update kubeflow dip-catalog
This commit is contained in:
+9
@@ -0,0 +1,9 @@
|
||||
# Enforce an explicit deny-by-default authorization model, similar to
|
||||
# the deprecated Istio RBAC
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: global-deny-all
|
||||
namespace: istio-system
|
||||
spec:
|
||||
{}
|
||||
@@ -0,0 +1,17 @@
|
||||
apiVersion: networking.istio.io/v1alpha3
|
||||
kind: Gateway
|
||||
metadata:
|
||||
name: istio-ingressgateway
|
||||
labels:
|
||||
release: istio
|
||||
spec:
|
||||
selector:
|
||||
app: istio-ingressgateway
|
||||
istio: ingressgateway
|
||||
servers:
|
||||
- port:
|
||||
number: 80
|
||||
name: http
|
||||
protocol: HTTP
|
||||
hosts:
|
||||
- '*'
|
||||
+15
@@ -0,0 +1,15 @@
|
||||
# Allow all traffic to the istio-ingressgateway
|
||||
apiVersion: security.istio.io/v1beta1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: istio-ingressgateway
|
||||
namespace: istio-system
|
||||
spec:
|
||||
action: ALLOW
|
||||
selector:
|
||||
# Same as the istio-ingressgateway Service selector
|
||||
matchLabels:
|
||||
app: istio-ingressgateway
|
||||
istio: ingressgateway
|
||||
rules:
|
||||
- {}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,16 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- install.yaml
|
||||
- gateway_authorizationpolicy.yaml
|
||||
- deny_all_authorizationpolicy.yaml
|
||||
- gateway.yaml
|
||||
- x-forwarded-host.yaml
|
||||
|
||||
patches:
|
||||
- path: patches/service.yaml
|
||||
- path: patches/istio-configmap-disable-tracing.yaml
|
||||
- path: patches/disable-debugging.yaml
|
||||
- path: patches/istio-ingressgateway-remove-pdb.yaml
|
||||
- path: patches/istiod-remove-pdb.yaml
|
||||
+18
@@ -0,0 +1,18 @@
|
||||
# Penetration test enahncement: check port 15010 & 8080 in istiod: According to https://istio.io/latest/docs/ops/best-practices/security/#control-plane port 15010
|
||||
# is not that problematic (only resource discovery). Other parts of the documentation also say| 15010 | GRPC | XDS and CA services (Plaintext, only for secure networks) |
|
||||
# We have a secure network layer and only XDS is served.
|
||||
# Port 8080 is not listed in the service and even if it would be somehow reachable by IP it only "offers read access".
|
||||
# Nevertheless we set ENABLE_DEBUG_ON_HTTP=false do disable it entirely.
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: istiod
|
||||
namespace: istio-system
|
||||
spec:
|
||||
template:
|
||||
spec:
|
||||
containers:
|
||||
- name: discovery
|
||||
env:
|
||||
- name: ENABLE_DEBUG_ON_HTTP
|
||||
value: 'false'
|
||||
+20
@@ -0,0 +1,20 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: istio
|
||||
namespace: istio-system
|
||||
data:
|
||||
# Configuration file for the mesh networks to be used by the Split Horizon EDS.
|
||||
mesh: |-
|
||||
accessLogFile: /dev/stdout
|
||||
defaultConfig:
|
||||
discoveryAddress: istiod.istio-system.svc:15012
|
||||
proxyMetadata: {}
|
||||
tracing: {}
|
||||
enablePrometheusMerge: true
|
||||
rootNamespace: istio-system
|
||||
tcpKeepalive:
|
||||
interval: 5s
|
||||
probes: 3
|
||||
time: 10s
|
||||
trustDomain: cluster.local
|
||||
+6
@@ -0,0 +1,6 @@
|
||||
$patch: delete
|
||||
apiVersion: policy/v1
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
name: istio-ingressgateway
|
||||
namespace: istio-system
|
||||
+6
@@ -0,0 +1,6 @@
|
||||
$patch: delete
|
||||
apiVersion: policy/v1
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
name: istiod
|
||||
namespace: istio-system
|
||||
@@ -0,0 +1,7 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: istio-ingressgateway
|
||||
namespace: istio-system
|
||||
spec:
|
||||
type: ClusterIP
|
||||
@@ -0,0 +1,42 @@
|
||||
# EnvoyFilter for adding the X-Forwarded-Host header.
|
||||
# Needed for the Rok GW to work correctly.
|
||||
# Older manifests used an Istio rule, but that relies on Mixer which
|
||||
# is deprecated. This way is more performant and up-to-date.
|
||||
#
|
||||
# TODO: X-Forwarded-Host needs to be applied in two steps:
|
||||
# 1. Put old host in `X-Forwarded-Host`
|
||||
# 2. Update Host in request
|
||||
#
|
||||
# This filter only does (1). It can't do (2) because it doesn't know the new
|
||||
# host yet. See if we can add an EnvoyFilter for (2). We currently have to do
|
||||
# this per VirtualService, in each app that needs it.
|
||||
apiVersion: networking.istio.io/v1alpha3
|
||||
kind: EnvoyFilter
|
||||
metadata:
|
||||
name: x-forwarded-host
|
||||
spec:
|
||||
workloadSelector:
|
||||
labels:
|
||||
istio: ingressgateway
|
||||
configPatches:
|
||||
# The first patch adds the lua filter to the listener/http connection manager
|
||||
- applyTo: HTTP_FILTER
|
||||
match:
|
||||
context: GATEWAY
|
||||
listener:
|
||||
filterChain:
|
||||
filter:
|
||||
name: "envoy.http_connection_manager"
|
||||
subFilter:
|
||||
name: "envoy.router"
|
||||
patch:
|
||||
operation: INSERT_BEFORE
|
||||
value:
|
||||
name: envoy.filters.http.lua
|
||||
typed_config:
|
||||
"@type": "type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua"
|
||||
inlineCode: |
|
||||
function envoy_on_request(request_handle)
|
||||
local host = request_handle:headers():get(":authority")
|
||||
request_handle:headers():add("x-forwarded-host", host)
|
||||
end
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- ../../base
|
||||
|
||||
components:
|
||||
- ../../../../oidc-client/oauth2-proxy/components/istio-external-auth-patches
|
||||
Reference in New Issue
Block a user