783aa03b6a
Feat pcapsaver ( #1621 )
...
* Add cmd to copy pcaps from worker
* Update commands to merge pcaps
* Remove test img
* Remove usage of http endpoint in copy
* Unify commands
* Add copy flag
* Address review comments
* Update k8s config path processing
* Remove debug prints
* setting the pcapSrcDit to the name of the command
* Update values.yaml
* Remove the start,stop and copy flags
* Clean up the the code a bit
Changed the logic so it's either copy or start/stop.
Works well for a first version.
* Improved the logic
* Changed pcapdump enable flag to boolean
* Added helm value documentation
* minor default configuration changes
* Fix default val for enabled
* Final changes
Cleaned up the helm worker template
Improve the logic a bit
* Code cleanup
Changed instances of `enable` to `enabled` for purpose of consistency
Removed unused helm environment variables
* Enable merging all node files to a single file.
Before the outcome had been a merged file per node.
Now the outcome is a single merged file for all nodes.
* Committed for testing purpose
* Reduced the initial disk foot print to 10MB per node
---------
Co-authored-by: bogdan.balan1 <bogdanvalentin.balan@1nce.com >
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-10-07 08:39:52 -07:00
Volodymyr Stoiko and GitHub
afa81e7be9
Update README with resource guard configuration ( #1623 )
2024-09-30 13:06:21 -07:00
9144d98d04
Add udp to list of enabled dissectors ( #1616 )
...
* Add `udp` to list of enabled dissectors
* ignore udp as part of a global filter
* have globalFilter ignore udp and icmp
* Have globalFilter ignore udp and icmp
* Update README.md
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-09-25 11:29:21 -07:00
Alon Girmonsky and GitHub
d61e6ab8eb
text change
2024-09-15 14:32:11 -07:00
Alon Girmonsky and GitHub
b6672661ad
text changes
2024-09-15 14:29:02 -07:00
Alon Girmonsky
88c72cda82
🔖 Bump the Helm chart version to 52.3.81
2024-09-14 11:53:26 -07:00
3c6307e93f
Add sentry related configurations ( #1606 )
...
* Add sentry configuration
* get helm values
* Add sentry configuration
---------
Co-authored-by: tiptophelmet <serhii.ponomarenko.jobs@gmail.com >
2024-09-09 16:40:08 -07:00
95637bfce8
Use major version as containers tag ( #1594 )
...
* Respect tagLocked version
* generate proper values
* fix helper
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-09-09 14:38:36 -07:00
Serhii Ponomarenko and GitHub
32caeb37e4
🔨 Create dissectorsUiEnabled flag ( #1599 )
...
* 🔨 Create `dissectorsUiEnabled` flag
* 🔨 Rename `dissectorsUiEnabled` flag
* 🔨 Add `DISSECTORS_UPDATING_ENABLED` config
* 🔨 Set `dissectorsUpdatingEnabled: true` by default
2024-08-29 09:36:58 -07:00
Ilya Gavrilov and GitHub
1dfef1be23
update helm readme ( #1596 )
2024-08-28 10:38:19 -07:00
Alon Girmonsky and GitHub
84f2ec944d
tcp dissector enabled by default ( #1591 )
...
* tcp dissector enabled by default
* changing the readme
In support of having the `tcp` dissector enabled by default.
* Update values.yaml
* Update complete.yaml
* updated the defaultFilter default value
1. Start with some level of "noise reduction" (`tcp` and `dns`).
2. Provide a hint how to use a display filter to filter out protocol aliases.
* Update values.yaml
filter out DNS and TCP
* Update complete.yaml
Filter out DNS and TCP
* Update README.md
Filter out TCP and DNS by default
2024-08-22 17:14:38 -07:00
Alon Girmonsky and GitHub
9069f10d94
TCP dissector description ( #1586 )
...
* TCP dissector description
Added a description how to use the TCP dissector.
* removed tcp from complete.yaml
2024-08-16 17:06:06 -07:00
Alon Girmonsky and GitHub
e70167c694
Added supported protocol dissectors section
2024-08-12 16:42:18 -07:00
Alon Girmonsky and GitHub
32136520d8
Slow start ( #1576 )
...
* Start `ExcludedNamespaces` empty by default
* Started Kubeshark with tap.stopped true by default
* Revert "Start `ExcludedNamespaces` empty by default"
This reverts commit 7de515dd3a .
* Start with traffic capture paused by default
Remove any namespaces to exclude by default
2024-08-06 15:39:42 -07:00
Alon Girmonsky and GitHub
df0aea1462
stash ( #1575 )
2024-07-31 15:14:36 -07:00
Alon Girmonsky and GitHub
a699755858
Way to avoid seeing DNS traffic
2024-07-25 18:43:40 -07:00
7168b5c515
🔨 Add canStopTrafficCapturing SAML authz action ( #1565 )
...
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-07-18 08:18:03 -07:00
M. Mert Yildiran and GitHub
c88b3b0ba7
Remove "Replay" function functionality ( #1563 )
2024-07-16 13:13:08 -07:00
Alon Girmonsky
d1cc890cad
set kernelModule.enabled default value to false
...
As a temporary remady:
1. ebpf and pf-ring become explicit options
2. af_packet becomes the default option
2024-05-31 20:59:51 -07:00
Alon Girmonsky and GitHub
1aef7be3fb
helm clone specific branch
...
Added instructions on how to clone a specific branch
2024-05-28 21:10:32 -07:00
247498492a
✨ Set custom timezone ( #1517 )
...
* 🔨 Add timezone config
* 🔨 Update `complete.yaml`
* 📝 Document `timezone` config
* 📝 Update `timezone` config docs
* 📝 Update `timezone` config docs
* 🔥 Remove unused `TIMEZONE` field from `ConfigMap`
* 🦺 Handle empty `tap.timezone` case
* 🔨 Move `timezone` from `.Values.tap` to `.Values`
* 🔨 Add `timezone` field to helm values
* 🔨 Update `complete.yaml`
* 📝 Update `timezone` config docs
* 🔨 Add `TIMEZONE` field to `ConfigMap`
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-03-19 12:06:50 +01:00
6785f024e4
✨ Feature-based SAML authorization ( #49 ) ( #1495 )
...
* 🔨 Add `showAdminConsoleLink` to helm values
* 🔨 Add `ShowAdminConsoleLink` to `TapConfig`
* 🔨 Regenerate `complete.yaml` manifest
* 📝 Update helm-chart `README.md`
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-02-06 13:36:32 -08:00
18d051af28
🔥 Remove old Descope auth ( #1490 )
...
* 🔥 Remove Descope-related config updates
* 🔥 Remove Descope-related helm values
* 🔥 Remove Descope-related k8s configs
* 🔥 Remove Descope-related fields from `tapConfig`
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-01-31 14:49:55 -08:00
Alon Girmonsky and GitHub
4117d008a9
Update README.md
2024-01-28 11:06:18 -08:00
bfa3efd23a
✨ SAML authorization ( #1487 )
...
* 🔨 Add `AUTH_SAML_ROLE_ATTRIBUTE` field to `ConfigMap`
* 📝 Document `tap.auth.saml.roleAttribute/roles` values
* 🔧 Re-generate `complete.yaml`
* 🔥 Remove `default` tag from `SamlConfig.RoleAttribute`
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-01-24 16:05:37 -08:00
a8dd332ff8
✨ SAML integration prototype ( #1475 )
...
* 🔨 Add `AUTH_TYPE` field to `ConfigMap`
* 🔨 Add `AUTH_SAML_IDP_METADATA_URL` field to `ConfigMap`
* 🔨 Add `AUTH_SAML_X509_CRT` field to `Secret`
* 🔨 Add `AUTH_SAML_X509_KEY` field to `Secret`
* 🔨 Mount SAML X.509 key pair into `hub`
* 🔨 Add `REACT_APP_AUTH_TYPE` environment variable to `front`
* 🔧 Add Nginx path rewrite for `/saml`
* 🔧 Raise request size to accept big SAML responses
* 🔨 Add `REACT_APP_AUTH_TYPE` environment default value
* 📝 Update `README.md`
* 📝 Update `README.md`
* 🔨 Add `AUTH_TYPE` config map key
* 🔨 Add `AUTH_SAML_IDP_METADATA_URL` config map key
* ☸ Set `CONFIG_AUTH_TYPE` from `TapConfig`
* ☸ Set `CONFIG_AUTH_SAML_IDP_METADATA_URL` from `TapConfig`
* ✨ Create `SamlConfig` in `TapConfig.AuthConfig`
* 🔨 Use updated `tap.auth.saml.idpMetadataUrl` tap config field
* 📝 Update `README.md`
* 🔨 Add `tap.insgress.enabled/host` to `ConfigMap`
* 🔨 Add `tap.proxy.front.port` to `ConfigMap`
* 🔨 Add `REACT_APP_AUTH_SAML_IDP_METADATA_URL` env to `front`
* 🔧 Supply `auth.saml` fields to `helm-chart/values.yaml`
* 🐛 Fix indentation for X.509 secrets
* 📝 Provide SAML setup docs
* 📝 Update SAML setup docs
* 📝 Update SAML setup docs
* Added callback URL indication
* 💥 Disable standard `Descope` auth
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-01-23 10:47:29 -08:00
aaeb3ca1eb
Load pf-ring kernel module in init container ( #1476 )
...
* Load kernel module in init container
* Update docs
* Update formatting
* Add pre-stop hook to unload pf_ring module
* Enable hook only on kernel module enabled
* fix template
* Use sidecontainer to unload pf_ring
* Add requirements for tracer into structs
* fix values
* fix typo
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2024-01-12 15:49:39 -08:00
Alon Girmonsky and GitHub
7df35e04a8
Update README.md
...
Changed `tap.tls` and `tap.serviceMesh` defaults to `true` following this commit: https://github.com/kubeshark/kubeshark/commit/8ba3e603a4f4e995c1ea3956f7bea34505bcbdc0
2024-01-12 09:36:34 -08:00
db51e6dbc2
✨ Add kubeshark-worker-metrics service and document it ( #1474 )
...
* Expose worker metrics
* Add metrics documentation
* upd
* Update metrics port configuration
* Update config/configStructs/tapConfig.go
Co-authored-by: M. Mert Yildiran <me@mertyildiran.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <me@mertyildiran.com >
* Update helm-chart/templates/16-worker-service-metrics.yaml
Co-authored-by: M. Mert Yildiran <me@mertyildiran.com >
---------
Co-authored-by: M. Mert Yildiran <me@mertyildiran.com >
2024-01-04 16:17:22 +03:00
Alon Girmonsky and GitHub
77878e97f5
Tracer, ServiceMesh - Disable by default and some docs updates ( #1472 )
...
* Disabled Tracer by default
As Tracer requires significantly more resources and elevated security capability, it is recommended to have it disabled by default and enabled on demand.
* Updated the tap.tls default value to false
* added description to the default and global KFL filters
* serviceMesh false by default
As serviceMesh requires elevated security permissions.
Furthermore this capability is required only in a fraction of the userbase. Some service mesh versions/configurations aren't supported. Therefore, it is recommended to start as disabled and enable on-demand
* Update the readme related to the service mesh default value
Set the default value of serviceMesh to false as among other things, it requires elevated security permissions and therefore should be enabled on demand.
2023-12-30 18:47:26 -08:00
6c01078f97
Add PF_RING related changes to docs and helm ( #1471 )
...
* Install pf-ring KMM Module and wait for it
* Add mode configuration
* save
* Update doc
* upd
* toc
* adjust template
* upd
* Add module cr verification job
* upd doc
* Fix binary name
* Add disable mode
* Update PF_RING.md
Some adjustments to the instructions.
* Update 15-pf-ring-kernel-module.yaml
Small syntax err
* upd
* merge master
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
2023-12-27 19:01:20 -08:00
d3c21a07bb
EFS persistent volume helm deployment support ( #1455 )
...
* EFS persistent volume
docs/14
EFS static and dynamic provision added to default
* Update helm-chart/values.yaml
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/templates/08-persistent-volume-claim.yaml
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update config/configStructs/tapConfig.go
Fix format
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Fix format config/configStructs/tapConfig.go
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Improve formatting
---------
Co-authored-by: Alon Girmonsky <1990761+alongir@users.noreply.github.com >
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
2023-12-11 10:52:58 -08:00
Alon Girmonsky and GitHub
1070d17e20
Update README.md
...
fixing syntax err
2023-12-05 00:17:36 -08:00
M. Mert Yildiran
88f8998df3
🔨 Update the worker pod and run make generate-helm-values && make generate-manifests
2023-11-21 20:24:14 +03:00
M. Mert Yildiran
62d4c3a86e
🔨 Add ApprovedTenants field to AuthConfig and enable auth by default
2023-10-26 20:27:34 +03:00
M. Mert Yildiran
3b5cd6c77b
🔨 Make the config field tags camelCase
2023-10-25 18:00:32 +03:00
M. Mert Yildiran
0e2bca9729
Revert " 🔨 Decrease the default storage limit back to 200Mi"
...
This reverts commit b1a40df069 .
2023-10-24 03:10:23 +03:00
M. Mert Yildiran
b1a40df069
🔨 Decrease the default storage limit back to 200Mi
2023-10-24 03:06:02 +03:00
2b92bb74c7
📝 Update README.md ( #1439 )
...
* Update README.md
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <me@mertyildiran.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <me@mertyildiran.com >
* Update README.md
fixed storage limit and change a title auth+eks
---------
Co-authored-by: M. Mert Yildiran <me@mertyildiran.com >
2023-10-17 01:42:29 +03:00
bdff836040
📝 Document the fields of values.yaml in Helm chart's README.md ( #1437 )
...
* Add Configuration parameters section
* Change proxy definition
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
* Update helm-chart/README.md
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
---------
Co-authored-by: M. Mert Yildiran <mehmetmertyildiran@gmail.com >
2023-10-13 16:18:35 +03:00
Alon Girmonsky and GitHub
1064305934
Update README.md
...
fixed helm command
2023-10-11 17:09:17 -07:00
M. Mert Yildiran
bb0172b151
📝 Update the README.md(s)
2023-09-25 23:26:06 +03:00
M. Mert Yildiran
c533bcd38c
✨ Add AUTH_ENABLED and AUTH_APPROVED_EMAILS environment variables to Hub's template
2023-08-09 01:22:10 +03:00
250a878407
✨ Allow to disable IPv6 for nginx ingress ( #1392 )
...
Co-authored-by: M. Mert Yildiran <me@mertyildiran.com >
2023-08-05 18:43:13 +03:00
M. Mert Yildiran
19443501da
⚡ Have consistent key style in values.yaml
2023-06-27 03:32:03 +03:00
Alon Girmonsky and GitHub
7208ed85d3
Update README.md
...
Adding a way to get the license where relevant.
2023-06-06 17:43:35 +03:00
M. Mert Yildiran
c0d7d0fe80
⚡ Update Helm README.md
2023-05-25 05:46:10 +03:00
M. Mert Yildiran
be5bd6a372
⚡ Template the AUTH_APPROVED_DOMAINS and certmanager.k8s.io/cluster-issuer
...
Also add `networking.k8s.io` to `apiGroups` in `ClusterRole`
2023-05-25 05:07:42 +03:00
M. Mert Yildiran
95edac9f8f
📚 Remove the WIP notice in the Helm chart README.md
2023-04-13 01:53:04 +03:00
M. Mert Yildiran
f6c4d43eb1
⚡ Update a README.md(s)
2023-04-12 03:12:32 +03:00