Desplegar utilizando ConfigMap

Kubernetes ConfigMap

SUSE® Security admite la configuración automatizada utilizando la función ConfigMap de Kubernetes. Esto permite el despliegue de SUSE® Security contenedores con las configuraciones, integraciones y otros ajustes apropiados de manera automatizada.

La configuración 'always_reload: true' se puede añadir en cualquier yaml de ConfigMap para forzar la recarga de ese yaml cada vez que el controlador se inicia (versión 4.3.2+). De lo contrario, el ConfigMap solo se cargará al inicio o tras un reinicio completo del clúster (ver sección de almacenamiento persistente a continuación).

Ejemplo completo de ConfigMap SUSE® Security (initcfg.yaml)

El último ConfigMap se puede encontrar en el siguiente initcfg.yaml.

El ejemplo también se muestra a continuación. Esto contiene todos los ajustes disponibles. Por favor, elimina las secciones que no son necesarias y edita las secciones que son necesarias.

Si utilizas ConfigMap en un secreto, consulta la sección a continuación para los cambios de formato.

apiVersion: v1
data:
  fedinitcfg.yaml: |
    # ============ this section is used for primary cluster ============ >>>
    # Optional. If specified, it overwrites the cluster name specified in the system configuration in the sysinitcfg.yaml file
    Cluster_Name: primary.cluster.local
    # Required and must be the same on primary cluster and remote clusters
    # It must be 36 characters long, i.e., 32 hex characters grouped as 8-4-4-4-12 and separated by four hyphens
    Join_Token: 2be93d8f-d42a-44fc-9d33-7c1a6153066b
    # Required: REST server/port of the neuvector-svc-controller-fed-master service
    Primary_Rest_Info:
      Server: 1.2.3.4
      Port: 11443
    # Optional. Supported value: https
    Use_Proxy: ""
    # Optional. Whether federal repo scan data deployment is enabled (for primary cluster only)
    Deploy_Repo_Scan_Data: false
    # <<< ============ this section is used for primary cluster ============
    # ============ this section is used for remote cluster ============ >>>
    # Optional. If specified, it overwrites the cluster name specified in the system configuration in the sysinitcfg.yaml file
    Cluster_Name: remote.cluster.local
    # Required and must be the same on primary cluster and remote clusters
    # It must be 36 characters long, i.e., 32 hex characters grouped as 8-4-4-4-12 and separated by four hyphens
    # The Join_Token specified in the remote cluster's fedinitcfg.yaml needs to be the same as the Join_Token specified in the primary cluster's fedinitcfg.yaml otherwise the auto-joining request will be declined by the primary cluster
    Join_Token: 2be93d8f-d42a-44fc-9d33-7c1a6153066b
    # Required: REST server/port of the neuvector-svc-controller-fed-master service
    Primary_Rest_Info:
      Server: 1.2.3.4
      Port: 11443
    # Optional, for remote cluster only. REST server/port of the neuvector-svc-controller-fed-managed service
    Managed_Rest_Info:
      Server: 4.3.2.1
      Port: 10443
    # Optional. Supported value: https
    Use_Proxy: ""
    # <<< ============ this section is used for remote cluster ============
  passwordprofileinitcfg.yaml: |
    # Optional. true or false or empty string(false)
    always_reload: false
    active_profile_name: default
    pwd_profiles:
    # only default profile is supported.
    - name: default
      comment: default from configMap
      min_len: 6
      min_uppercase_count: 0
      min_lowercase_count: 0
      min_digit_count: 0
      min_special_count: 0
      enable_block_after_failed_login: false
      block_after_failed_login_count: 0
      block_minutes: 0
      enable_password_expiration: false
      password_expire_after_days: 0
      enable_password_history: false
      password_keep_history_count: 0
      # Optional. value between 30 -- 3600  default 300
      session_timeout: 300
  roleinitcfg.yaml: |
    # Optional. true or false or empty string(false)
    always_reload: false
    roles:
    # Optional.
    - Comment: test role
    # Mandatory. name can have ^[a-zA-Z0-9]+[.:a-zA-Z0-9_-]*$
      Name: testrole
    # Mandatory
      Permissions:
        - id: config
          read: true
          write: true
        - id: rt_scan
          read: true
          write: true
        - id: reg_scan
          read: true
          write: true
        - id: ci_scan
          write: true
        - id: rt_policy
          read: true
          write: true
        - id: admctrl
          read: true
          write: true
        - id: compliance
          read: true
          write: true
        - id: audit_events
          read: true
        - id: security_events
          read: true
        - id: events
          read: true
        - id: authentication
          read: true
          write: true
        - id: authorization
          read: true
          write: true
  ldapinitcfg.yaml: |
    # Optional. true or false or empty string(false)
    always_reload: false
    # Mandatory. OpenLDAP or MicrosoftAD
    directory: OpenLDAP
    # Mandatory.
    Hostname: 1.2.3.4
    # Optional. the default value is 389
    Port: 389
    # Optional true or false or empty string(false)
    SSL: false
    # Mandatory.
    base_dn: cn=admin,dc=example,dc=org
    # Optional.
    bind_dn: dc=example,dc=org
    # Optional.
    bind_password: password
    # Optional. empty string(memberUid for openldap or member for windows ad)
    group_member_attr:
    # Optional. empty string(cn for openldap or sAMAccountName for windows ad)
    username_attr:
    # Optional. true or false or empty string(false)
    Enable: false
    # Optional. admin or reader or empty string(none)
    Default_Role: admin
    group_mapped_roles:
      - group: admin1
        global_role: admin
      - group: reader1
        global_role: reader
      - group: cipos1
        global_role: ciops
      - group: admin2
        global_role: admin
      - group: reader2
        global_role: reader
      - group: ciops2
        global_role: ciops
      - group: ns
        global_role:
        role_domains:
          testrole:
            - ns2-ciops1
            - ns2-ciops2
          reader:
            - ns2-reader1
            - ns2-reader2
          admin:
            - ns2-admin1
            - ns2-admin2
      - group: custom
        global_role: testrole
        role_domains:
          ciops:
            - custom-ciops1
            - custom-ciops2
          reader:
            - custom-reader1
            - custom-reader2
          admin:
            - custom-admin1
            - custom-admin2
  oidcinitcfg.yaml: |
    # Optional. true or false or empty string(false)
    always_reload: false
    # Mandatory
    Issuer: https://...
    # Mandatory
    Client_ID: f53c56ec...
    # Mandatory
    Client_Secret: AyAixE3...
    # Optional. empty or string(group filter info)
    Group_Claim:
    # Optional. empty string(openid,profile,email)
    Scopes:
      - openid
      - profile
      - email
    # Optional. true or false or empty string(false)
    Enable: false
    # Optional. admin or reader or empty string(none)
    Default_Role: admin
    group_mapped_roles:
      - group: admin1
        global_role: admin
      - group: reader1
        global_role: reader
      - group: cipos1
        global_role: ciops
      - group: admin2
        global_role: admin
      - group: reader2
        global_role: reader
      - group: ciops2
        global_role: ciops
      - group: ns
        global_role:
        role_domains:
          testrole:
            - ns2-ciops1
            - ns2-ciops2
          reader:
            - ns2-reader1
            - ns2-reader2
          admin:
            - ns2-admin1
            - ns2-admin2
      - group: custom
        global_role: testrole
        role_domains:
          ciops:
            - custom-ciops1
            - custom-ciops2
          reader:
            - custom-reader1
            - custom-reader2
          admin:
            - custom-admin1
            - custom-admin2
    group_claim: groups
  samlinitcfg.yaml: |
    # Optional. true or false or empty string(false)
    always_reload: false
    # Mandatory
    SSO_URL: https://...
    # Mandatory
    Issuer: https://...
    # Mandatory
    X509_Cert: |
      -----BEGIN CERTIFICATE-----
      MIIC8DCCAdigAwIBAgIQSMNDFv5HI7RPgF0uHW8YJDANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQD
      ...
      -----END CERTIFICATE-----
    x509_cert_extra:
      - |
        -----BEGIN CERTIFICATE-----
        MIIC8DCCAdigAwIBAgIQSMNDFv5HI7RPgF0uHW8YJDANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQD
        ...
        -----END CERTIFICATE-----
    # Optional. empty or string(group filter info)
    Group_Claim:
    # Optional. true or false or empty string(false)
    Enable: false
    # Optional. admin or reader or empty string(none)
    Default_Role: admin
    group_mapped_roles:
      - group: admin1
        global_role: admin
      - group: reader1
        global_role: reader
      - group: cipos1
        global_role: ciops
      - group: admin2
        global_role: admin
      - group: reader2
        global_role: reader
      - group: ciops2
        global_role: ciops
      - group: ns
        global_role:
        role_domains:
          testrole:
            - ns2-ciops1
            - ns2-ciops2
          reader:
            - ns2-reader1
            - ns2-reader2
          admin:
            - ns2-admin1
            - ns2-admin2
      - group: custom
        global_role: testrole
        role_domains:
          ciops:
            - custom-ciops1
            - custom-ciops2
          reader:
            - custom-reader1
            - custom-reader2
          admin:
            - custom-admin1
            - custom-admin2
    group_claim: groups
  sysinitcfg.yaml: |
    # Optional. By default, this parameter is set to false.  You can set it to true if you want to allow namespace user with runtime-policy(r) permission to export network policy of the groups
    Allow_Ns_User_Export_Net_Policy: false
    # Optional. true or false or empty string(false)
    always_reload: false
    # Optional. Choose between  Discover or Monitor or Protect or empty string(Discover)
    New_Service_Policy_Mode: Discover
    # Optional. zero-drift or basic or empty string(zero-drift)
    New_Service_Profile_Baseline: zero-drift
    # Optional. input valid ipv4 address or empty string
    Syslog_ip: 1.2.3.4
    # Optional. input 17, 6 or 66 here for udp, tcp, tcp+tls or empty string(17)
    Syslog_IP_Proto: 17
    # Optional. it is required when Syslog_IP_Proto is 66 only
    Syslog_Server_Cert: |
      -----BEGIN CERTIFICATE-----
      MIIC8DCCAdigAwIBAgIQSMNDFv5HI7RPgF0uHW8YJDANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQD
      ...
      -----END CERTIFICATE-----
    # Optional. empty string(514)
    Syslog_Port: 514
    # Optional. chose between Alert/Critical/Error/Warning/Notice/Info/Debug or empty string(Info)
    Syslog_Level: Info
    # Optional. true or false or empty string(false)
    Syslog_status: false
    Syslog_Categories:
    # Optional. can chose multiple between event/security-event/audit or empty string
      - event
      - security-event
      - audit
    # Optional. true or false or empty string(false)
    Syslog_in_json: false
    Auth_By_Platform: false
    single_cve_per_syslog: false
    syslog_cve_in_layers: false
    # Optional
    Webhooks:
      - name: myslack
        url: http...
        type: Slack
        enable: true
        use_proxy: false
      - name: mywebhook
        url: http...
        enable: true
        use_proxy: false
    # Optional. empty string
    Cluster_Name: cluster.local
    # Optional. chose multiple between cpath/mutex/conn/scan/cluster or empty string
    Controller_Debug:
      - cpath
    # Optional. true or false or empty string(true)
    Monitor_Service_Mesh: true
    # Optional. true or false or empty string(false)
    Registry_Http_Proxy_Status: false
    # Optional.  true or false or empty string(false)
    Registry_Https_Proxy_Status: false
    # Optional. http/https registry proxy or empty string
    Registry_Http_Proxy:
      URL: http...
      Username: username
      Password: password
    Registry_Https_Proxy:
      URL: https...
      Username: username
      Password: password
    Xff_Enabled: true
    Net_Service_Status: false
    Net_Service_Policy_Mode: Discover
    Disable_Net_Policy: false
    Scanner_Autoscale:
    # Optional. Choose between immediate or delayed or empty string
      Strategy:
      Min_Pods: 1
      Max_Pods: 3
    # Optional. true or false or empty string(false)
    No_Telemetry_Report: false
    # Optional. Mode Automation Discovery to Monitor. true or false or empty string(false)
    Mode_Auto_D2M: false
    # Optional. default value is 0. unit is seconds and range is between 3600 and 2592000 (1 hour to 30 days)
    Mode_Auto_D2M_Duration: 0
    # Optional. Mode Automation Monitor to Protect. true or false or empty string(false)
    Mode_Auto_M2P: false
    # Optional. default value is 0. unit is seconds and range is between 3600 and 2592000 (1 hour to 30 days)
    Mode_Auto_M2P_Duration: 0
    Scan_Config:
      # Optional. true or false or empty string(false)
      Auto_Scan: false
    # Optional. default value is 24. unit is hour and range is between 0 and 168
    Unused_Group_Aging: 24
  userinitcfg.yaml: |
    # Optional. true or false or empty string(false)
    always_reload: false
    users:
    # add multiple users below
    -
    # this user will be added
    # Optional.
      EMail: user1@email.com
    # Mandatory. username can have ^[a-zA-Z0-9]+[.:a-zA-Z0-9_-]*$
      Fullname: user1
    # Optional. en or zh_cn or empty string(en)
      Locale: en
    # Optional. password length minimal 6, don't lead with ]`}*|<>!%
      Password: password
    # Optional. admin or reader or empty string(none)
      Role: reader
    # Optional. admin group or reader group or empty string
      Role_Domains:
        admin:
          - admin1
          - admin2
        reader:
          - reader1
          - reader2
    # Optional. value between 30 -- 3600  default 300
      Timeout: 300
    -
    # this user will overwrite the original admin user
      Fullname: admin
      Password: password
      Role: admin
kind: ConfigMap
metadata:
  name: neuvector-init
  namespace: neuvector

Luego crea el objeto ConfigMap:

kubectl create -f initcfg.yaml

Ejemplos de ConfigMap Federados (fedinitcfg.yaml)

NeuVector v5.4.0 admite la automatización de Federación a través del ConfigMap. A continuación se presentan ejemplos de configuraciones fedinitcfg.yaml que se pueden aplicar a tus clústeres primarios y clústeres downstream dependiendo de tu caso de uso.

Ejemplo fedinitcfg.yaml para el clúster primario:

# Optional. If specified, it overwrites the cluster name specified in system configuration
Cluster_Name: cluster-primary-43
# Required and must be the same on primary cluster and managed clusters
# It must be 36 characters long, i.e., 32 hex characters grouped as 8-4-4-4-12 and separated by four hyphens
Join_Token: 2be93d8f-d42a-44fc-9d33-7c1a6153066b
# Required: REST server/port of the neuvector-svc-controller-fed-master service
Primary_Rest_Info:
    Server: 10.1.10.43
    Port: 30020
# Optional. Supported value: https
Use_Proxy: ""
# Optional. Whether federal repo scan data deployment is enabled (for primary cluster only)
Deploy_Repo_Scan_Data: false

Ejemplo fedinitcfg.yaml para clústeres downstream:

# Optional. If specified, it overwrites the cluster name specified in system configuration
Cluster_Name: cluster-managed-42
# Required and must be the same on primary cluster and managed clusters
# It must be 36 characters long, i.e., 32 hex characters grouped as 8-4-4-4-12 and separated by four hyphens
Join_Token: 2be93d8f-d42a-44fc-9d33-7c1a6153066b
# Required: REST server/port of the neuvector-svc-controller-fed-master service
Primary_Rest_Info:
    Server: 10.1.10.43
    Port: 30020
# Optional, for managed cluster only. REST server/port of the neuvector-svc-controller-api service
Managed_Rest_Info:
    Server: 10.1.10.42
    Port: 30010
# Optional. Supported value: https
Use_Proxy: ""

Proteger datos sensibles utilizando un secreto

Si se van a incluir datos sensibles en algunas secciones del ConfigMap, se puede crear un secreto para esas secciones con datos sensibles.

Por ejemplo, crea el ConfigMap para secciones NO sensibles como passwordProfile y role:

kubectl create configmap neuvector-init --from-file=$HOME/init/passwordprofileinitcfg.yaml --from-file=$HOME/init/roleinitcfg.yaml -n neuvector

Luego crea un secreto para secciones con datos sensibles, como:

kubectl create secret generic neuvector-init --from-file=$HOME/init/eulainitcfg.yaml --from-file=$HOME/init/ldapinitcfg.yaml --from-file=$HOME/init/oidcinitcfg.yaml --from-file=$HOME/init/samlinitcfg.yaml --from-file=$HOME/init/sysinitcfg.yaml --from-file=$HOME/init/userinitcfg.yaml -n neuvector

Elimina el carácter de tubería '|' en cada sección, como se muestra a continuación.

Ten en cuenta la eliminación del carácter de tubería a continuación si utilizas secciones de ConfigMap en un secreto, habilitado en true, y descomenta la sección que se va a incluir en el secreto.

secret:
    # NOTE: files defined here have preferrence over the ones defined in the configmap section
    enabled: true
    data:
      eulainitcfg.yaml:
        license_key: 0Bca63Iy2FiXGqjk...
      #   ...
      # ldapinitcfg.yaml:
      #   directory: OpenLDAP
      #   ...
      # oidcinitcfg.yaml:
      #   Issuer: https://...
      #   ...
      # samlinitcfg.yaml:
      #   ...
      # sysinitcfg.yaml:
      #   ...
      # userinitcfg.yaml:
      #   ...

Después de que se despliegue el controlador, todos los archivos de configuración tanto del ConfigMap como del secreto se almacenarán en la carpeta /etc/config.

Ten en cuenta que el secreto se menciona en los archivos yaml de despliegue estándar de Kubernetes y OpenShift deployment yaml files bajo Volúmenes.

ConfigMaps y almacenamiento persistente

Tanto los ConfigMaps como la copia de seguridad del almacenamiento persistente solo se leen cuando se despliega un nuevo SUSE® Security clúster, o cuando el clúster falla y se reinicia. No se utilizan durante las actualizaciones progresivas.

La copia de seguridad de la configuración del almacenamiento persistente se lee primero, luego se aplican los ConfigMaps, por lo que los ajustes del ConfigMap tienen prioridad. Todos los ajustes del ConfigMap (por ejemplo, actualizaciones) también se guardarán en el almacenamiento persistente.