
Reference in New Issue
Block a user