Files
Homelabv4/infrastructure/tetragon/tracing-policies/process-execution.yaml
T
Scooby HuskyandClaude Opus 4.6 131cbca4a6 Fix ArgoCD ServerSideDiff permanent OutOfSync diffs
Add explicit CRD/API defaults to manifests that were causing ArgoCD's
SSA dry-run to produce results different from live state:

- HTTPRoutes: add group, kind, weight defaults to parentRefs/backendRefs
- Kyverno ClusterPolicies: add skipBackgroundRequests, allowExistingViolations
- Tetragon TracingPolicies: add return, maxData, resolve, returnCopy defaults
- Gateway certificateRefs: add group="" default
- Guacamole Gateway: add group="" to certificateRefs

Add ignoreDifferences for resources that legitimately differ:
- Cilium cert Secrets (auto-generated, data always differs)
- Istio ValidatingWebhookConfiguration failurePolicy (istiod mutates)
- Crowdsec LAPI Secrets (randomly generated)
- ServiceMonitor/PodMonitor relabeling action defaults
- StatefulSet volumeClaimTemplates apiVersion/kind defaults

Persist argocd-cm ignoreDifferences config in ArgoCD Helm values.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 17:32:59 -05:00

35 lines
843 B
YAML

apiVersion: cilium.io/v1alpha1
kind: TracingPolicy
metadata:
name: shell-execution-monitoring
spec:
tracepoints:
- subsystem: raw_syscalls
event: sys_enter
args:
- index: 4
type: syscall64
maxData: false
resolve: ""
returnCopy: false
selectors:
- matchArgs:
- index: 4
operator: Equal
values:
- "59" # execve
matchBinaries:
- operator: In
values:
- /bin/sh
- /bin/bash
- /bin/dash
- /usr/bin/bash
- /usr/bin/sh
- /usr/bin/curl
- /usr/bin/wget
- /usr/bin/nc
- /usr/bin/ncat
matchActions:
- action: Post