organize deployment configuration
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Successful in 1m6s

This commit is contained in:
2026-08-15 13:17:46 -04:00
parent 12f3276465
commit fc53e16dd4
18 changed files with 26 additions and 13 deletions
+16
View File
@@ -5,6 +5,22 @@ fast reproducible demo, optional Flatcar plus Terraform and Ansible for a cloud
K3s host, Cilium eBPF networking, CIS Benchmark checks in CI, Kyverno
admission policies, and Falco runtime detection.
## Repository layout
Deployment and GitOps configuration is grouped under `deployments/`:
```text
deployments/
├── argocd/ # app-of-apps and child Application definitions
├── cilium/ # Cilium Helm values for the optional kube-proxy-free path
└── falco/ # Falco Operator values and custom resource definitions
```
The platform payloads remain separate from their deployment definitions. Kyverno
policies live under `policies/`, runtime demonstration workloads live under
`test-workloads/`, and cluster provisioning code remains under `terraform/`,
`ansible/`, and `local-quickstart/`.
## Phase 1: provision a local cluster
The primary quick-start path requires Docker, k3d, and kubectl:
@@ -2,7 +2,7 @@
ArgoCD is installed once into the local cluster; everything after that is
declared through the root Application. The root uses the app-of-apps pattern:
it watches `argocd/apps/`, and each child Application owns one platform or
it watches `deployments/argocd/apps/`, and each child Application owns one platform or
workload boundary.
## Bootstrap
@@ -16,7 +16,7 @@ workload boundary.
kubectl create namespace argocd --dry-run=client -o yaml | kubectl apply -f -
kubectl apply --server-side --force-conflicts -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
kubectl -n argocd rollout status deployment/argocd-server --timeout=180s
kubectl apply -f argocd/app-of-apps.yaml
kubectl apply -f deployments/argocd/app-of-apps.yaml
kubectl get applications -n argocd -w
```
@@ -37,5 +37,5 @@ should replace this with SSO/RBAC and remove the bootstrap credential.
For a kube-proxy-free Cilium cluster, install Cilium before ArgoCD using the
profile in `local-quickstart/cilium.md` or the Flatcar cloud bootstrap. The
Cilium Application is stored under `argocd/optional-apps/` and is not watched
Cilium Application is stored under `deployments/argocd/optional-apps/` and is not watched
by the default root app until the cluster is ready for it.
@@ -11,7 +11,7 @@ spec:
# Replace the owner after publishing this repository.
repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
targetRevision: main
path: argocd/apps
path: deployments/argocd/apps
destination:
server: https://kubernetes.default.svc
namespace: argocd
@@ -14,13 +14,13 @@ spec:
targetRevision: 0.3.1
helm:
valueFiles:
- $values/falco/falco-operator-values.yaml
- $values/deployments/falco/falco-operator-values.yaml
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
targetRevision: main
ref: values
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
targetRevision: main
path: falco/operator-resources
path: deployments/falco/operator-resources
destination:
server: https://kubernetes.default.svc
namespace: falco-operator
@@ -10,8 +10,6 @@ spec:
source:
repoURL: https://kyverno.github.io/kyverno/
chart: kyverno
# Chart 3.8.2 removes the deprecated bitnami/kubectl hook image used by
# the older chart and deploys Kyverno app version 1.18.2.
targetRevision: 3.8.2
helm:
values: |
@@ -13,7 +13,7 @@ spec:
targetRevision: 1.20.0
helm:
valueFiles:
- $values/cilium/cilium-values.yaml
- $values/deployments/cilium/cilium-values.yaml
- repoURL: https://git.swaphb.com/swaphb/kubernetes-security-baseline-lab.git
targetRevision: main
ref: values
@@ -22,4 +22,3 @@ spec:
namespace: kube-system
# Apply this Application manually only after bootstrapping a kube-proxy-free
# cluster and replacing the API endpoint placeholder.
@@ -1,5 +1,5 @@
# Falco Operator settings. Falco instances and their artifacts are managed by
# the CRs under falco/operator-resources.
# the CRs under deployments/falco/operator-resources.
replicaCount: 1
# Keep ArgoCD tracking labels on the operator itself, not on resources created
+2 -2
View File
@@ -16,7 +16,7 @@ Kubernetes service VIP because kube-proxy is disabled during bootstrap.
```bash
kubectl config current-context
kubectl get nodes -o wide
cp cilium/cilium-values.yaml /tmp/cilium-values.yaml
cp deployments/cilium/cilium-values.yaml /tmp/cilium-values.yaml
# Replace REPLACE_WITH_API_SERVER_DNS_OR_PRIVATE_IP with the reachable API endpoint.
helm repo add cilium https://helm.cilium.io/
helm repo update
@@ -29,7 +29,7 @@ kubectl -n kube-system get pods -l k8s-app=cilium
```
Install ArgoCD only after Cilium is Ready. Apply
`argocd/optional-apps/cilium.yaml` manually after the endpoint is configured;
`deployments/argocd/optional-apps/cilium.yaml` manually after the endpoint is configured;
it is intentionally outside the root app-of-apps watched directory until the
cluster has been bootstrapped without kube-proxy.