Commit Graph

107 Commits (fc4a6b1ccb3263844e8615857e518f365c39ba53)

Author SHA1 Message Date
vardhaman 44e6e8e5e3 CIS: added network policy related permissions to cis-scan-ns clusterrole 2023-02-24 21:48:09 +05:30
Rayan Das fd5aaacdd1 bump CIS Benchmark version to include new security-scan image 2023-02-22 16:33:26 +05:30
Mauren Berti ce1769a6f0
make charts 2023-02-09 09:45:25 -05:00
Mauren Berti 79a977493b
Update PSP approach for rancher-cis-benchmark.
* Remove all previous capabilities checks.
* Bump version from 3.0.1-rc6 to 4.0.0-rc1.
* Add new flag global.cattle.psp.enabled to control installation of PodSecurityPolicies.
* Add new validate-psp-install.yaml file to check whether PSPs can be installed.
* Update app-readme.md with PSP notice.
* Bump Kubernetes compatibility versions to < 1.26.0.
2023-02-09 09:22:06 -05:00
vardhaman 0f5ef706c1 CIS: updated clusterrolebinding name
also removed the unnecessary hook for deleting role binding
2023-02-07 17:54:12 +05:30
vardhaman 332dc80f61 bump cis-operator and cis benchmark chart version 2023-02-01 10:47:14 +05:30
vardhaman 1e8345e71d added tolerations variable for security scan job 2023-02-01 10:28:52 +05:30
Rayan Das 56bb7b322f bump security-scan version, cis-operator, and chart version 2023-01-25 17:15:58 +05:30
Rayan Das 115a07afba bump cis-benchmark version and chart version 2023-01-12 13:40:10 +05:30
Rayan Das 6335f0ec97 add condition to check for PSP capability in rancher-cis-benchmark 2023-01-11 22:42:48 +05:30
Rayan Das 6432a683b4 bump security-scan and cis-operator to the latest rc version 2022-12-20 14:42:27 +05:30
Vaishnav Gaikwad 8edef0570a Update cis-operator imagePullPolicy 2022-12-15 19:59:13 +05:30
vardhaman 39a83006e9 CIS BENCHMARK: added debug env var for cis operator 2022-12-06 11:48:40 +05:30
vardhaman 11895ff5bd updating cis to non rc v3.0.0 2022-11-09 14:37:41 +05:30
galal-hussein 5f2f0ba3dc update security-scan image 2022-10-19 18:02:30 +02:00
galal-hussein 3d4a61d672 fix permissions for cis-serviceaccount 2022-10-18 22:59:53 +02:00
galal-hussein 7641784193 Add PSP for cis-benchmark 2022-10-14 21:06:23 +02:00
Rayan Das d6cf998f18 bump security-scan to v0.2.9-rc4 2022-10-14 09:55:16 +05:30
galal-hussein 3fc4b81e99 Add privielges to cis-operator-serviceaccount in cis-operator namespace 2022-10-14 02:05:27 +02:00
galal-hussein 9a8fbadde3 Add pre-hook for upgrade fix and add serviceaccounts rbac 2022-10-13 20:51:13 +02:00
galal-hussein e0c2133e61 Add RBAC roles for cis benchmark chart 2022-10-12 20:07:16 +02:00
mitulshah-suse b626fd44bc update images and version 2022-09-27 12:55:51 +05:30
mitulshah-suse 1852d11a41 update rc versions to point to latest 2022-09-23 14:11:28 +05:30
mitulshah-suse 60f61ebef4 update version in benchmark,remove 1.5 scanprofile 2022-09-16 09:56:33 +05:30
Arvind Iyengar e5e2465150
Move upstream versioned charts to using majorVersion+1 and doNotRelease 2022-09-09 14:29:03 -07:00
Prachi Damle 021216ca72 Updating CIS to non rc v2.1.0 2022-08-16 17:08:49 -07:00
Rayan Das 3e596d562f bump cis-benchmark version to 2.1.0-rc1 2022-08-16 11:18:33 +05:30
Rayan Das 9872219088 bump CIS Benchmark version and security-scan version 2022-07-22 18:28:01 +05:30
Rayan Das 4c194bf9f9 bump CIS Benchmark version and security-scan version 2022-07-22 12:26:36 +05:30
dhruvmewada15 324b47d504 Added cis-1.23 profiles for base CIS, rke1, rke2, k3s 2022-07-11 16:31:35 +05:30
dhruvmewada15 463e7431dd Added cis-1.20 profiles for base CIS, rke1, rke2, k3s 2022-07-11 16:22:15 +05:30
Vaishnav Gaikwad 5f29efd3f9 update annotations and sonobuoy version 2022-07-07 17:20:59 +05:30
Vaishnav Gaikwad 6929fe59ab Bump security-scan version
New security-scan image has the eks-version fix
2022-06-23 19:16:13 +05:30
Vaishnav Gaikwad ccc57dfdf4 make clusterName string 2022-06-14 09:32:19 +05:30
Prachi Damle 9ebfe30a74 Bump rancher-cis-benchmark to non-rc tag 2.0.4 2022-05-10 12:52:32 -07:00
dhruvmewada15 1b52817c1c Update chart version and security-scan and cis-operator latest version 2022-05-03 14:06:15 +05:30
Prachi Damle 8ee909e723 Bump rancher-cis-benchmark to v2.0.3 2022-03-28 16:47:29 -07:00
Arvind Iyengar 5bf902b453
Fix rancher-cis-benchmark nodeSelector and tolerations 2022-03-18 13:58:09 -07:00
dhruvmewada15 e6bd990363 Update rancher/security-scan image rc tag 2022-03-03 23:43:56 +05:30
Luther Monson be5a59aeac add permits-os to all charts that needed it 2022-03-02 17:11:40 -07:00
dhruvmewada15 b0bc7a03ba Add AKS CIS Scan benchmark config 2022-02-15 23:04:00 +05:30
Arvind Iyengar 69516e7541
Redo Chart.yaml patches 2022-01-06 12:07:46 -08:00
Jacob Payne c1c66abfb9
(dev-v2.6-archive) rancher security scan v0.2.5
(partially cherry picked from commit 3fb8e00a9b)
2022-01-06 11:38:18 -08:00
Brenda Rearden 7f610e7b83
(dev-v2.6-archive) Merge pull request #1652 from brendarearden/2.6.3-kube-version
2.6.3 kube version

(partially cherry picked from commit 49e34f78b4)
2022-01-06 11:38:03 -08:00
Brenda Rearden 2b404d5db1
(dev-v2.6-archive) Merge pull request #1638 from innobead/longhorn-1.2.3
Longhorn 1.2.3 & 1.1.3 for v2.6

(partially cherry picked from commit d0acdab805)
2022-01-06 11:38:00 -08:00
brendarearden 83ff7b56f3
(dev-v2.6-archive) Add kube-version rancher-logging, cis benchmark
(partially cherry picked from commit d176540d04)
2022-01-06 11:38:00 -08:00
Colleen Murphy 68ad619fa3
(dev-v2.6-archive) Merge pull request #1625 from cmurphy/bump-kev2
Bump KEv2 operators

(partially cherry picked from commit 64f6c291de)
2022-01-06 11:37:43 -08:00
Jiaqi Luo 5f1dde5a21
(dev-v2.6-archive) [rancher-monitoring-crd] code refactor
(partially cherry picked from commit cfc2433953)
2022-01-06 11:37:42 -08:00
Colleen Murphy 7f2f418b2c
(dev-v2.6-archive) Bump external-ip-webhook
(partially cherry picked from commit c585a233bc)
2022-01-06 11:37:41 -08:00
Colleen Murphy c14b85702d
(dev-v2.6-archive) Bump KEv2 operators
(partially cherry picked from commit b4893deb99)
2022-01-06 11:37:41 -08:00