From f0cd1965b40cccdb35306e2c8917d702664c2e34 Mon Sep 17 00:00:00 2001 From: Avner Tzur Date: Mon, 4 Oct 2021 13:51:47 +0300 Subject: [PATCH 1/7] update git repo URL using https --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 5e4bd782..701c1bf5 100644 --- a/README.md +++ b/README.md @@ -123,7 +123,7 @@ Note: development (and the release process) is done with Go `1.16` 1. Clone Project ``` -git clone git@github.com:armosec/kubescape.git kubescape && cd "$_" +git clone https://github.com/armosec/kubescape.git kubescape && cd "$_" ``` 2. Build @@ -142,7 +142,7 @@ go mod tidy && go build -o kubescape . 1. Clone Project ``` -git clone git@github.com:armosec/kubescape.git kubescape && cd "$_" +git clone https://github.com/armosec/kubescape.git kubescape && cd "$_" ``` 2. Build From 3c12247b00d2655c203c169b897e62767b0e8911 Mon Sep 17 00:00:00 2001 From: Bezalel Brandwine Date: Mon, 4 Oct 2021 14:54:04 +0300 Subject: [PATCH 2/7] add index html as GitHub pages landing page --- website/index.html | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 website/index.html diff --git a/website/index.html b/website/index.html new file mode 100644 index 00000000..9c7d7b85 --- /dev/null +++ b/website/index.html @@ -0,0 +1,14 @@ + + + + Kubscape Website + +

Kubscape Website

+ + +

+ Join us!!! + +

+ + \ No newline at end of file From 263821ce67377188a062b35f49cd82abfed1c8ab Mon Sep 17 00:00:00 2001 From: Bezalel Brandwine Date: Mon, 4 Oct 2021 14:57:11 +0300 Subject: [PATCH 3/7] landing page in docs dir --- docs/index.html | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 docs/index.html diff --git a/docs/index.html b/docs/index.html new file mode 100644 index 00000000..9c7d7b85 --- /dev/null +++ b/docs/index.html @@ -0,0 +1,14 @@ + + + + Kubscape Website + +

Kubscape Website

+ + +

+ Join us!!! + +

+ + \ No newline at end of file From 25247491eeed6c8d9b3c7343b3c74137022f4e4b Mon Sep 17 00:00:00 2001 From: yiscah Date: Mon, 4 Oct 2021 16:56:18 +0300 Subject: [PATCH 4/7] add mitre to supportedFrameworks, accept upper/lowercase "MITRE" --- cmd/framework.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/cmd/framework.go b/cmd/framework.go index 1487e0fa..e247e183 100644 --- a/cmd/framework.go +++ b/cmd/framework.go @@ -23,7 +23,7 @@ import ( ) var scanInfo cautils.ScanInfo -var supportedFrameworks = []string{"nsa"} +var supportedFrameworks = []string{"nsa", "mitre"} type CLIHandler struct { policyHandler *policyhandler.PolicyHandler @@ -39,7 +39,7 @@ var frameworkCmd = &cobra.Command{ if len(args) < 1 && !(cmd.Flags().Lookup("use-from").Changed) { return fmt.Errorf("requires at least one argument") } else if len(args) > 0 { - if !isValidFramework(args[0]) { + if !isValidFramework(strings.ToLower(args[0])) { return fmt.Errorf(fmt.Sprintf("supported frameworks: %s", strings.Join(supportedFrameworks, ", "))) } } @@ -50,7 +50,7 @@ var frameworkCmd = &cobra.Command{ scanInfo.PolicyIdentifier.Kind = opapolicy.KindFramework if !(cmd.Flags().Lookup("use-from").Changed) { - scanInfo.PolicyIdentifier.Name = args[0] + scanInfo.PolicyIdentifier.Name = strings.ToLower(args[0]) } if len(args) > 0 { if len(args[1:]) == 0 || args[1] != "-" { From cdaa9aa1b03ed976bc30c62070b390fefea9a7dc Mon Sep 17 00:00:00 2001 From: Bezalel Brandwine Date: Tue, 5 Oct 2021 09:18:39 +0300 Subject: [PATCH 5/7] discord UI beautify --- docs/favicon.ico | Bin 0 -> 15406 bytes docs/index.html | 34 ++++++++++++++++++++++------------ 2 files changed, 22 insertions(+), 12 deletions(-) create mode 100644 docs/favicon.ico diff --git a/docs/favicon.ico b/docs/favicon.ico new file mode 100644 index 0000000000000000000000000000000000000000..038e7cf0702b3069efae53276510fc6a3e43acd6 GIT binary patch literal 15406 zcmeI2YmgjO6@YItw|h4WYJ4CuqAVIB2GEUYlHKX#MXW#- zt0g7AewZqv3%fhhGn3t71%eeYSb!;oN@0*l`A#q);gv`vA#pJR3Gq8U)7kEx?w;A% zhp}q9>Q;B(dtUe4bM8HTPAfG_Wz^icihHM8sg+uylZ*<}RBF>n zN}T}=C}33jxgEFHFD_JVu9f+OYiCw8(h5D9Pp-8TGp}6voN9M16 zHXmQ^ZdTtM!2LJRJBpUEU79@8#scHTqoUTp<#rp3k>M4ADcZ*7;s?|Ts~4y?Y5nJ@ z4*Gvx#Xsz3GZzL>y+>dS!K=a?%I8d3LhmZ{w7nPFFIQ=A7ux<<@b23Bx+?xr*V5Pf zV?1Bu_ZMvQ2Y!F_KG5B^Ai(EQk!fR2X>d1H@n2bM8Rtat{P$6%GQd3`um#)rPa$ib z={24`e9L%DX!`JRcXaS2U|$#bqNQ&{_M5zC`U;l5HV!A)SF+VRfZs1Tw1c#NRiDR- zPWx#=*tq9DrDhjxePC|1L(_Nz2h>e`;MV z4IJ+paI@;&1uHYanRCaqv}~qSw)J^QdKg}+PG*1kQ|%tp==oI-PVdWGI+w&>&P&d< zAHv_;XQx_@f@S<>pj*8qiNEyA8Hfz~rkXeO4woGL^?K*bNLJ0~YcMSC!= zaXvf*-d{MY;`FzRc`Z$wyNpTv0PXMkF+)fWM}JfFS6-^#7}xS$YHrCkE|a;2@G58I zy1}e^Lp}a7Ua)nRGxfy?4bD9M^VRT9q9O4Ib98I)h*8kV$|SsKzsv((qRYTJOYC6j zJ$c7GI|}c=7tZzKpfQT@ZHQB@M&_s<4;8SXBz&2pA16g*xDC7O zNWzQj7h8eW&Ip~?v9Wvmm#a5Laf;`w6R?}RfREbVL5ZP(55=WX{OG&b3Ttprlpb^3 zna>)_qVN*`p)-kzLuv?Pq#24wiH^N)|3rRc!{Vx@q%*En6&GL%F^X%N#-zGk-6PxN=B#w-u(duhyprwK1O9PT8Aw{dc zNNeRuP(tf!X`rQnmIkI-0}`LfH|~(F7L_dZ!Q-J(A2=JC=GV(niE2g{DYKFzARlGx zZPXQ>{9iZnGmn>g^)wZv*pJK$xQ?k7rr+TP{6wCEU5mK^i5>nE7!lX^4$`+f2iFQu-5eDB-T zdM$kbcwif79;`8jUIjOC{_qz6d$5c@_DwKX=GEA9<_hp7R~gPjgn5eG5233OTDg%1 zy^eQ&w)#>3Ir>m_+D|1mfr%uU#M9piY z$zCq?7Rl2!yhK8g0m-3Y6SB6P zFR?oD>iO{AFwkS3)oji~Y)JAe?7fmdj<+GpIDn6pMW+!l6JLMAIRwogL-U_W@?(>X znX4K(vl1Dx53TJ{r$TEze8ysVIbJ^W&x5(f_UFDn{x?`|z90M8T=ma5n-rVcTDIq8 z$$^_G^3@$0C7+G_*Wm}x#>&t7Q~TKC_8OPhtKkVV&KBsIpR3Y~UsKySfX&`929Mu1lz&q{-FjnCQXH z8ejA5WSmcU4pOIZj4P#Pl0=sn;6z})f;~Q8qk}44*6|=Px5_@8L}#M?Qb+P?pN{bd z_{Qo@)&|~XS*s-a@~;tl)gUxt_X5@sf6&jcH+^1Wup~Oo^xwWjorcX0()|CMBKr4y zV@p0aXIY#Li4LTehm5lCB>9ol)gD3ri<{l^lji2_8;z9pWk=qcg@-uk0E+qg<# zqjV~@IInJ4Q@0D)(tg)6Z<)wh66KThF1|E$p1BD9KL)>~@0x@7@SSls{)>h|CVAyd#Nd1EAh9FPcGmj>BBdZ>pYx~CCj{C{!#Gpruy!E z*GTQzF@MP%;%$h!I6ktDy3j(Oe<`cphwS%&6ROv;7XBU}YqCYoNo*(ee@mZcv-e89 z%9MX+lVW$V<87s^{;0_EJE^nU`U3joTQn(N;9pJZ;rK|iay5!4{~nj@%*WXSx2MRn z7n#3-Ezey?!**@}Hpyp*mG$n4#^8<08-)`alJ7b8x%-i+@}KRv9r*Tei1_U8e2?lv zr;G8K^~^UG7C(9ozur?^1Who>!&l^ay9@o}$BlxsJXY*~M?;ZHN7o zIjoU?{H8-w%m1kXvF*X|XYf%n6vM$uE3rs$$JJd1Lx!jS!n- z*LR`2qY~bAXQ{gu) z@j|_M^k1YpD*r+0M+y_pv+Lh7?@MRcZ$ne+!{;QY-At`xIIGT-vz+r}M)v%W;H{UI U23i_uX`rQnmIhiHn3M+o3)%k**8l(j literal 0 HcmV?d00001 diff --git a/docs/index.html b/docs/index.html index 9c7d7b85..add13cd3 100644 --- a/docs/index.html +++ b/docs/index.html @@ -1,14 +1,24 @@ - - - Kubscape Website - -

Kubscape Website

- - -

- Join us!!! - -

- + + + + Kubscape Website + + + + + + + Kubescap logo + + + \ No newline at end of file From 740ab7cb46cda191643f291d062cffd96b31c67c Mon Sep 17 00:00:00 2001 From: Bezalel Brandwine Date: Tue, 5 Oct 2021 09:21:58 +0300 Subject: [PATCH 6/7] point readme discord to github pages --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index face5a82..96817b2b 100644 --- a/README.md +++ b/README.md @@ -33,9 +33,9 @@ We invite you to our team! We are excited about this project and want to return Want to contribute? Want to discuss something? Have an issue? * Open a issue, we are trying to respond within 48 hours -* [Join us](https://discordapp.com/invite/CTcCaBbb) in a discussion on our discord server! +* [Join us](https://armosec.github.io/kubescape/) in a discussion on our discord server! -[logo](https://discordapp.com/invite/CTcCaBbb) +[logo](https://armosec.github.io/kubescape/) # Options and examples From 2b67cc520c8541c7fbedfe2bf9b4472508b5e54a Mon Sep 17 00:00:00 2001 From: dwertent Date: Tue, 5 Oct 2021 16:43:05 +0300 Subject: [PATCH 7/7] windows install support --- .github/workflows/build.yaml | 2 +- README.md | 35 ++++++++++++++- build.py | 82 ++++++++++++++++++++++++++++++++++++ install.ps1 | 26 ++++++++++++ 4 files changed, 143 insertions(+), 2 deletions(-) create mode 100644 build.py create mode 100644 install.ps1 diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 454681c9..7b16864c 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -44,7 +44,7 @@ jobs: ArmoERServer: report.euprod1.cyberarmorsoft.com ArmoWebsite: portal.armo.cloud CGO_ENABLED: 0 - run: mkdir -p build/${{ matrix.os }} && go mod tidy && go build -ldflags "-w -s -X github.com/armosec/kubescape/cmd.BuildNumber=$RELEASE -X github.com/armosec/kubescape/cautils/getter.ArmoBEURL=$ArmoBEServer -X github.com/armosec/kubescape/cautils/getter.ArmoERURL=$ArmoERServer -X github.com/armosec/kubescape/cautils/getter.ArmoFEURL=$ArmoWebsite" -o build/${{ matrix.os }}/kubescape # && md5sum build/${{ matrix.os }}/kubescape > build/${{ matrix.os }}/kubescape.md5 + run: python build.py - name: Upload Release binaries id: upload-release-asset diff --git a/README.md b/README.md index 96817b2b..83f57a7c 100644 --- a/README.md +++ b/README.md @@ -15,6 +15,8 @@ Use Kubescape to test clusters or scan single YAML files and integrate it to you curl -s https://raw.githubusercontent.com/armosec/kubescape/master/install.sh | /bin/bash ``` +[Install on windows](#install-on-windows) + ## Run: ``` kubescape scan framework nsa --exclude-namespaces kube-system,kube-public @@ -39,6 +41,20 @@ Want to contribute? Want to discuss something? Have an issue? # Options and examples +## Install on Windows + +**Requires powershell v5.0+** + +``` powershell +iwr -useb https://raw.githubusercontent.com/armosec/kubescape/master/install.ps1 | iex +``` + +Note: if you get an error you might need to change the execution policy (i.e. enable Powershell) with + +``` powershell +Set-ExecutionPolicy RemoteSigned -scope CurrentUser +``` + ## Flags | flag | default | description | options | @@ -119,7 +135,24 @@ Kubescape is an open source project, we welcome your feedback and ideas for impr # How to build -## For development +## Build using python script + +Kubescpae can be built using: + +``` sh +python built.py +``` + +Note: In order to built using the above script, one must set the environment +variables in this script: + ++ RELEASE ++ ArmoBEServer ++ ArmoERServer ++ ArmoWebsite + + +## Build using go Note: development (and the release process) is done with Go `1.16` diff --git a/build.py b/build.py new file mode 100644 index 00000000..cec9f379 --- /dev/null +++ b/build.py @@ -0,0 +1,82 @@ +import os +import sys +import hashlib +import platform +import subprocess + +BASE_GETTER_CONST = "github.com/armosec/kubescape/cautils/getter" +BE_SERVER_CONST = BASE_GETTER_CONST + ".ArmoBEURL" +ER_SERVER_CONST = BASE_GETTER_CONST + ".ArmoERURL" +WEBSITE_CONST = BASE_GETTER_CONST + ".ArmoFEURL" + +def checkStatus(status, msg): + if status != 0: + sys.stderr.write(msg) + exit(status) + + +def getBuildDir(): + currentPlatform = platform.system() + buildDir = "build/" + + if currentPlatform == "Windows": buildDir += "windows-latest" + elif currentPlatform == "Linux": buildDir += "ubuntu-latest" + elif currentPlatform == "Darwin": buildDir += "macos-latest" + else: raise OSError("Platform %s is not supported!" % (currentPlatform)) + + return buildDir + +def getPackageName(): + packageName = "kubescape" + if platform.system() == "Windows": packageName += ".exe" + + return packageName + + +def main(): + print("Building Kubescape") + + # print environment variables + print(os.environ) + + # Set some variables + packageName = getPackageName() + buildUrl = "github.com/armosec/kubescape/cmd.BuildNumber" + releaseVersion = os.getenv("RELEASE") + ArmoBEServer = os.getenv("ArmoBEServer") + ArmoERServer = os.getenv("ArmoERServer") + ArmoWebsite = os.getenv("ArmoWebsite") + + # Create build directory + buildDir = getBuildDir() + + if not os.path.isdir(buildDir): + os.makedirs(buildDir) + + # Get dependencies + try: + status = subprocess.call(["go", "mod", "tidy"]) + checkStatus(status, "Faild to get dependancies") + + except OSError: + print("An error occure: (Hint: check if go is installed)") + raise + + # Build kubescape + ldflags = "-w -s -X %s=%s -X %s=%s -X %s=%s -X %s=%s" \ + % (buildUrl, releaseVersion, BE_SERVER_CONST, ArmoBEServer, + ER_SERVER_CONST, ArmoERServer, WEBSITE_CONST, ArmoWebsite) + status = subprocess.call(["go", "build", "-o", "%s/%s" % (buildDir, packageName), "-ldflags" ,ldflags]) + checkStatus(status, "Faild to build kubescape") + + + sha1 = hashlib.sha1() + with open(buildDir + "/" + packageName, "rb") as kube: + sha1.update(kube.read()) + with open(buildDir + "/" + packageName + ".sha1", "w") as kube_sha: + kube_sha.write(sha1.hexdigest()) + + print("Build Done.") + +if __name__ == "__main__": + main() \ No newline at end of file diff --git a/install.ps1 b/install.ps1 new file mode 100644 index 00000000..0bbcf61b --- /dev/null +++ b/install.ps1 @@ -0,0 +1,26 @@ +Write-Host "Installing Kubescape..." -ForegroundColor Cyan + +$BASE_DIR=$env:USERPROFILE + "\.kubescape" +$packageName = "/kubescape-windows-latest" + +# Get latest release url +$config = Invoke-WebRequest "https://api.github.com/repos/armosec/kubescape/releases/latest" | ConvertFrom-Json +$url = $config.html_url.Replace("/tag/","/download/") +$fullUrl = $url + $packageName + +# Create a new directory if needed +New-Item -Path $BASE_DIR -ItemType "directory" -ErrorAction SilentlyContinue + +# Download the binary +Invoke-WebRequest -Uri $fullUrl -OutFile $BASE_DIR\kubescape.exe + +# Update user PATH if needed +$currentPath = [Environment]::GetEnvironmentVariable("Path", "User") +if (-not $currentPath.Contains($BASE_DIR)) { + $confirmation = Read-Host "Add kubescape to user path? (y/n)" + if ($confirmation -eq 'y') { + [Environment]::SetEnvironmentVariable("Path", [Environment]::GetEnvironmentVariable("Path", "User") + ";$BASE_DIR;", "User") + } +} + +Write-Host "Finished Installation" -ForegroundColor Green