mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-20 23:16:49 +00:00
Add explicit CRD/API defaults to manifests that were causing ArgoCD's SSA dry-run to produce results different from live state: - HTTPRoutes: add group, kind, weight defaults to parentRefs/backendRefs - Kyverno ClusterPolicies: add skipBackgroundRequests, allowExistingViolations - Tetragon TracingPolicies: add return, maxData, resolve, returnCopy defaults - Gateway certificateRefs: add group="" default - Guacamole Gateway: add group="" to certificateRefs Add ignoreDifferences for resources that legitimately differ: - Cilium cert Secrets (auto-generated, data always differs) - Istio ValidatingWebhookConfiguration failurePolicy (istiod mutates) - Crowdsec LAPI Secrets (randomly generated) - ServiceMonitor/PodMonitor relabeling action defaults - StatefulSet volumeClaimTemplates apiVersion/kind defaults Persist argocd-cm ignoreDifferences config in ArgoCD Helm values. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
41 lines
879 B
YAML
41 lines
879 B
YAML
apiVersion: cilium.io/v1alpha1
|
|
kind: TracingPolicy
|
|
metadata:
|
|
name: privilege-escalation-detection
|
|
spec:
|
|
kprobes:
|
|
- call: __x64_sys_setuid
|
|
syscall: true
|
|
return: false
|
|
args:
|
|
- index: 0
|
|
type: int
|
|
maxData: false
|
|
resolve: ""
|
|
returnCopy: false
|
|
selectors:
|
|
- matchArgs:
|
|
- index: 0
|
|
operator: Equal
|
|
values:
|
|
- "0"
|
|
matchActions:
|
|
- action: Post
|
|
- call: __x64_sys_setgid
|
|
syscall: true
|
|
return: false
|
|
args:
|
|
- index: 0
|
|
type: int
|
|
maxData: false
|
|
resolve: ""
|
|
returnCopy: false
|
|
selectors:
|
|
- matchArgs:
|
|
- index: 0
|
|
operator: Equal
|
|
values:
|
|
- "0"
|
|
matchActions:
|
|
- action: Post
|