diff --git a/assets/index.yaml b/assets/index.yaml index 36c4ce24e..1e7e1e241 100644 --- a/assets/index.yaml +++ b/assets/index.yaml @@ -592,6 +592,27 @@ entries: - assets/rancher-backup/rancher-backup-crd-1.0.200.tgz version: 1.0.200 rancher-cis-benchmark: + - annotations: + catalog.cattle.io/auto-install: rancher-cis-benchmark-crd=match + catalog.cattle.io/certified: rancher + catalog.cattle.io/display-name: CIS Benchmark + catalog.cattle.io/namespace: cis-operator-system + catalog.cattle.io/provides-gvr: cis.cattle.io.clusterscans/v1 + catalog.cattle.io/release-name: rancher-cis-benchmark + catalog.cattle.io/ui-component: rancher-cis-benchmark + apiVersion: v1 + appVersion: v1.0.3 + created: "2020-12-02T17:32:52.357792398Z" + description: The cis-operator enables running CIS benchmark security scans on + a kubernetes cluster + digest: b4a3a389580d3a351ff06bf199794ce1de9cd19cfeb695c80a6b6fd8f0eafbee + icon: https://charts.rancher.io/assets/logos/cis-kube-bench.svg + keywords: + - security + name: rancher-cis-benchmark + urls: + - assets/rancher-cis-benchmark/rancher-cis-benchmark-1.0.300.tgz + version: 1.0.300 - annotations: catalog.cattle.io/auto-install: rancher-cis-benchmark-crd=match catalog.cattle.io/certified: rancher @@ -634,6 +655,20 @@ entries: - assets/rancher-cis-benchmark/rancher-cis-benchmark-1.0.100.tgz version: 1.0.100 rancher-cis-benchmark-crd: + - annotations: + catalog.cattle.io/certified: rancher + catalog.cattle.io/hidden: "true" + catalog.cattle.io/namespace: cis-operator-system + catalog.cattle.io/release-name: rancher-cis-benchmark-crd + apiVersion: v1 + created: "2020-12-02T17:32:52.358042101Z" + description: Installs the CRDs for rancher-cis-benchmark. + digest: bb3546b52282fbd22011e6e00aac1f499796101cb2611cc12db9acf7e4d0109b + name: rancher-cis-benchmark-crd + type: application + urls: + - assets/rancher-cis-benchmark/rancher-cis-benchmark-crd-1.0.300.tgz + version: 1.0.300 - annotations: catalog.cattle.io/certified: rancher catalog.cattle.io/hidden: "true" @@ -2008,4 +2043,4 @@ entries: urls: - assets/rio/rio-0.8.000.tgz version: 0.8.000 -generated: "2020-12-02T17:21:06.473670905Z" +generated: "2020-12-02T17:32:52.356910489Z" diff --git a/assets/rancher-cis-benchmark/rancher-cis-benchmark-1.0.300.tgz b/assets/rancher-cis-benchmark/rancher-cis-benchmark-1.0.300.tgz new file mode 100644 index 000000000..c1714e24f Binary files /dev/null and b/assets/rancher-cis-benchmark/rancher-cis-benchmark-1.0.300.tgz differ diff --git a/assets/rancher-cis-benchmark/rancher-cis-benchmark-crd-1.0.300.tgz b/assets/rancher-cis-benchmark/rancher-cis-benchmark-crd-1.0.300.tgz new file mode 100644 index 000000000..b379cf710 Binary files /dev/null and b/assets/rancher-cis-benchmark/rancher-cis-benchmark-crd-1.0.300.tgz differ diff --git a/charts/rancher-cis-benchmark/Chart.yaml b/charts/rancher-cis-benchmark/Chart.yaml index 99756e585..8041685f1 100644 --- a/charts/rancher-cis-benchmark/Chart.yaml +++ b/charts/rancher-cis-benchmark/Chart.yaml @@ -1,9 +1,9 @@ apiVersion: v1 -appVersion: v1.0.2 +appVersion: v1.0.3 description: The cis-operator enables running CIS benchmark security scans on a kubernetes cluster name: rancher-cis-benchmark -version: 1.0.200 +version: 1.0.300 icon: https://charts.rancher.io/assets/logos/cis-kube-bench.svg keywords: - security diff --git a/charts/rancher-cis-benchmark/charts-crd/Chart.yaml b/charts/rancher-cis-benchmark/charts-crd/Chart.yaml index 0107c0281..bf56c6b33 100644 --- a/charts/rancher-cis-benchmark/charts-crd/Chart.yaml +++ b/charts/rancher-cis-benchmark/charts-crd/Chart.yaml @@ -1,5 +1,5 @@ apiVersion: v1 -version: 1.0.200 +version: 1.0.300 description: Installs the CRDs for rancher-cis-benchmark. name: rancher-cis-benchmark-crd type: application diff --git a/charts/rancher-cis-benchmark/templates/benchmark-rke2-cis-1.5-hardened.yaml b/charts/rancher-cis-benchmark/templates/benchmark-rke2-cis-1.5-hardened.yaml new file mode 100644 index 000000000..3d83e9bd8 --- /dev/null +++ b/charts/rancher-cis-benchmark/templates/benchmark-rke2-cis-1.5-hardened.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: cis.cattle.io/v1 +kind: ClusterScanBenchmark +metadata: + name: rke2-cis-1.5-hardened +spec: + clusterProvider: rke2 + minKubernetesVersion: "1.18.0" diff --git a/charts/rancher-cis-benchmark/templates/benchmark-rke2-cis-1.5-permissive.yaml b/charts/rancher-cis-benchmark/templates/benchmark-rke2-cis-1.5-permissive.yaml new file mode 100644 index 000000000..f66aa8f6e --- /dev/null +++ b/charts/rancher-cis-benchmark/templates/benchmark-rke2-cis-1.5-permissive.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: cis.cattle.io/v1 +kind: ClusterScanBenchmark +metadata: + name: rke2-cis-1.5-permissive +spec: + clusterProvider: rke2 + minKubernetesVersion: "1.18.0" diff --git a/charts/rancher-cis-benchmark/templates/configmap.yaml b/charts/rancher-cis-benchmark/templates/configmap.yaml index 7f14b1396..f32ea1fa2 100644 --- a/charts/rancher-cis-benchmark/templates/configmap.yaml +++ b/charts/rancher-cis-benchmark/templates/configmap.yaml @@ -6,6 +6,7 @@ metadata: data: # Default ClusterScanProfiles per cluster provider type rke: "rke-profile-permissive" + rke2: "rke2-cis-1.5-profile-permissive" eks: "eks-profile" gke: "gke-profile" - default: "cis-1.5-profile" \ No newline at end of file + default: "cis-1.5-profile" diff --git a/charts/rancher-cis-benchmark/templates/scanprofile-rke2-cis-1.5-hardened.yml b/charts/rancher-cis-benchmark/templates/scanprofile-rke2-cis-1.5-hardened.yml new file mode 100644 index 000000000..83eb3131e --- /dev/null +++ b/charts/rancher-cis-benchmark/templates/scanprofile-rke2-cis-1.5-hardened.yml @@ -0,0 +1,9 @@ +--- +apiVersion: cis.cattle.io/v1 +kind: ClusterScanProfile +metadata: + name: rke2-cis-1.5-profile-hardened + annotations: + clusterscanprofile.cis.cattle.io/builtin: "true" +spec: + benchmarkVersion: rke2-cis-1.5-hardened diff --git a/charts/rancher-cis-benchmark/templates/scanprofile-rke2-cis-1.5-permissive.yml b/charts/rancher-cis-benchmark/templates/scanprofile-rke2-cis-1.5-permissive.yml new file mode 100644 index 000000000..40dc44bdf --- /dev/null +++ b/charts/rancher-cis-benchmark/templates/scanprofile-rke2-cis-1.5-permissive.yml @@ -0,0 +1,9 @@ +--- +apiVersion: cis.cattle.io/v1 +kind: ClusterScanProfile +metadata: + name: rke2-cis-1.5-profile-permissive + annotations: + clusterscanprofile.cis.cattle.io/builtin: "true" +spec: + benchmarkVersion: rke2-cis-1.5-permissive diff --git a/charts/rancher-cis-benchmark/values.yaml b/charts/rancher-cis-benchmark/values.yaml index c726c9bc4..b00a2af62 100644 --- a/charts/rancher-cis-benchmark/values.yaml +++ b/charts/rancher-cis-benchmark/values.yaml @@ -5,10 +5,10 @@ image: cisoperator: repository: rancher/cis-operator - tag: v1.0.1 + tag: v1.0.3-rc2 securityScan: repository: rancher/security-scan - tag: v0.2.1 + tag: v0.2.2-rc1 sonobuoy: repository: rancher/sonobuoy-sonobuoy tag: v0.16.3 diff --git a/index.yaml b/index.yaml index 36c4ce24e..1e7e1e241 100644 --- a/index.yaml +++ b/index.yaml @@ -592,6 +592,27 @@ entries: - assets/rancher-backup/rancher-backup-crd-1.0.200.tgz version: 1.0.200 rancher-cis-benchmark: + - annotations: + catalog.cattle.io/auto-install: rancher-cis-benchmark-crd=match + catalog.cattle.io/certified: rancher + catalog.cattle.io/display-name: CIS Benchmark + catalog.cattle.io/namespace: cis-operator-system + catalog.cattle.io/provides-gvr: cis.cattle.io.clusterscans/v1 + catalog.cattle.io/release-name: rancher-cis-benchmark + catalog.cattle.io/ui-component: rancher-cis-benchmark + apiVersion: v1 + appVersion: v1.0.3 + created: "2020-12-02T17:32:52.357792398Z" + description: The cis-operator enables running CIS benchmark security scans on + a kubernetes cluster + digest: b4a3a389580d3a351ff06bf199794ce1de9cd19cfeb695c80a6b6fd8f0eafbee + icon: https://charts.rancher.io/assets/logos/cis-kube-bench.svg + keywords: + - security + name: rancher-cis-benchmark + urls: + - assets/rancher-cis-benchmark/rancher-cis-benchmark-1.0.300.tgz + version: 1.0.300 - annotations: catalog.cattle.io/auto-install: rancher-cis-benchmark-crd=match catalog.cattle.io/certified: rancher @@ -634,6 +655,20 @@ entries: - assets/rancher-cis-benchmark/rancher-cis-benchmark-1.0.100.tgz version: 1.0.100 rancher-cis-benchmark-crd: + - annotations: + catalog.cattle.io/certified: rancher + catalog.cattle.io/hidden: "true" + catalog.cattle.io/namespace: cis-operator-system + catalog.cattle.io/release-name: rancher-cis-benchmark-crd + apiVersion: v1 + created: "2020-12-02T17:32:52.358042101Z" + description: Installs the CRDs for rancher-cis-benchmark. + digest: bb3546b52282fbd22011e6e00aac1f499796101cb2611cc12db9acf7e4d0109b + name: rancher-cis-benchmark-crd + type: application + urls: + - assets/rancher-cis-benchmark/rancher-cis-benchmark-crd-1.0.300.tgz + version: 1.0.300 - annotations: catalog.cattle.io/certified: rancher catalog.cattle.io/hidden: "true" @@ -2008,4 +2043,4 @@ entries: urls: - assets/rio/rio-0.8.000.tgz version: 0.8.000 -generated: "2020-12-02T17:21:06.473670905Z" +generated: "2020-12-02T17:32:52.356910489Z" diff --git a/sha256sum/rancher-cis-benchmark/rancher-cis-benchmark.sum b/sha256sum/rancher-cis-benchmark/rancher-cis-benchmark.sum index 255ab5798..97b0ec556 100644 --- a/sha256sum/rancher-cis-benchmark/rancher-cis-benchmark.sum +++ b/sha256sum/rancher-cis-benchmark/rancher-cis-benchmark.sum @@ -1,4 +1,4 @@ -dc9df3797e1e98031033d43344a531fc65d4e6f7d8bddedc195b2e46428898f0 packages/rancher-cis-benchmark/charts/Chart.yaml +09f57ab0d8519e96543b2d0424db4db5025a14514a9b19a474a373122f7c1e0f packages/rancher-cis-benchmark/charts/Chart.yaml 9baf24b59311c30d10bf55b49011eac6b9831cc65b7f27663a34e54654100c54 packages/rancher-cis-benchmark/charts/README.md ace091a954095a89b2d4fc2ef0e0f1fafe655b1b945cd09e53cb956fa5d615ac packages/rancher-cis-benchmark/charts/app-readme.md 9ad8e48444b777c30f8c8ae5cecb1044bbc84cba0c5e4cbb2bf8cf71a45a3928 packages/rancher-cis-benchmark/charts/crds/clusterscan.yaml @@ -11,8 +11,10 @@ becca0471d85c022ecf824348b21c3a11d38bba0acced43ce993b021a1874390 packages/ranch 21d443b5fbdcf02f911ab7f8114c1eb45c4dffc8fa9c848645d3dbc7a71c70f5 packages/rancher-cis-benchmark/charts/templates/benchmark-gke-1.0.yaml 3915880e4245d9628c83c7fef64d4341bca2694ddb93628c0551bc4828b6c096 packages/rancher-cis-benchmark/charts/templates/benchmark-rke-cis-1.5-hardened.yaml 14c91263219b5eb53350c0b2e062915b1c43d5f30b55a5572049ba20fd80804d packages/rancher-cis-benchmark/charts/templates/benchmark-rke-cis-1.5-permissive.yaml +0c40aef91ce41c01a8256b55125371cdc13f79f0d7fd06db0efaf5d9e5207b83 packages/rancher-cis-benchmark/charts/templates/benchmark-rke2-cis-1.5-hardened.yaml +e720b2e7a687e597c7bd334658c33013b9d1bcf212e4dbd1e1fc4f6e9c4d6d10 packages/rancher-cis-benchmark/charts/templates/benchmark-rke2-cis-1.5-permissive.yaml 0393b0ab137aaa765fc6476a7c1a7692f4a20227ccecb75c19cdff3114ccedb3 packages/rancher-cis-benchmark/charts/templates/cis-roles.yaml -87dc1227e30773891879b99d8c552535422077914ffa01da825763a4c7bb2c14 packages/rancher-cis-benchmark/charts/templates/configmap.yaml +8320218cf4cc9b36ccc0b9be8699ba51ae2ab2c297925fffe377435239f97768 packages/rancher-cis-benchmark/charts/templates/configmap.yaml e3576671c34e9876aaee9e4bf18f5cd2fde9402626b29df81ba81e7d5aef425b packages/rancher-cis-benchmark/charts/templates/deployment.yaml 77fcc6ff5d342c3f170058b0bb6f6aa4810aa620138c7fb669b749f0a9755642 packages/rancher-cis-benchmark/charts/templates/network_policy_allow_all.yaml 94c6519bf22bd835372d73de3ba63c9c62c99167b00bab409cd493e1899732bc packages/rancher-cis-benchmark/charts/templates/patch_default_serviceaccount.yaml @@ -20,8 +22,10 @@ b0d928117df2de06bc4469dd0d8abfdb87db4e9547614181efbdc6cc164ae2d5 packages/ranch 7dd7c461e68ff8dd98fcee215b5d0951386d127eaa2ebcd56d0f5cd6ccac9dfa packages/rancher-cis-benchmark/charts/templates/scanprofile-cis-1.5.yml c7c40d70234820340f93b5b046055dc21bf9cf98242637dc98472fbf6300909f packages/rancher-cis-benchmark/charts/templates/scanprofile-rke-hardened.yml b689137c836ccdb48ee1bd38b8c925c4e57b5ae123054e1aa8a3ff47c5d24a0a packages/rancher-cis-benchmark/charts/templates/scanprofile-rke-permissive.yml +3406a8e64fd8e98b87660030a017f5760c5402948b3098c454e7950c7323236e packages/rancher-cis-benchmark/charts/templates/scanprofile-rke2-cis-1.5-hardened.yml +7f25094be8b7ed96d211c75fb45dbe763a309fad1d3139def40168fca857440a packages/rancher-cis-benchmark/charts/templates/scanprofile-rke2-cis-1.5-permissive.yml 11ee5c240f5ea07f2112edf4c862209b578e8e042999d6072871ddd4c00750a9 packages/rancher-cis-benchmark/charts/templates/scanprofileeks.yml e8c359cdfb1a1b12284af75d180c21af1258caf094a47a96557877f4f5d5f50c packages/rancher-cis-benchmark/charts/templates/scanprofilegke.yml 6e0510dc05660d52057f0ff4d6169d70bb19ba66d9cd92ed58cd617beb6e2cc1 packages/rancher-cis-benchmark/charts/templates/serviceaccount.yaml -8ad9f979e91b2ba33c65b1d3af67f808e83b2abb09deb57225ff01545c4b0183 packages/rancher-cis-benchmark/charts/values.yaml +ff134826828843ef1755e50c6b67534825bbaffb6fdd4e8a6be041f97a7b2b5c packages/rancher-cis-benchmark/charts/values.yaml 951ad1d2a7ded610f857e3c82ee9844eddc8fdc888a70feb709bc50e1e942cb5 packages/rancher-cis-benchmark/package.yaml