Files
Scooby HuskyandClaude Opus 4.6 131cbca4a6 Fix ArgoCD ServerSideDiff permanent OutOfSync diffs
Add explicit CRD/API defaults to manifests that were causing ArgoCD's
SSA dry-run to produce results different from live state:

- HTTPRoutes: add group, kind, weight defaults to parentRefs/backendRefs
- Kyverno ClusterPolicies: add skipBackgroundRequests, allowExistingViolations
- Tetragon TracingPolicies: add return, maxData, resolve, returnCopy defaults
- Gateway certificateRefs: add group="" default
- Guacamole Gateway: add group="" to certificateRefs

Add ignoreDifferences for resources that legitimately differ:
- Cilium cert Secrets (auto-generated, data always differs)
- Istio ValidatingWebhookConfiguration failurePolicy (istiod mutates)
- Crowdsec LAPI Secrets (randomly generated)
- ServiceMonitor/PodMonitor relabeling action defaults
- StatefulSet volumeClaimTemplates apiVersion/kind defaults

Persist argocd-cm ignoreDifferences config in ArgoCD Helm values.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 17:32:59 -05:00

84 lines
2.6 KiB
YAML

apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: require-istio-ambient-mesh
annotations:
policies.kyverno.io/title: Require Istio Ambient Mesh Enrollment
policies.kyverno.io/category: Zero Trust
policies.kyverno.io/severity: high
policies.kyverno.io/description: >-
Application namespaces must be enrolled in Istio ambient mesh via the
istio.io/dataplane-mode=ambient label for zero-trust mTLS enforcement.
spec:
validationFailureAction: Audit
background: true
rules:
- name: check-namespace-ambient-label
skipBackgroundRequests: true
match:
any:
- resources:
kinds:
- Namespace
exclude:
any:
- resources:
names:
# Core Kubernetes
- kube-system
- kube-public
- kube-node-lease
- kyverno
- default
# Infrastructure
- istio-system
- cert-manager
- cnpg-system
- rook-ceph
- vault
- external-secrets
- redis-operator
- mariadb-system
- scylla-operator
- scylla-manager
- reloader
- checkov
- kiali-operator
- envoy-gateway-system
- tetragon
- prometheus
- crowdsec
- cilium-secrets
- gateway
- argocd
- netbird-operator
# Rancher (exact names)
- cattle-system
- cattle-fleet-system
- cattle-fleet-local-system
- cattle-capi-system
- cattle-turtles-system
- cattle-ui-plugin-system
- cattle-impersonation-system
- cattle-global-data
- cattle-local-user-passwords
- cattle-fleet-clusters-system
- fleet-default
- fleet-local
- local
# Rancher dynamic namespaces (wildcard)
- cattle-*
- fleet-*
- c-*
- p-*
- u-*
- user-*
- cluster-fleet-*
validate:
allowExistingViolations: true
message: "Application namespaces must have istio.io/dataplane-mode=ambient for zero-trust mTLS."
pattern:
metadata:
labels:
istio.io/dataplane-mode: ambient