mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-21 05:26:49 +00:00
Remove nessus from cluster configuration
Remove all nessus references: ArgoCD project destination, Istio ambient enrollment, waypoint gateway, authorization policies, ext-authz policy, TLS certificate, ingress gateway host, Kyverno exclusion, and Authentik forward-auth blueprint. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
c5e13377bd
commit
f8eea2ed45
@@ -49,8 +49,6 @@ spec:
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: istio-system
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: nessus
|
||||
server: https://kubernetes.default.svc
|
||||
- namespace: authentik
|
||||
server: https://kubernetes.default.svc
|
||||
clusterResourceWhitelist:
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
# endpoint to authenticate requests to protected services.
|
||||
#
|
||||
# Services protected by this provider:
|
||||
# - Prometheus, Ceph Dashboard, TeslaMate, ESPHome, Frigate, Kiali, Nessus, Netbird
|
||||
# - Prometheus, Ceph Dashboard, TeslaMate, ESPHome, Frigate, Kiali, Netbird
|
||||
#
|
||||
# Services with native OIDC are NOT included here (they handle auth themselves):
|
||||
# - GitLab, ArgoCD, Grafana, n8n, Home Assistant, Rancher, Nextcloud
|
||||
|
||||
@@ -273,30 +273,6 @@ spec:
|
||||
ipBlocks:
|
||||
- "10.244.0.0/16"
|
||||
|
||||
---
|
||||
# --- Nessus: Allow ingress + Prometheus + intra-namespace ---
|
||||
apiVersion: security.istio.io/v1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: allow-nessus-access
|
||||
namespace: nessus
|
||||
spec:
|
||||
action: ALLOW
|
||||
rules:
|
||||
# Intra-namespace
|
||||
- from:
|
||||
- source:
|
||||
namespaces:
|
||||
- nessus
|
||||
- from:
|
||||
- source:
|
||||
namespaces:
|
||||
- istio-system
|
||||
- from:
|
||||
- source:
|
||||
namespaces:
|
||||
- prometheus
|
||||
|
||||
---
|
||||
# --- Rancher: Allow ingress + Prometheus + intra-namespace ---
|
||||
apiVersion: security.istio.io/v1
|
||||
|
||||
@@ -25,7 +25,7 @@ spec:
|
||||
echo "=== Enrolling app namespaces in Istio ambient mesh ==="
|
||||
|
||||
# Enroll app namespaces in ambient mesh
|
||||
APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole nessus cattle-system)
|
||||
APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole cattle-system)
|
||||
for ns in "${APP_NAMESPACES[@]}"; do
|
||||
echo "Enrolling $ns in ambient mesh..."
|
||||
kubectl label namespace "$ns" istio.io/dataplane-mode=ambient --overwrite 2>/dev/null || true
|
||||
@@ -34,7 +34,7 @@ spec:
|
||||
|
||||
# Attach waypoint proxies for L7 policy enforcement
|
||||
echo "Attaching waypoint proxies to app namespaces..."
|
||||
WAYPOINT_APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole nessus)
|
||||
WAYPOINT_APP_NAMESPACES=(argocd gitlab n8n nextcloud teslamate home-assistant frigate guacamole)
|
||||
for ns in "${WAYPOINT_APP_NAMESPACES[@]}"; do
|
||||
kubectl label namespace "$ns" istio.io/use-waypoint=waypoint --overwrite 2>/dev/null || true
|
||||
done
|
||||
|
||||
@@ -31,7 +31,6 @@ spec:
|
||||
- everest.kube.huskypup.net
|
||||
- rancher.kube.huskypup.net
|
||||
- netbird.kube.huskypup.net
|
||||
- nessus.kube.huskypup.net
|
||||
- scylla-manager.kube.huskypup.net
|
||||
|
||||
---
|
||||
@@ -71,7 +70,6 @@ spec:
|
||||
- everest.kube.huskypup.net
|
||||
- rancher.kube.huskypup.net
|
||||
- netbird.kube.huskypup.net
|
||||
- nessus.kube.huskypup.net
|
||||
- scylla-manager.kube.huskypup.net
|
||||
tls:
|
||||
mode: SIMPLE
|
||||
|
||||
@@ -119,21 +119,3 @@ spec:
|
||||
- operation:
|
||||
hosts:
|
||||
- scylla-manager.kube.huskypup.net
|
||||
---
|
||||
# --- Nessus: Require Authentik auth ---
|
||||
# NOTE: Namespace 'nessus' must exist before applying this policy.
|
||||
# This policy will be skipped if the namespace doesn't exist yet.
|
||||
apiVersion: security.istio.io/v1
|
||||
kind: AuthorizationPolicy
|
||||
metadata:
|
||||
name: ext-authz-nessus
|
||||
namespace: nessus
|
||||
spec:
|
||||
action: CUSTOM
|
||||
provider:
|
||||
name: authentik-ext-authz
|
||||
rules:
|
||||
- to:
|
||||
- operation:
|
||||
hosts:
|
||||
- nessus.kube.huskypup.net
|
||||
|
||||
@@ -238,20 +238,6 @@ spec:
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
name: waypoint
|
||||
namespace: nessus
|
||||
labels:
|
||||
istio.io/waypoint-for: service
|
||||
spec:
|
||||
gatewayClassName: istio-waypoint
|
||||
listeners:
|
||||
- name: mesh
|
||||
port: 15008
|
||||
protocol: HBONE
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
name: waypoint
|
||||
namespace: crowdsec
|
||||
|
||||
@@ -59,7 +59,6 @@ spec:
|
||||
- authentik
|
||||
- checkov
|
||||
- n8n
|
||||
- nessus
|
||||
validate:
|
||||
allowExistingViolations: true
|
||||
message: >-
|
||||
|
||||
Reference in New Issue
Block a user