Remove nessus from cluster configuration

Remove all nessus references: ArgoCD project destination, Istio ambient
enrollment, waypoint gateway, authorization policies, ext-authz policy,
TLS certificate, ingress gateway host, Kyverno exclusion, and Authentik
forward-auth blueprint.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Scooby Husky
2026-03-10 21:02:45 -05:00
co-authored by Claude Opus 4.6
parent c5e13377bd
commit f8eea2ed45
8 changed files with 3 additions and 64 deletions
@@ -273,30 +273,6 @@ spec:
ipBlocks:
- "10.244.0.0/16"
---
# --- Nessus: Allow ingress + Prometheus + intra-namespace ---
apiVersion: security.istio.io/v1
kind: AuthorizationPolicy
metadata:
name: allow-nessus-access
namespace: nessus
spec:
action: ALLOW
rules:
# Intra-namespace
- from:
- source:
namespaces:
- nessus
- from:
- source:
namespaces:
- istio-system
- from:
- source:
namespaces:
- prometheus
---
# --- Rancher: Allow ingress + Prometheus + intra-namespace ---
apiVersion: security.istio.io/v1
@@ -25,7 +25,7 @@ spec:
echo "=== Enrolling app namespaces in Istio ambient mesh ==="
# Enroll app namespaces in ambient mesh
APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole nessus cattle-system)
APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole cattle-system)
for ns in "${APP_NAMESPACES[@]}"; do
echo "Enrolling $ns in ambient mesh..."
kubectl label namespace "$ns" istio.io/dataplane-mode=ambient --overwrite 2>/dev/null || true
@@ -34,7 +34,7 @@ spec:
# Attach waypoint proxies for L7 policy enforcement
echo "Attaching waypoint proxies to app namespaces..."
WAYPOINT_APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole nessus)
WAYPOINT_APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole)
for ns in "${WAYPOINT_APP_NAMESPACES[@]}"; do
kubectl label namespace "$ns" istio.io/use-waypoint=waypoint --overwrite 2>/dev/null || true
done
@@ -31,7 +31,6 @@ spec:
- everest.kube.huskypup.net
- rancher.kube.huskypup.net
- netbird.kube.huskypup.net
- nessus.kube.huskypup.net
- scylla-manager.kube.huskypup.net
---
@@ -71,7 +70,6 @@ spec:
- everest.kube.huskypup.net
- rancher.kube.huskypup.net
- netbird.kube.huskypup.net
- nessus.kube.huskypup.net
- scylla-manager.kube.huskypup.net
tls:
mode: SIMPLE
@@ -119,21 +119,3 @@ spec:
- operation:
hosts:
- scylla-manager.kube.huskypup.net
---
# --- Nessus: Require Authentik auth ---
# NOTE: Namespace 'nessus' must exist before applying this policy.
# This policy will be skipped if the namespace doesn't exist yet.
apiVersion: security.istio.io/v1
kind: AuthorizationPolicy
metadata:
name: ext-authz-nessus
namespace: nessus
spec:
action: CUSTOM
provider:
name: authentik-ext-authz
rules:
- to:
- operation:
hosts:
- nessus.kube.huskypup.net
@@ -238,20 +238,6 @@ spec:
---
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: waypoint
namespace: nessus
labels:
istio.io/waypoint-for: service
spec:
gatewayClassName: istio-waypoint
listeners:
- name: mesh
port: 15008
protocol: HBONE
---
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: waypoint
namespace: crowdsec