Change chart directory structure
This commit is contained in:
+9
@@ -0,0 +1,9 @@
|
||||
# Enforce an explicit deny-by-default authorization model, similar to
|
||||
# the deprecated Istio RBAC
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: global-deny-all
|
||||
namespace: istio-system
|
||||
spec:
|
||||
{}
|
||||
+17
@@ -0,0 +1,17 @@
|
||||
apiVersion: networking.istio.io/v1alpha3
|
||||
kind: Gateway
|
||||
metadata:
|
||||
name: istio-ingressgateway
|
||||
labels:
|
||||
release: istio
|
||||
spec:
|
||||
selector:
|
||||
app: istio-ingressgateway
|
||||
istio: ingressgateway
|
||||
servers:
|
||||
- port:
|
||||
number: 80
|
||||
name: http
|
||||
protocol: HTTP
|
||||
hosts:
|
||||
- '*'
|
||||
+15
@@ -0,0 +1,15 @@
|
||||
# Allow all traffic to the istio-ingressgateway
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: istio-ingressgateway
|
||||
namespace: istio-system
|
||||
spec:
|
||||
action: ALLOW
|
||||
selector:
|
||||
# Same as the istio-ingressgateway Service selector
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
istio: ingressgateway
|
||||
rules:
|
||||
- {}
|
||||
+3756
File diff suppressed because it is too large
Load Diff
+21
@@ -0,0 +1,21 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- install.yaml
|
||||
- gateway_authorizationpolicy.yaml
|
||||
- deny_all_authorizationpolicy.yaml
|
||||
- gateway.yaml
|
||||
|
||||
patches:
|
||||
- path: patches/service.yaml
|
||||
- path: patches/istio-configmap-disable-tracing.yaml
|
||||
- path: patches/disable-debugging.yaml
|
||||
- path: patches/istio-ingressgateway-remove-pdb.yaml
|
||||
- path: patches/istiod-remove-pdb.yaml
|
||||
- path: patches/seccomp-istio-ingressgateway.yaml
|
||||
- path: patches/seccomp-istiod.yaml
|
||||
|
||||
images:
|
||||
- name: busybox
|
||||
newName: registry.k8s.io/busybox
|
||||
+18
@@ -0,0 +1,18 @@
|
||||
# Penetration test enahncement: check port 15010 & 8080 in istiod: According to https://istio.io/latest/docs/ops/best-practices/security/#control-plane port 15010
|
||||
# is not that problematic (only resource discovery). Other parts of the documentation also say| 15010 | GRPC | XDS and CA services (Plaintext, only for secure networks) |
|
||||
# We have a secure network layer and only XDS is served.
|
||||
# Port 8080 is not listed in the service and even if it would be somehow reachable by IP it only "offers read access".
|
||||
# Nevertheless we set ENABLE_DEBUG_ON_HTTP=false do disable it entirely.
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: istiod
|
||||
namespace: istio-system
|
||||
spec:
|
||||
template:
|
||||
spec:
|
||||
containers:
|
||||
- name: discovery
|
||||
env:
|
||||
- name: ENABLE_DEBUG_ON_HTTP
|
||||
value: 'false'
|
||||
+20
@@ -0,0 +1,20 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: istio
|
||||
namespace: istio-system
|
||||
data:
|
||||
# Configuration file for the mesh networks to be used by the Split Horizon EDS.
|
||||
mesh: |-
|
||||
accessLogFile: /dev/stdout
|
||||
defaultConfig:
|
||||
discoveryAddress: istiod.istio-system.svc:15012
|
||||
proxyMetadata: {}
|
||||
tracing: {}
|
||||
enablePrometheusMerge: true
|
||||
rootNamespace: istio-system
|
||||
tcpKeepalive:
|
||||
interval: 5s
|
||||
probes: 3
|
||||
time: 10s
|
||||
trustDomain: cluster.local
|
||||
+6
@@ -0,0 +1,6 @@
|
||||
$patch: delete
|
||||
apiVersion: policy/v1
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
name: istio-ingressgateway
|
||||
namespace: istio-system
|
||||
+6
@@ -0,0 +1,6 @@
|
||||
$patch: delete
|
||||
apiVersion: policy/v1
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
name: istiod
|
||||
namespace: istio-system
|
||||
+16
@@ -0,0 +1,16 @@
|
||||
# Seccomp profile must be explicitly set to one of the allowed values. Both the Unconfined profile and the absence of a profile are prohibited.
|
||||
# According to https://kubernetes.io/docs/concepts/security/pod-security-standards/#:~:text=undefined/null-,Seccomp%20(v1.19%2B),-Seccomp%20profile%20must
|
||||
# This is done to enable 'restricted' level security standards for the pods.
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: istio-ingressgateway
|
||||
namespace: istio-system
|
||||
spec:
|
||||
template:
|
||||
spec:
|
||||
containers:
|
||||
- name: istio-proxy
|
||||
securityContext:
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
+16
@@ -0,0 +1,16 @@
|
||||
# Seccomp profile must be explicitly set to one of the allowed values. Both the Unconfined profile and the absence of a profile are prohibited.
|
||||
# According to https://kubernetes.io/docs/concepts/security/pod-security-standards/#:~:text=undefined/null-,Seccomp%20(v1.19%2B),-Seccomp%20profile%20must
|
||||
# This is done to enable 'restricted' level security standards for the pods.
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: istiod
|
||||
namespace: istio-system
|
||||
spec:
|
||||
template:
|
||||
spec:
|
||||
containers:
|
||||
- name: discovery
|
||||
securityContext:
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: istio-ingressgateway
|
||||
namespace: istio-system
|
||||
spec:
|
||||
type: ClusterIP
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- ../../base
|
||||
|
||||
components:
|
||||
- ../../../../oauth2-proxy/components/istio-external-auth-patches
|
||||
Reference in New Issue
Block a user