mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-20 23:16:49 +00:00
Add explicit CRD/API defaults to manifests that were causing ArgoCD's SSA dry-run to produce results different from live state: - HTTPRoutes: add group, kind, weight defaults to parentRefs/backendRefs - Kyverno ClusterPolicies: add skipBackgroundRequests, allowExistingViolations - Tetragon TracingPolicies: add return, maxData, resolve, returnCopy defaults - Gateway certificateRefs: add group="" default - Guacamole Gateway: add group="" to certificateRefs Add ignoreDifferences for resources that legitimately differ: - Cilium cert Secrets (auto-generated, data always differs) - Istio ValidatingWebhookConfiguration failurePolicy (istiod mutates) - Crowdsec LAPI Secrets (randomly generated) - ServiceMonitor/PodMonitor relabeling action defaults - StatefulSet volumeClaimTemplates apiVersion/kind defaults Persist argocd-cm ignoreDifferences config in ArgoCD Helm values. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
84 lines
2.6 KiB
YAML
84 lines
2.6 KiB
YAML
apiVersion: kyverno.io/v1
|
|
kind: ClusterPolicy
|
|
metadata:
|
|
name: require-istio-ambient-mesh
|
|
annotations:
|
|
policies.kyverno.io/title: Require Istio Ambient Mesh Enrollment
|
|
policies.kyverno.io/category: Zero Trust
|
|
policies.kyverno.io/severity: high
|
|
policies.kyverno.io/description: >-
|
|
Application namespaces must be enrolled in Istio ambient mesh via the
|
|
istio.io/dataplane-mode=ambient label for zero-trust mTLS enforcement.
|
|
spec:
|
|
validationFailureAction: Audit
|
|
background: true
|
|
rules:
|
|
- name: check-namespace-ambient-label
|
|
skipBackgroundRequests: true
|
|
match:
|
|
any:
|
|
- resources:
|
|
kinds:
|
|
- Namespace
|
|
exclude:
|
|
any:
|
|
- resources:
|
|
names:
|
|
# Core Kubernetes
|
|
- kube-system
|
|
- kube-public
|
|
- kube-node-lease
|
|
- kyverno
|
|
- default
|
|
# Infrastructure
|
|
- istio-system
|
|
- cert-manager
|
|
- cnpg-system
|
|
- rook-ceph
|
|
- vault
|
|
- external-secrets
|
|
- redis-operator
|
|
- mariadb-system
|
|
- scylla-operator
|
|
- scylla-manager
|
|
- reloader
|
|
- checkov
|
|
- kiali-operator
|
|
- envoy-gateway-system
|
|
- tetragon
|
|
- prometheus
|
|
- crowdsec
|
|
- cilium-secrets
|
|
- gateway
|
|
- argocd
|
|
- netbird-operator
|
|
# Rancher (exact names)
|
|
- cattle-system
|
|
- cattle-fleet-system
|
|
- cattle-fleet-local-system
|
|
- cattle-capi-system
|
|
- cattle-turtles-system
|
|
- cattle-ui-plugin-system
|
|
- cattle-impersonation-system
|
|
- cattle-global-data
|
|
- cattle-local-user-passwords
|
|
- cattle-fleet-clusters-system
|
|
- fleet-default
|
|
- fleet-local
|
|
- local
|
|
# Rancher dynamic namespaces (wildcard)
|
|
- cattle-*
|
|
- fleet-*
|
|
- c-*
|
|
- p-*
|
|
- u-*
|
|
- user-*
|
|
- cluster-fleet-*
|
|
validate:
|
|
allowExistingViolations: true
|
|
message: "Application namespaces must have istio.io/dataplane-mode=ambient for zero-trust mTLS."
|
|
pattern:
|
|
metadata:
|
|
labels:
|
|
istio.io/dataplane-mode: ambient
|