Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6b72508e0b | ||
|
|
5c5d3d4e5d | ||
|
|
52df126b93 | ||
|
|
6ae13d8603 | ||
|
|
6aff3c8ee0 | ||
|
|
714add15e2 | ||
|
|
05da87eadf | ||
|
|
908a3a9c72 | ||
|
|
3e8a3c92e6 | ||
|
|
bddfece857 | ||
|
|
268f0e6811 | ||
|
|
e31f3f1b41 | ||
|
|
5acdc4a4b9 | ||
|
|
0f1d4cd952 | ||
|
|
c398f1043c | ||
|
|
091fa77d11 | ||
|
|
1b97f31edb | ||
|
|
8c454fa733 | ||
|
|
32c1150b28 | ||
|
|
19341205b7 | ||
|
|
89dfce5bbd | ||
|
|
a62389b85f | ||
|
|
5aa397ca22 | ||
|
|
d41ce88f16 | ||
|
|
310015ff53 | ||
|
|
bb7ba83362 | ||
|
|
c0d8eb6318 | ||
|
|
19bf91e13b | ||
|
|
9ae4f774e9 | ||
|
|
6c14d968c9 | ||
|
|
3e655d846b | ||
|
|
0232e31a50 | ||
|
|
a396f049d0 | ||
|
|
a55acdd372 | ||
|
|
ca3e46ebbd | ||
|
|
e661e9542d | ||
|
|
b923caf79e | ||
|
|
3e79863aa7 | ||
|
|
d172d8e18b | ||
|
|
38c410c5aa | ||
|
|
653eac6002 | ||
|
|
6c995eb04c | ||
|
|
e52f1e76e9 | ||
|
|
cf69099d3a | ||
|
|
20f1be3975 | ||
|
|
f602687c90 | ||
|
|
a3404a132d | ||
|
|
46836ccc4c | ||
|
|
ff8e66af07 | ||
|
|
01cc5fa642 | ||
|
|
cd47487b0b | ||
|
|
7e7e553c0d | ||
|
|
8385fd10e5 | ||
|
|
ccc795d58e | ||
|
|
0007b12080 | ||
|
|
2958b5cc07 | ||
|
|
0c5014489e | ||
|
|
ebf99869ff | ||
|
|
a43a0fe2f5 | ||
|
|
88b57f9f32 | ||
|
|
e028c34448 | ||
|
|
7c1ec6a762 | ||
|
|
fa6843ae61 | ||
|
|
76cc9e3296 | ||
|
|
6bcdb834ed | ||
|
|
2bac1c9ba9 | ||
|
|
0e6ca81f57 | ||
|
|
4bc2522e25 | ||
|
|
d4bb6239c7 | ||
|
|
082e9c0406 | ||
|
|
178742e0f3 | ||
|
|
1651aa7004 | ||
|
|
e6c9e4558e | ||
|
|
b6f1bdf098 | ||
|
|
cbc15ad069 | ||
|
|
68d295ec6b | ||
|
|
90339357c2 | ||
|
|
2e7368d011 | ||
|
|
6cd65fbed8 | ||
|
|
1ede736971 | ||
|
|
1935abd563 | ||
|
|
842ccf4853 | ||
|
|
2c56a313a1 | ||
|
|
7b00d73a6f | ||
|
|
a995e7e724 | ||
|
|
3211d6d25d | ||
|
|
d011bb454a | ||
|
|
8e62436697 | ||
|
|
c9811171ce | ||
|
|
30eebaf16a | ||
|
|
dbf001fa53 | ||
|
|
f753fc91f2 | ||
|
|
239a321588 | ||
|
|
61eb1f95a4 | ||
|
|
a66a6b89da | ||
|
|
46923d0a0a | ||
|
|
ba1b4d5db9 | ||
|
|
ba0a25acf9 | ||
|
|
371e30fe3d | ||
|
|
1013834e3c | ||
|
|
e802c28801 | ||
|
|
14d503580b | ||
|
|
0fc109c199 | ||
|
|
63fd576d3e | ||
|
|
f0c8ee256e | ||
|
|
d5cb68084e | ||
|
|
f7d2309608 | ||
|
|
d800e8d629 | ||
|
|
eebc9537a2 | ||
|
|
1fed099b53 | ||
|
|
25dfae1fea | ||
|
|
c365fb08cf | ||
|
|
768b715fdf | ||
|
|
7d938ac405 | ||
|
|
2f5964519a | ||
|
|
2064384985 | ||
|
|
b436699260 | ||
|
|
1a025da649 | ||
|
|
4c3d0e0603 | ||
|
|
714b7bfbba | ||
|
|
16ffe1e1c4 | ||
|
|
7f1c143d77 | ||
|
|
f42af35352 | ||
|
|
8bbe13b6fa | ||
|
|
dea7143827 | ||
|
|
41d5f72822 | ||
|
|
3e49a3af98 | ||
|
|
89ff4a6d53 | ||
|
|
a5852f3003 | ||
|
|
4a04999ce7 | ||
|
|
c16aac808f | ||
|
|
0aa173789a | ||
|
|
38b5cd8193 | ||
|
|
ef59f7c26e | ||
|
|
08900887e4 | ||
|
|
9ddbe5a329 | ||
|
|
3f7fccf5f1 | ||
|
|
d9e148c0f2 | ||
|
|
613c4b9ea1 | ||
|
|
fe0060af77 | ||
|
|
7b428fe230 | ||
|
|
2e148546d8 | ||
|
|
23d76594a6 | ||
|
|
512a5f2886 | ||
|
|
09d5fdcd1e | ||
|
|
e4d6fb9b61 | ||
|
|
c11b839009 |
@@ -17,6 +17,7 @@ references:
|
||||
echo 'export PUSH_ALL_VERSION_TAGS=true' >> ${BASH_ENV}
|
||||
echo 'export GOPROXY=https://proxy.golang.org' >> ${BASH_ENV}
|
||||
echo 'export GO111MODULE=on' >> ${BASH_ENV}
|
||||
echo 'export GOFLAGS=-mod=mod' >> ${BASH_ENV}
|
||||
|
||||
install_k8s: &install_k8s
|
||||
run:
|
||||
@@ -58,16 +59,6 @@ references:
|
||||
helm install cert-manager jetstack/cert-manager --namespace cert-manager --version 0.16.1 --set "installCRDs=true" --wait
|
||||
echo "Install cert-manager successful"
|
||||
|
||||
# Test scripts
|
||||
update_coverage: &update_coverage
|
||||
run:
|
||||
name: Update Coverage
|
||||
command: |
|
||||
if [[ -z $CIRCLE_PR_NUMBER ]]; then
|
||||
bash <(curl -s https://codecov.io/bash)
|
||||
else
|
||||
echo "Skipping coverage for forked PR"
|
||||
fi
|
||||
test_binary_dashboard: &test_binary_dashboard
|
||||
run:
|
||||
name: Test Dashboard
|
||||
@@ -96,8 +87,8 @@ references:
|
||||
run:
|
||||
name: Install GoReleaser
|
||||
command: |
|
||||
curl -fsSLo goreleaser.deb https://github.com/goreleaser/goreleaser/releases/download/v0.131.1/goreleaser_amd64.deb
|
||||
echo "640790dcbfa864f26de4c26c2d491f293a64525c8c6641c5bbdec7136b38977e goreleaser.deb" | sha256sum -c -
|
||||
curl -fsSLo goreleaser.deb https://github.com/goreleaser/goreleaser/releases/download/v0.174.2/goreleaser_amd64.deb
|
||||
echo "bad33997ea9977a84196bdca1d5993fada909cd81c3e88d52bd297666bea61a4 goreleaser.deb" | sha256sum -c -
|
||||
sudo dpkg -i goreleaser.deb
|
||||
rm goreleaser.deb
|
||||
|
||||
@@ -157,22 +148,36 @@ jobs:
|
||||
test:
|
||||
working_directory: /go/src/github.com/fairwindsops/polaris/
|
||||
docker:
|
||||
- image: circleci/golang:1.13
|
||||
- image: circleci/golang:1.16
|
||||
steps:
|
||||
- checkout
|
||||
- *set_environment_variables
|
||||
- run: go get -u golang.org/x/lint/golint
|
||||
- run: go list ./... | grep -v vendor | xargs golint -set_exit_status
|
||||
- run: go list ./... | grep -v vendor | xargs go vet
|
||||
- run: go test ./pkg/... -coverprofile=coverage.txt -covermode=count
|
||||
- run: go test ./... -coverprofile=coverage.txt -covermode=count
|
||||
- run: go run main.go audit --audit-path ./deploy --set-exit-code-below-score 100 --set-exit-code-on-danger
|
||||
- *update_coverage
|
||||
- *test_binary_dashboard
|
||||
|
||||
insights:
|
||||
docker:
|
||||
- image: quay.io/reactiveops/ci-images:v11.0-stretch
|
||||
steps:
|
||||
- checkout
|
||||
- setup_remote_docker
|
||||
- run:
|
||||
name: Adjust configs for latest image
|
||||
command: |
|
||||
sed -r "s|'(quay.io/fairwinds/polaris:).+'|'\1${CIRCLE_SHA1}'|" ./deploy/webhook.yaml > ./deploy/dashboard.yaml
|
||||
sed -r "s|'(quay.io/fairwinds/polaris:).+'|'\1${CIRCLE_SHA1}'|" ./deploy/dashboard.yaml > ./deploy/webhook.yaml
|
||||
- run:
|
||||
name: Insights CI
|
||||
command: curl -L https://insights.fairwinds.com/v0/insights-ci.sh | bash
|
||||
|
||||
release_binary:
|
||||
working_directory: /go/src/github.com/fairwindsops/polaris/
|
||||
docker:
|
||||
- image: circleci/golang:1.13
|
||||
- image: circleci/golang:1.16
|
||||
steps:
|
||||
- checkout
|
||||
- setup_remote_docker
|
||||
@@ -194,6 +199,31 @@ jobs:
|
||||
- *set_environment_variables
|
||||
- *docker_build_and_push
|
||||
|
||||
publish_docs:
|
||||
docker:
|
||||
- image: cimg/node:15.5.1
|
||||
steps:
|
||||
- checkout
|
||||
- run:
|
||||
name: Build Docs Site
|
||||
command: |
|
||||
set -e
|
||||
cd ./docs
|
||||
npm install
|
||||
npm run check-links
|
||||
npm run build
|
||||
- run:
|
||||
name: Install AWS CLI
|
||||
command: |
|
||||
curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
|
||||
unzip awscliv2.zip
|
||||
sudo ./aws/install
|
||||
- run:
|
||||
name: Publish Docs Site to S3
|
||||
command: |
|
||||
cd ./dist
|
||||
aws s3 sync ./ s3://polaris.docs.fairwinds.com --delete
|
||||
|
||||
workflows:
|
||||
version: 2
|
||||
|
||||
@@ -210,6 +240,12 @@ workflows:
|
||||
filters:
|
||||
branches:
|
||||
ignore: /pull\/[0-9]+/
|
||||
- insights:
|
||||
requires:
|
||||
- push
|
||||
filters:
|
||||
branches:
|
||||
ignore: /pull\/[0-9]+/
|
||||
- test_k8s:
|
||||
requires:
|
||||
- push
|
||||
@@ -224,7 +260,6 @@ workflows:
|
||||
filters:
|
||||
branches:
|
||||
ignore: /.*/
|
||||
# Testing tags are reserved for testing circle test + build steps
|
||||
tags:
|
||||
ignore: /^testing-.*/
|
||||
- release_images:
|
||||
@@ -234,6 +269,11 @@ workflows:
|
||||
filters:
|
||||
branches:
|
||||
ignore: /.*/
|
||||
# Testing tags are reserved for testing circle test + build steps
|
||||
tags:
|
||||
ignore: /^testing-.*/
|
||||
- publish_docs:
|
||||
filters:
|
||||
branches:
|
||||
ignore: /.*/
|
||||
tags:
|
||||
ignore: /^testing-.*/
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
# The action uses an own Dockerfile on purpose because the root Dockerfile takes way too long to build for an action
|
||||
|
||||
FROM alpine:3.10
|
||||
|
||||
RUN apk add --no-cache \
|
||||
bash \
|
||||
ca-certificates \
|
||||
curl \
|
||||
wget \
|
||||
tar \
|
||||
jq
|
||||
|
||||
COPY get_polaris.sh /get_polaris.sh
|
||||
|
||||
ENTRYPOINT ["/get_polaris.sh"]
|
||||
@@ -0,0 +1,22 @@
|
||||
name: 'Install polaris'
|
||||
description: 'Download a specific polaris version'
|
||||
|
||||
inputs:
|
||||
version:
|
||||
description: 'version of polaris'
|
||||
required: true
|
||||
default: 'latest'
|
||||
|
||||
runs:
|
||||
using: 'docker'
|
||||
image: './Dockerfile'
|
||||
args:
|
||||
- ${{ inputs.version }}
|
||||
|
||||
outputs:
|
||||
version:
|
||||
description: 'Version of polaris installed'
|
||||
|
||||
branding:
|
||||
icon: 'download-cloud'
|
||||
color: 'gray-dark'
|
||||
@@ -0,0 +1,20 @@
|
||||
#!/bin/bash
|
||||
if [[ -z "$INPUT_VERSION" ]]; then
|
||||
echo "Missing polaris version information"
|
||||
exit 1
|
||||
fi
|
||||
POLARIS_URL=https://github.com/FairwindsOps/polaris/releases/download/$INPUT_VERSION/polaris_linux_amd64.tar.gz
|
||||
polaris version | grep "$INPUT_VERSION" &> /dev/null
|
||||
if [ $? == 0 ]; then
|
||||
echo "Polaris $INPUT_VERSION is already installed! Exiting gracefully."
|
||||
exit 0
|
||||
else
|
||||
echo "Installing polaris to path from " $POLARIS_URL
|
||||
fi
|
||||
TARGET_FILE="polaris.tar.gz"
|
||||
curl -LJ -o $TARGET_FILE $POLARIS_URL
|
||||
mkdir polaris
|
||||
tar -xzf $TARGET_FILE -C polaris
|
||||
rm $TARGET_FILE
|
||||
echo "polaris" >> $GITHUB_PATH
|
||||
echo "::set-output name=version::$INPUT_VERSION"
|
||||
@@ -0,0 +1,44 @@
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: gomod
|
||||
directory: "/"
|
||||
schedule:
|
||||
interval: weekly
|
||||
time: "11:00"
|
||||
ignore:
|
||||
- dependency-name: cloud.google.com/go
|
||||
versions:
|
||||
- ">= 0.57.a, < 0.58"
|
||||
- dependency-name: github.com/go-logr/logr
|
||||
versions:
|
||||
- ">= 0.2.a, < 0.3"
|
||||
- dependency-name: github.com/go-logr/zapr
|
||||
versions:
|
||||
- ">= 0.2.a, < 0.3"
|
||||
- dependency-name: github.com/googleapis/gnostic
|
||||
versions:
|
||||
- ">= 0.4.a, < 0.5"
|
||||
- dependency-name: github.com/googleapis/gnostic
|
||||
versions:
|
||||
- ">= 0.5.a, < 0.6"
|
||||
- dependency-name: github.com/qri-io/jsonschema
|
||||
versions:
|
||||
- ">= 0.2.a, < 0.3"
|
||||
- dependency-name: k8s.io/api
|
||||
versions:
|
||||
- ">= 0.19.a, < 0.20"
|
||||
- dependency-name: k8s.io/apimachinery
|
||||
versions:
|
||||
- ">= 0.19.a, < 0.20"
|
||||
- dependency-name: k8s.io/client-go
|
||||
versions:
|
||||
- ">= 0.19.a, < 0.20"
|
||||
- dependency-name: sigs.k8s.io/controller-runtime
|
||||
versions:
|
||||
- ">= 0.5.a, < 0.6"
|
||||
- dependency-name: sigs.k8s.io/controller-runtime
|
||||
versions:
|
||||
- ">= 0.8.a, < 0.9"
|
||||
- dependency-name: k8s.io/apimachinery
|
||||
versions:
|
||||
- 0.20.4
|
||||
@@ -0,0 +1,18 @@
|
||||
daysUntilStale: 30
|
||||
daysUntilClose: 7
|
||||
onlyLabels: []
|
||||
exemptLabels:
|
||||
- pinned
|
||||
- security
|
||||
|
||||
exemptProjects: false
|
||||
exemptMilestones: true
|
||||
exemptAssignees: false
|
||||
staleLabel: stale
|
||||
|
||||
markComment: >
|
||||
This issue has been automatically marked as stale because it has not had
|
||||
recent activity. It will be closed if no further activity occurs. Thank you
|
||||
for your contributions.
|
||||
|
||||
limitPerRun: 30
|
||||
@@ -1,40 +0,0 @@
|
||||
# This file is generated from FairwindsOps/documentation-template
|
||||
# DO NOT EDIT MANUALLY
|
||||
|
||||
name: Build Website
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ master ]
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
node-version: [14.x]
|
||||
defaults:
|
||||
run:
|
||||
working-directory: ./docs-md
|
||||
env:
|
||||
CI: true
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v2
|
||||
- name: Use Node.js ${{ matrix.node-version }}
|
||||
uses: actions/setup-node@v1
|
||||
with:
|
||||
node-version: ${{ matrix.node-version }}
|
||||
- run: npm ci
|
||||
- name: Build site
|
||||
run: npm run build
|
||||
- name: Check links
|
||||
run: npm run check-links
|
||||
- name: Push changes
|
||||
run: |
|
||||
username="GitHub Actions"
|
||||
git config user.email "opensource@fairwinds.com"
|
||||
git config user.name $username
|
||||
git add ../docs/
|
||||
git commit -m "[CI] rebuild website"
|
||||
git push -u origin +master:website
|
||||
@@ -0,0 +1,27 @@
|
||||
name: Test setup-polaris
|
||||
on:
|
||||
pull_request:
|
||||
branches: [ master ]
|
||||
|
||||
jobs:
|
||||
build-int:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v2
|
||||
- name: Setup polaris
|
||||
uses: ./.github/actions/setup-polaris
|
||||
with:
|
||||
version: 4.2.0
|
||||
- name: Use command
|
||||
run: polaris version
|
||||
|
||||
build-ext:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v2
|
||||
- name: Setup polaris
|
||||
uses: fairwindsops/polaris/.github/actions/setup-polaris@master
|
||||
with:
|
||||
version: 4.2.0
|
||||
- name: Use command
|
||||
run: polaris version
|
||||
@@ -26,3 +26,4 @@ dist
|
||||
*-test.yaml
|
||||
|
||||
node_modules
|
||||
/dist
|
||||
|
||||
@@ -7,21 +7,28 @@ changelog:
|
||||
- '^docs:'
|
||||
- '^test:'
|
||||
builds:
|
||||
- id: watcher
|
||||
- id: polaris
|
||||
env:
|
||||
- CGO_ENABLED=0
|
||||
- GO111MODULE=on
|
||||
goos:
|
||||
- linux
|
||||
- darwin
|
||||
- windows
|
||||
goarch:
|
||||
- amd64
|
||||
- arm
|
||||
- arm64
|
||||
- 386
|
||||
goarm:
|
||||
- 6
|
||||
- 7
|
||||
archives:
|
||||
- id: polaris
|
||||
builds: ["polaris"]
|
||||
name_template: "{{ .ProjectName }}_{{ .Os }}_{{ .Arch }}{{ if .Arm }}v{{ .Arm }}{{ end }}{{ if .Mips }}_{{ .Mips }}{{ end }}"
|
||||
brews:
|
||||
- name: polaris
|
||||
github:
|
||||
tap:
|
||||
owner: FairwindsOps
|
||||
name: homebrew-tap
|
||||
folder: Formula
|
||||
|
||||
@@ -1 +1 @@
|
||||
* @rbren @makoscafee @jordandoig @baderbuddy @shaswa
|
||||
* @rbren @makoscafee
|
||||
@@ -0,0 +1,74 @@
|
||||
# Contributor Covenant Code of Conduct
|
||||
|
||||
## Our Pledge
|
||||
|
||||
In the interest of fostering an open and welcoming environment, we as
|
||||
contributors and maintainers pledge to making participation in our project and
|
||||
our community a harassment-free experience for everyone, regardless of age, body
|
||||
size, disability, ethnicity, gender identity and expression, level of experience,
|
||||
nationality, personal appearance, race, religion, or sexual identity and
|
||||
orientation.
|
||||
|
||||
## Our Standards
|
||||
|
||||
Examples of behavior that contributes to creating a positive environment
|
||||
include:
|
||||
|
||||
* Using welcoming and inclusive language
|
||||
* Being respectful of differing viewpoints and experiences
|
||||
* Gracefully accepting constructive criticism
|
||||
* Focusing on what is best for the community
|
||||
* Showing empathy towards other community members
|
||||
|
||||
Examples of unacceptable behavior by participants include:
|
||||
|
||||
* The use of sexualized language or imagery and unwelcome sexual attention or
|
||||
advances
|
||||
* Trolling, insulting/derogatory comments, and personal or political attacks
|
||||
* Public or private harassment
|
||||
* Publishing others' private information, such as a physical or electronic
|
||||
address, without explicit permission
|
||||
* Other conduct which could reasonably be considered inappropriate in a
|
||||
professional setting
|
||||
|
||||
## Our Responsibilities
|
||||
|
||||
Project maintainers are responsible for clarifying the standards of acceptable
|
||||
behavior and are expected to take appropriate and fair corrective action in
|
||||
response to any instances of unacceptable behavior.
|
||||
|
||||
Project maintainers have the right and responsibility to remove, edit, or
|
||||
reject comments, commits, code, wiki edits, issues, and other contributions
|
||||
that are not aligned to this Code of Conduct, or to ban temporarily or
|
||||
permanently any contributor for other behaviors that they deem inappropriate,
|
||||
threatening, offensive, or harmful.
|
||||
|
||||
## Scope
|
||||
|
||||
This Code of Conduct applies both within project spaces and in public spaces
|
||||
when an individual is representing the project or its community. Examples of
|
||||
representing a project or community include using an official project e-mail
|
||||
address, posting via an official social media account, or acting as an appointed
|
||||
representative at an online or offline event. Representation of a project may be
|
||||
further defined and clarified by project maintainers.
|
||||
|
||||
## Enforcement
|
||||
|
||||
Instances of abusive, harassing, or otherwise unacceptable behavior may be
|
||||
reported by contacting the project team at opensource@fairwinds.com. All
|
||||
complaints will be reviewed and investigated and will result in a response that
|
||||
is deemed necessary and appropriate to the circumstances. The project team is
|
||||
obligated to maintain confidentiality with regard to the reporter of an incident.
|
||||
Further details of specific enforcement policies may be posted separately.
|
||||
|
||||
Project maintainers who do not follow or enforce the Code of Conduct in good
|
||||
faith may face temporary or permanent repercussions as determined by other
|
||||
members of the project's leadership.
|
||||
|
||||
## Attribution
|
||||
|
||||
This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4,
|
||||
available at [http://contributor-covenant.org/version/1/4][version]
|
||||
|
||||
[homepage]: http://contributor-covenant.org
|
||||
[version]: http://contributor-covenant.org/version/1/4/
|
||||
@@ -1,4 +1,4 @@
|
||||
FROM golang:1.13 AS build-env
|
||||
FROM golang:1.16 AS build-env
|
||||
WORKDIR /go/src/github.com/fairwindsops/polaris/
|
||||
|
||||
ENV GO111MODULE=on
|
||||
@@ -15,7 +15,7 @@ RUN go get -u github.com/gobuffalo/packr/v2/packr2
|
||||
COPY . .
|
||||
RUN packr2 build -a -o polaris *.go
|
||||
|
||||
FROM alpine:3.10
|
||||
FROM alpine:3.14
|
||||
WORKDIR /usr/local/bin
|
||||
RUN apk --no-cache add ca-certificates
|
||||
|
||||
|
||||
@@ -3,19 +3,22 @@
|
||||
<br>
|
||||
<h3>Best Practices for Kubernetes Workload Configuration</h3>
|
||||
<a href="https://github.com/FairwindsOps/polaris">
|
||||
<img src="https://img.shields.io/static/v1.svg?label=Version&message=3.0.0&color=239922">
|
||||
<img src="https://img.shields.io/static/v1.svg?label=Version&message=4.2.0&color=239922">
|
||||
</a>
|
||||
<a href="https://goreportcard.com/report/github.com/FairwindsOps/polaris">
|
||||
<img src="https://goreportcard.com/badge/github.com/FairwindsOps/polaris">
|
||||
</a>
|
||||
<a href="https://circleci.com/gh/FairwindsOps/polaris.svg">
|
||||
<a href="https://circleci.com/gh/FairwindsOps/polaris">
|
||||
<img src="https://circleci.com/gh/FairwindsOps/polaris.svg?style=svg">
|
||||
</a>
|
||||
<a href="https://insights.fairwinds.com/gh/FairwindsOps/polaris">
|
||||
<img src="https://insights.fairwinds.com/v0/gh/FairwindsOps/polaris/badge.svg">
|
||||
</a>
|
||||
</div>
|
||||
|
||||
Fairwinds' Polaris keeps your clusters sailing smoothly. It runs a variety of checks to ensure that
|
||||
Kubernetes pods and controllers are configured using best practices, helping you avoid
|
||||
problems in the future. Polaris can be run in a few different modes:
|
||||
problems in the future.
|
||||
|
||||
Polaris can be run in three different modes:
|
||||
* As a [dashboard](https://polaris.docs.fairwinds.com/dashboard), so you can audit what's running inside your cluster.
|
||||
@@ -26,41 +29,38 @@ Polaris can be run in three different modes:
|
||||
<img src="https://polaris.docs.fairwinds.com/img/architecture.svg" alt="Polaris Architecture" width="550"/>
|
||||
</p>
|
||||
|
||||
**Want to learn more?** Reach out on [the Slack channel](https://fairwindscommunity.slack.com/messages/polaris) ([request invite](https://join.slack.com/t/fairwindscommunity/shared_invite/zt-e3c6vj4l-3lIH6dvKqzWII5fSSFDi1g)), send an email to `opensource@fairwinds.com`, or join us for [office hours on Zoom](https://fairwindscommunity.slack.com/messages/office-hours)
|
||||
|
||||
|
||||
## Documentation
|
||||
Check out the [documentation at docs.fairwinds.com](https://polaris.docs.fairwinds.com)
|
||||
|
||||
## Integration with Fairwinds Insights
|
||||
<p align="center">
|
||||
<img src="https://polaris.docs.fairwinds.com/img/FW_Insights_Polaris.svg" alt="Fairwinds Insights" width="550"/>
|
||||
</p>
|
||||
<!-- Begin boilerplate -->
|
||||
## Join the Fairwinds Open Source Community
|
||||
|
||||
[Fairwinds Insights](https://www.fairwinds.com/fairwinds-polaris-upgrade)
|
||||
is a platform for auditing Kubernetes clusters and enforcing policy. If you'd like to:
|
||||
* manage Polaris across a fleet of clusters
|
||||
* track findings over time
|
||||
* send results to services like Slack and Datadog
|
||||
* add additional checks from tools like
|
||||
[Trivy](https://github.com/aquasecurity/trivy),
|
||||
[Goldilocks](https://github.com/FairwindsOps/goldilocks/), and
|
||||
[OPA](https://www.openpolicyagent.org)
|
||||
The goal of the Fairwinds Community is to exchange ideas, influence the open source roadmap,
|
||||
and network with fellow Kubernetes users.
|
||||
[Chat with us on Slack](https://join.slack.com/t/fairwindscommunity/shared_invite/zt-e3c6vj4l-3lIH6dvKqzWII5fSSFDi1g)
|
||||
or
|
||||
[join the user group](https://www.fairwinds.com/open-source-software-user-group) to get involved!
|
||||
|
||||
you can sign up for a [free account here](https://insights.fairwinds.com?source=polaris).
|
||||
<a href="https://www.fairwinds.com/t-shirt-offer?utm_source=polaris&utm_medium=polaris&utm_campaign=polaris-tshirt">
|
||||
<img src="https://www.fairwinds.com/hubfs/Doc_Banners/Fairwinds_OSS_User_Group_740x125_v6.png" alt="Love Fairwinds Open Source? Share your business email and job title and we'll send you a free Fairwinds t-shirt!" />
|
||||
</a>
|
||||
|
||||
## Contributing
|
||||
PRs welcome! Check out the [Contributing Guidelines](https://polaris.docs.fairwinds.com/contributing) and [Code of Conduct](https://polaris.docs.fairwinds.com/code-of-conduct) for more information.
|
||||
## Other Projects from Fairwinds
|
||||
|
||||
## Further Information
|
||||
A history of changes to this project can be viewed in the [Changelog](https://polaris.docs.fairwinds.com/changelog)
|
||||
Enjoying Polaris? Check out some of our other projects:
|
||||
* [Goldilocks](https://github.com/FairwindsOps/Goldilocks) - Right-size your Kubernetes Deployments by compare your memory and CPU settings against actual usage
|
||||
* [Pluto](https://github.com/FairwindsOps/Pluto) - Detect Kubernetes resources that have been deprecated or removed in future versions
|
||||
* [Nova](https://github.com/FairwindsOps/Nova) - Check to see if any of your Helm charts have updates available
|
||||
* [rbac-manager](https://github.com/FairwindsOps/rbac-manager) - Simplify the management of RBAC in your Kubernetes clusters
|
||||
|
||||
If you'd like to learn more about Polaris, or if you'd like to speak with
|
||||
a Kubernetes expert, you can contact `info@fairwinds.com` or [visit our website](https://fairwinds.com)
|
||||
|
||||
---
|
||||
|
||||
<p align="center">
|
||||
<img src="https://polaris.docs.fairwinds.com/img/dashboard-screenshot.png" alt="Polaris Dashboard" width="550"/>
|
||||
</p>
|
||||
Or [check out the full list](https://www.fairwinds.com/open-source-software?utm_source=polaris&utm_medium=polaris&utm_campaign=polaris)
|
||||
## Fairwinds Insights
|
||||
If you're interested in running Polaris in multiple clusters,
|
||||
tracking the results over time, integrating with Slack, Datadog, and Jira,
|
||||
or unlocking other functionality, check out
|
||||
[Fairwinds Insights](https://www.fairwinds.com/polaris-user-insights-demo?utm_source=polaris&utm_medium=polaris&utm_campaign=polaris),
|
||||
a platform for auditing and enforcing policy in Kubernetes clusters.
|
||||
|
||||
<a href="https://www.fairwinds.com/polaris-user-insights-demo?utm_source=polaris&utm_medium=ad&utm_campaign=polarisad">
|
||||
<img src="https://www.fairwinds.com/hubfs/Doc_Banners/Fairwinds_Polaris_Ad.png" alt="Fairwinds Insights" />
|
||||
</a>
|
||||
|
||||
@@ -14,12 +14,13 @@ schema:
|
||||
properties:
|
||||
add:
|
||||
type: array
|
||||
not:
|
||||
contains:
|
||||
const: ALL
|
||||
not:
|
||||
contains:
|
||||
const: SYS_ADMIN
|
||||
not:
|
||||
contains:
|
||||
const: NET_ADMIN
|
||||
allOf:
|
||||
- not:
|
||||
contains:
|
||||
pattern: '^(?i)ALL$'
|
||||
- not:
|
||||
contains:
|
||||
pattern: '^(?i)SYS_ADMIN$'
|
||||
- not:
|
||||
contains:
|
||||
pattern: '^(?i)NET_ADMIN$'
|
||||
|
||||
@@ -5,27 +5,52 @@ target: Container
|
||||
schema:
|
||||
'$schema': http://json-schema.org/draft-07/schema
|
||||
type: object
|
||||
required:
|
||||
- securityContext
|
||||
properties:
|
||||
securityContext:
|
||||
type: object
|
||||
required:
|
||||
- capabilities
|
||||
properties:
|
||||
capabilities:
|
||||
type: object
|
||||
required:
|
||||
- drop
|
||||
properties:
|
||||
add:
|
||||
enum:
|
||||
- CHOWN
|
||||
- DAC_OVERRIDE
|
||||
- FSETID
|
||||
- FOWNER
|
||||
- MKNOD
|
||||
- NET_RAW
|
||||
- SETGID
|
||||
- SETUID
|
||||
- SETFCAP
|
||||
- SETPCAP
|
||||
- NET_BIND_SERVICE
|
||||
- SYS_CHROOT
|
||||
- KILL
|
||||
- AUDIT_WRITE
|
||||
|
||||
drop:
|
||||
type: array
|
||||
oneOf:
|
||||
- contains:
|
||||
pattern: '^(?i)ALL$'
|
||||
- allOf:
|
||||
- contains:
|
||||
pattern: '^(?i)NET_ADMIN$'
|
||||
- contains:
|
||||
pattern: '^(?i)CHOWN$'
|
||||
- contains:
|
||||
pattern: '^(?i)DAC_OVERRIDE$'
|
||||
- contains:
|
||||
pattern: '^(?i)FSETID$'
|
||||
- contains:
|
||||
pattern: '^(?i)FOWNER$'
|
||||
- contains:
|
||||
pattern: '^(?i)MKNOD$'
|
||||
- contains:
|
||||
pattern: '^(?i)NET_RAW$'
|
||||
- contains:
|
||||
pattern: '^(?i)SETGID$'
|
||||
- contains:
|
||||
pattern: '^(?i)SETUID$'
|
||||
- contains:
|
||||
pattern: '^(?i)SETFCAP$'
|
||||
- contains:
|
||||
pattern: '^(?i)SETPCAP$'
|
||||
- contains:
|
||||
pattern: '^(?i)NET_BIND_SERVICE$'
|
||||
- contains:
|
||||
pattern: '^(?i)SYS_CHROOT$'
|
||||
- contains:
|
||||
pattern: '^(?i)KILL$'
|
||||
- contains:
|
||||
pattern: '^(?i)AUDIT_WRITE$'
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
successMessage: Label app.kubernetes.io/name matches metadata.name
|
||||
failureMessage: Label app.kubernetes.io/name must match metadata.name
|
||||
target: Controller
|
||||
schema:
|
||||
'$schema': http://json-schema.org/draft-07/schema
|
||||
type: object
|
||||
properties:
|
||||
metadata:
|
||||
type: object
|
||||
required: ["labels"]
|
||||
properties:
|
||||
labels:
|
||||
type: object
|
||||
required: ["app.kubernetes.io/name"]
|
||||
properties:
|
||||
app.kubernetes.io/name:
|
||||
const: "{{ .metadata.name }}"
|
||||
@@ -0,0 +1,39 @@
|
||||
successMessage: A PodDisruptionBudget is attached
|
||||
failureMessage: Should have a PodDisruptionBudget
|
||||
category: Reliability
|
||||
target: Controller
|
||||
controllers:
|
||||
include:
|
||||
- Deployment
|
||||
schema:
|
||||
'$schema': http://json-schema.org/draft-07/schema
|
||||
type: object
|
||||
properties:
|
||||
metadata:
|
||||
type: object
|
||||
properties:
|
||||
labels:
|
||||
type: object
|
||||
minProperties: 1
|
||||
additionalSchemaStrings:
|
||||
policy/PodDisruptionBudget: |
|
||||
type: object
|
||||
properties:
|
||||
spec:
|
||||
type: object
|
||||
required: ["selector"]
|
||||
properties:
|
||||
selector:
|
||||
type: object
|
||||
required: ["matchLabels"]
|
||||
properties:
|
||||
matchLabels:
|
||||
type: object
|
||||
anyOf:
|
||||
{{ range $key, $value := .metadata.labels }}
|
||||
- properties:
|
||||
"{{ $key }}":
|
||||
type: string
|
||||
const: {{ $value }}
|
||||
required: ["{{ $key }}"]
|
||||
{{ end }}
|
||||
@@ -2,15 +2,42 @@ successMessage: Filesystem is read only
|
||||
failureMessage: Filesystem should be read only
|
||||
category: Security
|
||||
target: Container
|
||||
schemaTarget: Pod
|
||||
schema:
|
||||
'$schema': http://json-schema.org/draft-07/schema
|
||||
type: object
|
||||
required:
|
||||
- securityContext
|
||||
properties:
|
||||
securityContext:
|
||||
required:
|
||||
- readOnlyRootFilesystem
|
||||
definitions:
|
||||
goodSecurityContext:
|
||||
type: object
|
||||
anyOf:
|
||||
- required:
|
||||
- readOnlyRootFilesystem
|
||||
properties:
|
||||
readOnlyRootFilesystem:
|
||||
const: true
|
||||
notBadSecurityContext:
|
||||
type: object
|
||||
properties:
|
||||
readOnlyRootFilesystem:
|
||||
const: true
|
||||
type: object
|
||||
anyOf:
|
||||
- required:
|
||||
- securityContext
|
||||
properties:
|
||||
securityContext:
|
||||
$ref: "#/definitions/goodSecurityContext"
|
||||
containers:
|
||||
type: array
|
||||
items:
|
||||
properties:
|
||||
securityContext:
|
||||
$ref: "#/definitions/notBadSecurityContext"
|
||||
- properties:
|
||||
containers:
|
||||
type: array
|
||||
items:
|
||||
required:
|
||||
- securityContext
|
||||
properties:
|
||||
securityContext:
|
||||
$ref: "#/definitions/goodSecurityContext"
|
||||
@@ -0,0 +1,22 @@
|
||||
successMessage: Voluntary evictions are possible
|
||||
failureMessage: Voluntary evictions are not possible
|
||||
category: Reliability
|
||||
target: policy/PodDisruptionBudget
|
||||
schema:
|
||||
'$schema': http://json-schema.org/draft-07/schema
|
||||
type: object
|
||||
required:
|
||||
- spec
|
||||
properties:
|
||||
spec:
|
||||
type: object
|
||||
properties:
|
||||
minAvailable:
|
||||
not:
|
||||
const: '100%'
|
||||
maxUnavailable:
|
||||
allOf:
|
||||
- not:
|
||||
const: 0
|
||||
- not:
|
||||
const: '0%'
|
||||
@@ -2,12 +2,42 @@ successMessage: Privilege escalation not allowed
|
||||
failureMessage: Privilege escalation should not be allowed
|
||||
category: Security
|
||||
target: Container
|
||||
schemaTarget: Pod
|
||||
schema:
|
||||
'$schema': http://json-schema.org/draft-07/schema
|
||||
type: object
|
||||
properties:
|
||||
securityContext:
|
||||
definitions:
|
||||
goodSecurityContext:
|
||||
type: object
|
||||
anyOf:
|
||||
- required:
|
||||
- allowPrivilegeEscalation
|
||||
properties:
|
||||
allowPrivilegeEscalation:
|
||||
const: false
|
||||
notBadSecurityContext:
|
||||
type: object
|
||||
properties:
|
||||
allowPrivilegeEscalation:
|
||||
not:
|
||||
const: true
|
||||
const: false
|
||||
type: object
|
||||
anyOf:
|
||||
- required:
|
||||
- securityContext
|
||||
properties:
|
||||
securityContext:
|
||||
$ref: "#/definitions/goodSecurityContext"
|
||||
containers:
|
||||
type: array
|
||||
items:
|
||||
properties:
|
||||
securityContext:
|
||||
$ref: "#/definitions/notBadSecurityContext"
|
||||
- properties:
|
||||
containers:
|
||||
type: array
|
||||
items:
|
||||
required:
|
||||
- securityContext
|
||||
properties:
|
||||
securityContext:
|
||||
$ref: "#/definitions/goodSecurityContext"
|
||||
@@ -2,12 +2,23 @@ successMessage: Not running as privileged
|
||||
failureMessage: Should not be running as privileged
|
||||
category: Security
|
||||
target: Container
|
||||
schemaTarget: Pod
|
||||
schema:
|
||||
'$schema': http://json-schema.org/draft-07/schema
|
||||
type: object
|
||||
properties:
|
||||
securityContext:
|
||||
definitions:
|
||||
notBadSecurityContext:
|
||||
type: object
|
||||
properties:
|
||||
privileged:
|
||||
not:
|
||||
const: true
|
||||
type: object
|
||||
properties:
|
||||
securityContext:
|
||||
$ref: "#/definitions/notBadSecurityContext"
|
||||
containers:
|
||||
type: array
|
||||
items:
|
||||
properties:
|
||||
securityContext:
|
||||
$ref: "#/definitions/notBadSecurityContext"
|
||||
@@ -1,7 +1,7 @@
|
||||
successMessage: Ingress has TLS configured
|
||||
failureMessage: Ingress does not have TLS configured
|
||||
category: Security
|
||||
target: Ingress
|
||||
target: networking.k8s.io/Ingress
|
||||
schema:
|
||||
'$schema': http://json-schema.org/draft-07/schema
|
||||
type: object
|
||||
|
||||
@@ -22,8 +22,8 @@ import (
|
||||
"io/ioutil"
|
||||
"net/http"
|
||||
"os"
|
||||
"os/exec"
|
||||
|
||||
conf "github.com/fairwindsops/polaris/pkg/config"
|
||||
"github.com/fairwindsops/polaris/pkg/kube"
|
||||
"github.com/fairwindsops/polaris/pkg/validator"
|
||||
"github.com/sirupsen/logrus"
|
||||
@@ -32,22 +32,30 @@ import (
|
||||
)
|
||||
|
||||
var setExitCode bool
|
||||
var onlyShowFailedTests bool
|
||||
var minScore int
|
||||
var auditOutputURL string
|
||||
var auditOutputFile string
|
||||
var auditOutputFormat string
|
||||
var resourceToAudit string
|
||||
var useColor bool
|
||||
var helmChart string
|
||||
var helmValues string
|
||||
|
||||
func init() {
|
||||
rootCmd.AddCommand(auditCmd)
|
||||
auditCmd.PersistentFlags().StringVar(&auditPath, "audit-path", "", "If specified, audits one or more YAML files instead of a cluster.")
|
||||
auditCmd.PersistentFlags().BoolVar(&setExitCode, "set-exit-code-on-danger", false, "Set an exit code of 3 when the audit contains danger-level issues.")
|
||||
auditCmd.PersistentFlags().BoolVar(&onlyShowFailedTests, "only-show-failed-tests", false, "If specified, audit output will only show failed tests.")
|
||||
auditCmd.PersistentFlags().IntVar(&minScore, "set-exit-code-below-score", 0, "Set an exit code of 4 when the score is below this threshold (1-100).")
|
||||
auditCmd.PersistentFlags().StringVar(&auditOutputURL, "output-url", "", "Destination URL to send audit results.")
|
||||
auditCmd.PersistentFlags().StringVar(&auditOutputFile, "output-file", "", "Destination file for audit results.")
|
||||
auditCmd.PersistentFlags().StringVarP(&auditOutputFormat, "format", "f", "json", "Output format for results - json, yaml, or score.")
|
||||
auditCmd.PersistentFlags().StringVarP(&auditOutputFormat, "format", "f", "json", "Output format for results - json, yaml, pretty, or score.")
|
||||
auditCmd.PersistentFlags().BoolVar(&useColor, "color", true, "Whether to use color in pretty format.")
|
||||
auditCmd.PersistentFlags().StringVar(&displayName, "display-name", "", "An optional identifier for the audit.")
|
||||
auditCmd.PersistentFlags().StringVar(&resourceToAudit, "resource", "", "Audit a specific resource, in the format namespace/kind/version/name, e.g. nginx-ingress/Deployment.apps/v1/default-backend.")
|
||||
auditCmd.PersistentFlags().StringVar(&helmChart, "helm-chart", "", "Will fill out Helm template")
|
||||
auditCmd.PersistentFlags().StringVar(&helmValues, "helm-values", "", "Optional flag to add helm values")
|
||||
}
|
||||
|
||||
var auditCmd = &cobra.Command{
|
||||
@@ -58,8 +66,28 @@ var auditCmd = &cobra.Command{
|
||||
if displayName != "" {
|
||||
config.DisplayName = displayName
|
||||
}
|
||||
if helmChart != "" {
|
||||
var err error
|
||||
auditPath, err = ProcessHelmTemplates(helmChart, helmValues)
|
||||
if err != nil {
|
||||
logrus.Infof("Couldn't process helm chart: %v", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
}
|
||||
|
||||
auditData := runAndReportAudit(cmd.Context(), config, auditPath, resourceToAudit, auditOutputFile, auditOutputURL, auditOutputFormat)
|
||||
k, err := kube.CreateResourceProvider(context.TODO(), auditPath, resourceToAudit, config)
|
||||
if err != nil {
|
||||
logrus.Errorf("Error fetching Kubernetes resources %v", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
|
||||
auditData, err := validator.RunAudit(config, k)
|
||||
if err != nil {
|
||||
logrus.Errorf("Error while running audit on resources: %v", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
|
||||
outputAudit(auditData, auditOutputFile, auditOutputURL, auditOutputFormat, useColor, onlyShowFailedTests)
|
||||
|
||||
summary := auditData.GetSummary()
|
||||
score := summary.GetScore()
|
||||
@@ -73,29 +101,55 @@ var auditCmd = &cobra.Command{
|
||||
},
|
||||
}
|
||||
|
||||
func runAndReportAudit(ctx context.Context, c conf.Configuration, auditPath, workload, outputFile, outputURL, outputFormat string) validator.AuditData {
|
||||
// Create a kubernetes client resource provider
|
||||
k, err := kube.CreateResourceProvider(ctx, auditPath, workload)
|
||||
// ProcessHelmTemplates turns helm into yaml to be processed by Polaris or the other tools.
|
||||
func ProcessHelmTemplates(helmChart, helmValues string) (string, error) {
|
||||
cmd := exec.Command("helm", "dependency", "update", helmChart)
|
||||
output, err := cmd.CombinedOutput()
|
||||
if err != nil {
|
||||
logrus.Errorf("Error fetching Kubernetes resources %v", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
var auditData validator.AuditData
|
||||
auditData, err = validator.RunAudit(c, k)
|
||||
|
||||
if err != nil {
|
||||
logrus.Errorf("Error while running audit on resources: %v", err)
|
||||
os.Exit(1)
|
||||
logrus.Error(string(output))
|
||||
return "", err
|
||||
}
|
||||
|
||||
dir, err := ioutil.TempDir("", "*")
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
params := []string{
|
||||
"template", helmChart,
|
||||
helmChart,
|
||||
"--output-dir",
|
||||
dir,
|
||||
}
|
||||
if helmValues != "" {
|
||||
params = append(params, "--values", helmValues)
|
||||
}
|
||||
|
||||
cmd = exec.Command("helm", params...)
|
||||
output, err = cmd.CombinedOutput()
|
||||
|
||||
if err != nil {
|
||||
logrus.Error(string(output))
|
||||
return "", err
|
||||
}
|
||||
return dir, nil
|
||||
}
|
||||
|
||||
func outputAudit(auditData validator.AuditData, outputFile, outputURL, outputFormat string, useColor bool, onlyShowFailedTests bool) {
|
||||
if onlyShowFailedTests {
|
||||
auditData = auditData.RemoveSuccessfulResults()
|
||||
}
|
||||
var outputBytes []byte
|
||||
var err error
|
||||
if outputFormat == "score" {
|
||||
outputBytes = []byte(fmt.Sprintf("%d\n", auditData.GetSummary().GetScore()))
|
||||
} else if outputFormat == "yaml" {
|
||||
jsonBytes, err := json.Marshal(auditData)
|
||||
var jsonBytes []byte
|
||||
jsonBytes, err = json.Marshal(auditData)
|
||||
if err == nil {
|
||||
outputBytes, err = yaml.JSONToYAML(jsonBytes)
|
||||
}
|
||||
} else if outputFormat == "pretty" {
|
||||
outputBytes = []byte(auditData.GetPrettyOutput(useColor))
|
||||
} else {
|
||||
outputBytes, err = json.MarshalIndent(auditData, "", " ")
|
||||
}
|
||||
@@ -149,5 +203,4 @@ func runAndReportAudit(ctx context.Context, c conf.Configuration, auditPath, wor
|
||||
}
|
||||
}
|
||||
}
|
||||
return auditData
|
||||
}
|
||||
|
||||
@@ -27,10 +27,12 @@ import (
|
||||
var serverPort int
|
||||
var basePath string
|
||||
var loadAuditFile string
|
||||
var listeningAddress string
|
||||
|
||||
func init() {
|
||||
rootCmd.AddCommand(dashboardCmd)
|
||||
dashboardCmd.PersistentFlags().IntVarP(&serverPort, "port", "p", 8080, "Port for the dashboard webserver.")
|
||||
dashboardCmd.PersistentFlags().StringVar(&listeningAddress, "listening-address", "", "Listening Address for the dashboard webserver.")
|
||||
dashboardCmd.PersistentFlags().StringVar(&basePath, "base-path", "/", "Path on which the dashboard is served.")
|
||||
dashboardCmd.PersistentFlags().StringVar(&loadAuditFile, "load-audit-file", "", "Runs the dashboard with data saved from a past audit.")
|
||||
dashboardCmd.PersistentFlags().StringVar(&auditPath, "audit-path", "", "If specified, audits one or more YAML files instead of a cluster.")
|
||||
@@ -59,6 +61,6 @@ var dashboardCmd = &cobra.Command{
|
||||
http.Handle("/", router)
|
||||
|
||||
logrus.Infof("Starting Polaris dashboard server on port %d", serverPort)
|
||||
logrus.Fatal(http.ListenAndServe(fmt.Sprintf(":%d", serverPort), nil))
|
||||
logrus.Fatal(http.ListenAndServe(fmt.Sprintf("%s:%d", listeningAddress, serverPort), nil))
|
||||
},
|
||||
}
|
||||
|
||||
@@ -25,7 +25,7 @@ import (
|
||||
)
|
||||
|
||||
var configPath string
|
||||
var disallowExemptions bool
|
||||
var disallowExemptions, disallowConfigExemptions, disallowAnnotationExemptions bool
|
||||
var logLevel string
|
||||
var auditPath string
|
||||
var displayName string
|
||||
@@ -37,7 +37,9 @@ var (
|
||||
func init() {
|
||||
// Flags
|
||||
rootCmd.PersistentFlags().StringVarP(&configPath, "config", "c", "", "Location of Polaris configuration file.")
|
||||
rootCmd.PersistentFlags().BoolVarP(&disallowExemptions, "disallow-exemptions", "", false, "Disallow any exemptions from configuration file.")
|
||||
rootCmd.PersistentFlags().BoolVarP(&disallowExemptions, "disallow-exemptions", "", false, "Disallow any configured exemption.")
|
||||
rootCmd.PersistentFlags().BoolVarP(&disallowConfigExemptions, "disallow-config-exemptions", "", false, "Disallow exemptions set within the configuration file.")
|
||||
rootCmd.PersistentFlags().BoolVarP(&disallowAnnotationExemptions, "disallow-annotation-exemptions", "", false, "Disallow any exemption defined as a controller annotation.")
|
||||
rootCmd.PersistentFlags().StringVarP(&logLevel, "log-level", "", logrus.InfoLevel.String(), "Logrus log level.")
|
||||
flag.Parse()
|
||||
pflag.CommandLine.AddGoFlagSet(flag.CommandLine)
|
||||
@@ -63,10 +65,9 @@ var rootCmd = &cobra.Command{
|
||||
os.Exit(1)
|
||||
}
|
||||
|
||||
if disallowExemptions {
|
||||
config.DisallowExemptions = true
|
||||
}
|
||||
|
||||
config.DisallowExemptions = disallowExemptions
|
||||
config.DisallowConfigExemptions = disallowConfigExemptions
|
||||
config.DisallowAnnotationExemptions = disallowAnnotationExemptions
|
||||
},
|
||||
Run: func(cmd *cobra.Command, args []string) {
|
||||
logrus.Error("You must specify a sub-command.")
|
||||
|
||||
@@ -1,2 +0,0 @@
|
||||
coverage:
|
||||
range: 50...80
|
||||
@@ -0,0 +1,23 @@
|
||||
# See https://help.github.com/articles/ignoring-files/ for more about ignoring files.
|
||||
|
||||
# dependencies
|
||||
/node_modules
|
||||
/.pnp
|
||||
.pnp.js
|
||||
|
||||
# testing
|
||||
/coverage
|
||||
|
||||
# production
|
||||
/build
|
||||
|
||||
# misc
|
||||
.DS_Store
|
||||
.env.local
|
||||
.env.development.local
|
||||
.env.test.local
|
||||
.env.production.local
|
||||
|
||||
npm-debug.log*
|
||||
yarn-debug.log*
|
||||
yarn-error.log*
|
||||
@@ -0,0 +1,6 @@
|
||||
trailingComma: "es5"
|
||||
tabWidth: 2
|
||||
semi: true
|
||||
singleQuote: true
|
||||
jsxSingleQuote: false
|
||||
parser: typescript
|
||||
@@ -0,0 +1,46 @@
|
||||
# Getting Started with Create React App
|
||||
|
||||
This project was bootstrapped with [Create React App](https://github.com/facebook/create-react-app).
|
||||
|
||||
## Available Scripts
|
||||
|
||||
In the project directory, you can run:
|
||||
|
||||
### `npm start`
|
||||
|
||||
Runs the app in the development mode.\
|
||||
Open [http://localhost:3000](http://localhost:3000) to view it in the browser.
|
||||
|
||||
The page will reload if you make edits.\
|
||||
You will also see any lint errors in the console.
|
||||
|
||||
### `npm test`
|
||||
|
||||
Launches the test runner in the interactive watch mode.\
|
||||
See the section about [running tests](https://facebook.github.io/create-react-app/docs/running-tests) for more information.
|
||||
|
||||
### `npm run build`
|
||||
|
||||
Builds the app for production to the `build` folder.\
|
||||
It correctly bundles React in production mode and optimizes the build for the best performance.
|
||||
|
||||
The build is minified and the filenames include the hashes.\
|
||||
Your app is ready to be deployed!
|
||||
|
||||
See the section about [deployment](https://facebook.github.io/create-react-app/docs/deployment) for more information.
|
||||
|
||||
### `npm run eject`
|
||||
|
||||
**Note: this is a one-way operation. Once you `eject`, you can’t go back!**
|
||||
|
||||
If you aren’t satisfied with the build tool and configuration choices, you can `eject` at any time. This command will remove the single build dependency from your project.
|
||||
|
||||
Instead, it will copy all the configuration files and the transitive dependencies (webpack, Babel, ESLint, etc) right into your project so you have full control over them. All of the commands except `eject` will still work, but they will point to the copied scripts so you can tweak them. At this point you’re on your own.
|
||||
|
||||
You don’t have to ever use `eject`. The curated feature set is suitable for small and middle deployments, and you shouldn’t feel obligated to use this feature. However we understand that this tool wouldn’t be useful if you couldn’t customize it when you are ready for it.
|
||||
|
||||
## Learn More
|
||||
|
||||
You can learn more in the [Create React App documentation](https://facebook.github.io/create-react-app/docs/getting-started).
|
||||
|
||||
To learn React, check out the [React documentation](https://reactjs.org/).
|
||||
@@ -0,0 +1,51 @@
|
||||
{
|
||||
"name": "dashboard",
|
||||
"version": "0.1.0",
|
||||
"private": true,
|
||||
"dependencies": {
|
||||
"@testing-library/jest-dom": "^5.15.0",
|
||||
"@testing-library/react": "^11.2.7",
|
||||
"@testing-library/user-event": "^12.8.3",
|
||||
"@types/jest": "^26.0.24",
|
||||
"@types/node": "^12.20.36",
|
||||
"@types/react": "^17.0.34",
|
||||
"@types/react-bootstrap": "^0.32.28",
|
||||
"@types/react-dom": "^17.0.11",
|
||||
"bootstrap": "^5.1.3",
|
||||
"node-sass": "^6.0.1",
|
||||
"react": "^17.0.2",
|
||||
"react-bootstrap": "^2.0.1",
|
||||
"react-dom": "^17.0.2",
|
||||
"react-scripts": "4.0.3",
|
||||
"typescript": "^4.4.4",
|
||||
"web-vitals": "^1.1.2"
|
||||
},
|
||||
"scripts": {
|
||||
"start": "react-scripts start",
|
||||
"build": "react-scripts build",
|
||||
"test": "react-scripts test",
|
||||
"eject": "react-scripts eject"
|
||||
},
|
||||
"eslintConfig": {
|
||||
"extends": [
|
||||
"react-app",
|
||||
"react-app/jest"
|
||||
]
|
||||
},
|
||||
"browserslist": {
|
||||
"production": [
|
||||
">0.2%",
|
||||
"not dead",
|
||||
"not op_mini all"
|
||||
],
|
||||
"development": [
|
||||
"last 1 chrome version",
|
||||
"last 1 firefox version",
|
||||
"last 1 safari version"
|
||||
]
|
||||
},
|
||||
"devDependencies": {
|
||||
"@axe-core/react": "^4.3.1",
|
||||
"prettier": "^2.4.1"
|
||||
}
|
||||
}
|
||||
|
After Width: | Height: | Size: 342 B |
@@ -0,0 +1,37 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="utf-8" />
|
||||
<link rel="icon" href="%PUBLIC_URL%/favicon.ico" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1" />
|
||||
<meta name="theme-color" content="#000000" />
|
||||
<meta
|
||||
name="description"
|
||||
content="Validation of best practices in your Kubernetes clusters"
|
||||
/>
|
||||
<!--
|
||||
Notice the use of %PUBLIC_URL% in the tags above.
|
||||
It will be replaced with the URL of the `public` folder during the build.
|
||||
Only files inside the `public` folder can be referenced from the HTML.
|
||||
|
||||
Unlike "/favicon.ico" or "favicon.ico", "%PUBLIC_URL%/favicon.ico" will
|
||||
work correctly both with client-side routing and a non-root public URL.
|
||||
Learn how to configure a non-root public URL by running `npm run build`.
|
||||
-->
|
||||
<title>Fairwinds Polaris</title>
|
||||
</head>
|
||||
<body>
|
||||
<noscript>You need to enable JavaScript to run this app.</noscript>
|
||||
<div id="root"></div>
|
||||
<!--
|
||||
This HTML file is a template.
|
||||
If you open it directly in the browser, you will see an empty page.
|
||||
|
||||
You can add webfonts, meta tags, or analytics to this file.
|
||||
The build step will place the bundled scripts into the <body> tag.
|
||||
|
||||
To begin the development, run `npm start` or `yarn start`.
|
||||
To create a production bundle, use `npm run build` or `yarn build`.
|
||||
-->
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,3 @@
|
||||
# https://www.robotstxt.org/robotstxt.html
|
||||
User-agent: *
|
||||
Disallow:
|
||||
@@ -0,0 +1,18 @@
|
||||
@import "~bootstrap/scss/bootstrap.scss";
|
||||
|
||||
.App {
|
||||
width: 100%;
|
||||
height: 100%;
|
||||
display: flex;
|
||||
|
||||
.app-content {
|
||||
padding: 1rem;
|
||||
width: 100%;
|
||||
height: 100%;
|
||||
}
|
||||
|
||||
#mainContainer {
|
||||
width: 100%;
|
||||
height: 100%;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
import React from 'react';
|
||||
import { render, screen } from '@testing-library/react';
|
||||
import App from './App';
|
||||
|
||||
test('renders learn react link', () => {
|
||||
render(<App />);
|
||||
const linkElement = screen.getByText(/learn react/i);
|
||||
expect(linkElement).toBeInTheDocument();
|
||||
});
|
||||
@@ -0,0 +1,43 @@
|
||||
import React, { useState, useEffect } from 'react';
|
||||
import LeftNavBar from './components/Navigation/LeftBar/LeftNavBar';
|
||||
import TopNavBar from './components/Navigation/TopBar/TopNavBar';
|
||||
|
||||
import './App.scss';
|
||||
import data from './data.json';
|
||||
|
||||
function App() {
|
||||
const [pageDisplay, setPageDisplay] = useState<string>('dashboard');
|
||||
const [namespaces, setNamespaces] = useState<string[]>([]);
|
||||
const [selectedNamespace, setSelectedNamespace] = useState<string>('');
|
||||
|
||||
useEffect(() => {
|
||||
const allNamespaces: Set<string> = new Set();
|
||||
data.Results.forEach((result) => {
|
||||
allNamespaces.add(result.Namespace);
|
||||
});
|
||||
setNamespaces(Array.from(allNamespaces));
|
||||
setSelectedNamespace('');
|
||||
}, []);
|
||||
|
||||
return (
|
||||
<div className="App">
|
||||
<LeftNavBar />
|
||||
<div id="mainContainer">
|
||||
<TopNavBar
|
||||
pageDisplay={pageDisplay}
|
||||
setPageDisplay={setPageDisplay}
|
||||
namespaces={namespaces}
|
||||
setSelected={setSelectedNamespace}
|
||||
/>
|
||||
<main className="app-content">
|
||||
{pageDisplay === 'dashboard' && <h1>Polaris Dashboard</h1>}
|
||||
{pageDisplay === 'namespaces' && (
|
||||
<h1>{selectedNamespace} Namespace</h1>
|
||||
)}
|
||||
</main>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
export default App;
|
||||
@@ -0,0 +1,5 @@
|
||||
<svg width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path d="M4.83333 4C4.61232 4 4.40036 4.08231 4.24408 4.22882C4.0878 4.37534 4 4.57405 4 4.78125C4 4.98845 4.0878 5.18716 4.24408 5.33368C4.40036 5.48019 4.61232 5.5625 4.83333 5.5625H14.8333C15.0543 5.5625 15.2663 5.48019 15.4226 5.33368C15.5789 5.18716 15.6667 4.98845 15.6667 4.78125C15.6667 4.57405 15.5789 4.37534 15.4226 4.22882C15.2663 4.08231 15.0543 4 14.8333 4H4.83333ZM4 7.90625C4 7.69905 4.0878 7.50034 4.24408 7.35382C4.40036 7.20731 4.61232 7.125 4.83333 7.125H14.8333C15.0543 7.125 15.2663 7.20731 15.4226 7.35382C15.5789 7.50034 15.6667 7.69905 15.6667 7.90625C15.6667 8.11345 15.5789 8.31216 15.4226 8.45868C15.2663 8.60519 15.0543 8.6875 14.8333 8.6875H4.83333C4.61232 8.6875 4.40036 8.60519 4.24408 8.45868C4.0878 8.31216 4 8.11345 4 7.90625ZM4.83333 10.25C4.61232 10.25 4.40036 10.3323 4.24408 10.4788C4.0878 10.6253 4 10.824 4 11.0312C4 11.2385 4.0878 11.4372 4.24408 11.5837C4.40036 11.7302 4.61232 11.8125 4.83333 11.8125H14.8333C15.0543 11.8125 15.2663 11.7302 15.4226 11.5837C15.5789 11.4372 15.6667 11.2385 15.6667 11.0312C15.6667 10.824 15.5789 10.6253 15.4226 10.4788C15.2663 10.3323 15.0543 10.25 14.8333 10.25H4.83333ZM4.83333 13.375C4.61232 13.375 4.40036 13.4573 4.24408 13.6038C4.0878 13.7503 4 13.949 4 14.1562C4 14.3635 4.0878 14.5622 4.24408 14.7087C4.40036 14.8552 4.61232 14.9375 4.83333 14.9375H9.83333C10.0543 14.9375 10.2663 14.8552 10.4226 14.7087C10.5789 14.5622 10.6667 14.3635 10.6667 14.1562C10.6667 13.949 10.5789 13.7503 10.4226 13.6038C10.2663 13.4573 10.0543 13.375 9.83333 13.375H4.83333Z" fill="white"/>
|
||||
<path d="M0 2.5C0 1.83696 0.351189 1.20107 0.976311 0.732233C1.60143 0.263392 2.44928 0 3.33333 0L16.6667 0C17.5507 0 18.3986 0.263392 19.0237 0.732233C19.6488 1.20107 20 1.83696 20 2.5V17.5C20 18.163 19.6488 18.7989 19.0237 19.2678C18.3986 19.7366 17.5507 20 16.6667 20H3.33333C2.44928 20 1.60143 19.7366 0.976311 19.2678C0.351189 18.7989 0 18.163 0 17.5V2.5ZM16.6667 1.25H3.33333C2.89131 1.25 2.46738 1.3817 2.15482 1.61612C1.84226 1.85054 1.66667 2.16848 1.66667 2.5V17.5C1.66667 17.8315 1.84226 18.1495 2.15482 18.3839C2.46738 18.6183 2.89131 18.75 3.33333 18.75H16.6667C17.1087 18.75 17.5326 18.6183 17.8452 18.3839C18.1577 18.1495 18.3333 17.8315 18.3333 17.5V2.5C18.3333 2.16848 18.1577 1.85054 17.8452 1.61612C17.5326 1.3817 17.1087 1.25 16.6667 1.25Z" fill="white"/>
|
||||
</svg>
|
||||
|
||||
|
After Width: | Height: | Size: 2.4 KiB |
@@ -0,0 +1,3 @@
|
||||
<svg width="25" height="19" viewBox="0 0 25 19" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path d="M25 3.125C25 2.2962 24.6708 1.50134 24.0847 0.915291C23.4987 0.32924 22.7038 0 21.875 0H3.125C2.2962 0 1.50134 0.32924 0.915293 0.915291C0.329241 1.50134 0 2.2962 0 3.125V15.625C0 16.4538 0.329241 17.2487 0.915293 17.8347C1.50134 18.4208 2.2962 18.75 3.125 18.75H21.875C22.7038 18.75 23.4987 18.4208 24.0847 17.8347C24.6708 17.2487 25 16.4538 25 15.625V3.125ZM21.875 1.5625C22.2894 1.5625 22.6868 1.72712 22.9799 2.02015C23.2729 2.31317 23.4375 2.7106 23.4375 3.125V3.46406L12.5 10.0266L1.5625 3.46406V3.125C1.5625 2.7106 1.72712 2.31317 2.02015 2.02015C2.31317 1.72712 2.7106 1.5625 3.125 1.5625H21.875ZM1.5625 5.28594L8.99688 9.74687L1.5625 14.2406V5.2875V5.28594ZM1.61563 16.0328L10.5141 10.6562L12.5 11.8484L14.4875 10.6562L23.3844 16.0312C23.295 16.3632 23.0987 16.6563 22.8258 16.8654C22.5529 17.0744 22.2187 17.1876 21.875 17.1875H3.125C2.78147 17.1877 2.44744 17.0747 2.17459 16.866C1.90174 16.6573 1.70529 16.3644 1.61563 16.0328ZM23.4375 14.2406L16.0031 9.74687L23.4375 5.28594V14.2391V14.2406Z" fill="white"/>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 1.1 KiB |
@@ -0,0 +1,3 @@
|
||||
<svg width="25" height="24" viewBox="0 0 25 24" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path d="M12.5 0C5.59375 0 0 5.50583 0 12.3035C0 17.7478 3.57812 22.3463 8.54688 23.9765C9.17188 24.0842 9.40625 23.715 9.40625 23.3921C9.40625 23.0999 9.39062 22.131 9.39062 21.1005C6.25 21.6696 5.4375 20.347 5.1875 19.6549C5.04688 19.3012 4.4375 18.2092 3.90625 17.917C3.46875 17.6863 2.84375 17.1173 3.89062 17.1019C4.875 17.0865 5.57812 17.9939 5.8125 18.363C6.9375 20.2239 8.73438 19.701 9.45312 19.3781C9.5625 18.5783 9.89062 18.04 10.25 17.7325C7.46875 17.4249 4.5625 16.3637 4.5625 11.6576C4.5625 10.3196 5.04688 9.21227 5.84375 8.35102C5.71875 8.04343 5.28125 6.78232 5.96875 5.09058C5.96875 5.09058 7.01562 4.76762 9.40625 6.3517C10.4062 6.07487 11.4688 5.93645 12.5313 5.93645C13.5938 5.93645 14.6563 6.07487 15.6563 6.3517C18.0469 4.75224 19.0938 5.09058 19.0938 5.09058C19.7812 6.78232 19.3438 8.04343 19.2188 8.35102C20.0156 9.21227 20.5 10.3042 20.5 11.6576C20.5 16.3791 17.5781 17.4249 14.7969 17.7325C15.25 18.1169 15.6406 18.8552 15.6406 20.0086C15.6406 21.6542 15.625 22.9768 15.625 23.3921C15.625 23.715 15.8594 24.0995 16.4844 23.9765C18.966 23.1521 21.1224 21.5824 22.65 19.4884C24.1777 17.3944 24.9996 14.8815 25 12.3035C25 5.50583 19.4062 0 12.5 0Z" fill="white"/>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 1.3 KiB |
@@ -0,0 +1,3 @@
|
||||
<svg width="9" height="14" viewBox="0 0 9 14" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path d="M0.755859 1.59702L7.77688 7.00555L0.755859 12.4141V1.59702ZM0.353294 12.7242C0.353419 12.7241 0.353541 12.724 0.353666 12.7239L0.353294 12.7242ZM8.03353 7.20326L8.03397 7.2036L8.18654 7.00555L8.03397 7.2036C8.03382 7.20349 8.03367 7.20337 8.03353 7.20326Z" stroke="white" stroke-width="1.5"/>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 403 B |
@@ -0,0 +1,3 @@
|
||||
<svg width="20" height="21" viewBox="0 0 20 21" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path d="M7.66849 0L7.39526 2.46812C6.35771 2.81801 5.41199 3.37161 4.60838 4.08015L2.33151 3.07832L0 7.12204L1.99452 8.58833C1.89056 9.10843 1.83971 9.64966 1.83971 10.2004C1.83971 10.751 1.89059 11.2923 1.99452 11.8124L0 13.2787L2.33151 17.3224L4.60838 16.3206C5.41199 17.0291 6.35771 17.5827 7.39526 17.9326L7.66849 20.4007H12.3315L12.6047 17.9326C13.6423 17.5827 14.588 17.0291 15.3916 16.3206L17.6685 17.3224L20 13.2787L18.0055 11.8124C18.1094 11.2923 18.1603 10.751 18.1603 10.2004C18.1603 9.64966 18.1094 9.10843 18.0055 8.58833L20 7.12204L17.6685 3.07832L15.3916 4.08015C14.588 3.37161 13.6423 2.81801 12.6047 2.46812L12.3315 0H7.66849ZM10 5.2459C12.7363 5.2459 14.9545 7.46404 14.9545 10.2004C14.9545 12.9366 12.7363 15.1548 10 15.1548C7.26374 15.1548 5.04554 12.9366 5.04554 10.2004C5.04554 7.46404 7.26374 5.2459 10 5.2459Z" fill="white"/>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 954 B |
@@ -0,0 +1,3 @@
|
||||
<svg width="25" height="25" viewBox="0 0 25 25" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path d="M5.25313 15.7969C5.25313 17.2437 4.07188 18.4234 2.62656 18.4234C1.18125 18.4234 0 17.2437 0 15.7984C0 14.3531 1.18125 13.1719 2.625 13.1719H5.25313V15.7969ZM6.575 15.7969C6.575 14.3531 7.75625 13.1719 9.20156 13.1719C10.6469 13.1719 11.8281 14.3531 11.8281 15.7969V22.375C11.8281 23.8188 10.6469 25 9.20312 25C8.50702 24.9988 7.83974 24.7219 7.34723 24.23C6.85472 23.7381 6.57706 23.0711 6.575 22.375V15.7969ZM9.20312 5.25313C7.75625 5.25313 6.575 4.07188 6.575 2.62656C6.575 1.18125 7.75625 0 9.20312 0C10.65 0 11.8281 1.18125 11.8281 2.625V5.25313H9.20312ZM9.20312 6.575C10.6469 6.575 11.8281 7.75625 11.8281 9.20156C11.8281 10.6469 10.6469 11.8281 9.20312 11.8281H2.625C1.18281 11.8281 0 10.6469 0 9.20312C0 7.75625 1.18125 6.575 2.625 6.575H9.20312ZM19.7484 9.20312C19.7484 7.75625 20.9281 6.575 22.3734 6.575C23.8188 6.575 25 7.75625 25 9.20156C25 10.6469 23.8188 11.8281 22.375 11.8281H19.7484V9.20312ZM18.4234 9.20312C18.4234 10.6469 17.2437 11.8281 15.7984 11.8281C15.1026 11.8265 14.4357 11.5494 13.9436 11.0576C13.4514 10.5657 13.1739 9.89895 13.1719 9.20312V2.625C13.1719 1.18281 14.3531 0 15.7969 0C17.2437 0 18.4234 1.18125 18.4234 2.625V9.20312ZM15.7969 19.7469C17.2437 19.7469 18.425 20.9281 18.425 22.3734C18.425 23.8188 17.2437 25 15.7969 25C14.35 25 13.1703 23.8188 13.1703 22.375V19.7469H15.7953H15.7969ZM15.7969 18.4234C14.3531 18.4234 13.1719 17.2437 13.1719 15.7984C13.1719 14.3531 14.3531 13.1719 15.7969 13.1719H22.375C23.8188 13.1719 25 14.3531 25 15.7969C25 17.2437 23.8188 18.4234 22.375 18.4234H15.7969Z" fill="white"/>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 1.6 KiB |
@@ -0,0 +1,3 @@
|
||||
<svg width="25" height="21" viewBox="0 0 25 21" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path d="M7.85313 21C17.2875 21 22.4484 12.9187 22.4484 5.9228C22.4484 5.69666 22.4484 5.46729 22.4391 5.24115C23.4438 4.4892 24.311 3.55825 25 2.49191C24.0614 2.91972 23.0668 3.20168 22.0484 3.32863C23.1211 2.66578 23.9246 1.62283 24.3094 0.393637C23.3015 1.01088 22.1985 1.44418 21.0484 1.67457C20.2753 0.823345 19.2522 0.259434 18.1376 0.0701857C17.0231 -0.119063 15.8793 0.0769118 14.8833 0.627754C13.8874 1.1786 13.095 2.05356 12.6288 3.11713C12.1626 4.18069 12.0487 5.37349 12.3047 6.51077C10.2652 6.40505 8.27003 5.85733 6.4485 4.90314C4.62698 3.94894 3.01982 2.60957 1.73125 0.971914C1.07709 2.13991 0.877459 3.5215 1.17288 4.83614C1.46831 6.15077 2.23665 7.29989 3.32187 8.05015C2.50866 8.02159 1.71331 7.79584 1 7.39111V7.4638C1.0014 8.68736 1.41142 9.87289 2.16074 10.82C2.91006 11.7671 3.95273 12.4177 5.1125 12.6618C4.67229 12.7872 4.21755 12.8497 3.76094 12.8476C3.43904 12.8486 3.11778 12.8178 2.80156 12.7555C3.12935 13.8088 3.76761 14.7297 4.62695 15.3892C5.48628 16.0488 6.52365 16.4139 7.59375 16.4336C5.77587 17.9096 3.53031 18.7102 1.21875 18.7063C0.811439 18.7081 0.404411 18.6838 0 18.6336C2.34612 20.1799 5.07078 21.0009 7.85313 21Z" fill="white"/>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 1.2 KiB |
|
Before Width: | Height: | Size: 13 KiB After Width: | Height: | Size: 13 KiB |
@@ -0,0 +1,63 @@
|
||||
.left-nav-bar {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
justify-content: space-between;
|
||||
background-color: #23103a;
|
||||
color: white;
|
||||
height: 100vh;
|
||||
padding: 1rem;
|
||||
width: 250px;
|
||||
min-width: 250px;
|
||||
|
||||
.top-div {
|
||||
img {
|
||||
width: 220px;
|
||||
}
|
||||
}
|
||||
|
||||
.bottom-div {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
flex-wrap: wrap;
|
||||
gap: 1rem;
|
||||
|
||||
.links-title {
|
||||
color: #eceeef;
|
||||
font-size: 1rem;
|
||||
font-weight: 300;
|
||||
margin-bottom: 0;
|
||||
}
|
||||
|
||||
.nav-link-section {
|
||||
display: flex;
|
||||
flex-direction: row;
|
||||
flex-wrap: wrap;
|
||||
align-items: center;
|
||||
gap: 1rem;
|
||||
text-decoration: none;
|
||||
|
||||
.link-name {
|
||||
font-size: 1.2rem;
|
||||
font-weight: 300;
|
||||
margin-bottom: 0;
|
||||
}
|
||||
|
||||
.docs {
|
||||
color: white;
|
||||
}
|
||||
}
|
||||
|
||||
.external-links {
|
||||
display: flex;
|
||||
flex-direction: row;
|
||||
flex-wrap: wrap;
|
||||
justify-content: space-between;
|
||||
}
|
||||
.feedback {
|
||||
text-decoration: none;
|
||||
color: white;
|
||||
font-size: 1rem;
|
||||
font-weight: 300;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,79 @@
|
||||
import React from 'react';
|
||||
// import Settings from '../../assets/icons/settings.svg';
|
||||
import Docs from '../../../assets/icons/docs.svg';
|
||||
import RightArrow from '../../../assets/icons/rightArrow.svg';
|
||||
import Github from '../../../assets/icons/github.svg';
|
||||
import Twitter from '../../../assets/icons/twitter.svg';
|
||||
import Slack from '../../../assets/icons/slack.svg';
|
||||
import Email from '../../../assets/icons/email.svg';
|
||||
import PolarisLogo from '../../../assets/images/polaris-logo.png';
|
||||
|
||||
import './LeftNavBar.scss';
|
||||
|
||||
const LeftNavBar = (): JSX.Element => {
|
||||
return (
|
||||
<section className="left-nav-bar">
|
||||
<div className="top-div">
|
||||
<img src={PolarisLogo} alt="Polaris icon" />
|
||||
</div>
|
||||
<div className="bottom-div">
|
||||
<h2 className="links-title">Application</h2>
|
||||
{/* TODO: no settings in Polaris? */}
|
||||
{/* <div className="nav-link-section">
|
||||
<img src={Settings} alt='gear icon' />
|
||||
<h3 className="link-name">Settings</h3>
|
||||
</div> */}
|
||||
<a
|
||||
className="nav-link-section"
|
||||
href="https://polaris.docs.fairwinds.com/"
|
||||
target="_blank"
|
||||
rel="noreferrer"
|
||||
>
|
||||
<img src={Docs} alt="doc icon" />
|
||||
<h3 className="link-name docs">Docs</h3>
|
||||
<img src={RightArrow} alt="arrow pointing right" />
|
||||
</a>
|
||||
<div className="external-links">
|
||||
<a
|
||||
href="https://github.com/FairwindsOps/polaris"
|
||||
target="_blank"
|
||||
rel="noreferrer"
|
||||
>
|
||||
<img src={Github} alt="github logo" />
|
||||
</a>
|
||||
<a
|
||||
href="https://twitter.com/fairwindsops"
|
||||
target="_blank"
|
||||
rel="noreferrer"
|
||||
>
|
||||
<img src={Twitter} alt="twitter logo" />
|
||||
</a>
|
||||
<a
|
||||
href="https://join.slack.com/t/fairwindscommunity/shared_invite/zt-e3c6vj4l-3lIH6dvKqzWII5fSSFDi1g"
|
||||
target="_blank"
|
||||
rel="noreferrer"
|
||||
>
|
||||
<img src={Slack} alt="slack logo" />
|
||||
</a>
|
||||
<a
|
||||
href="https://www.fairwinds.com/fairwinds-newsletter"
|
||||
target="_blank"
|
||||
rel="noreferrer"
|
||||
>
|
||||
<img src={Email} alt="envelope for newsletter" />
|
||||
</a>
|
||||
</div>
|
||||
<a
|
||||
href="https://github.com/fairwindsops/polaris/issues"
|
||||
target="_blank"
|
||||
rel="noreferrer"
|
||||
className="feedback"
|
||||
>
|
||||
Feedback
|
||||
</a>
|
||||
</div>
|
||||
</section>
|
||||
);
|
||||
};
|
||||
|
||||
export default LeftNavBar;
|
||||
@@ -0,0 +1,40 @@
|
||||
.top-nav-bar {
|
||||
z-index: 3;
|
||||
background-color: white;
|
||||
height: 3rem;
|
||||
position: sticky;
|
||||
top: 0;
|
||||
padding-bottom: 0 !important;
|
||||
|
||||
.top-nav {
|
||||
padding: 0 24px;
|
||||
height: inherit;
|
||||
align-content: end;
|
||||
width: 100%;
|
||||
|
||||
.nav-item > .dropdown-menu {
|
||||
max-height: 15rem;
|
||||
overflow: auto;
|
||||
}
|
||||
|
||||
.nav-item > .nav-link {
|
||||
color: #495057;
|
||||
|
||||
&:hover,
|
||||
&:focus {
|
||||
border-color: transparent;
|
||||
}
|
||||
&.active {
|
||||
border-color: #fff #fff;
|
||||
margin-bottom: -2px;
|
||||
border-bottom: 2px solid #445688;
|
||||
color: #445688;
|
||||
padding-bottom: 14px;
|
||||
}
|
||||
}
|
||||
|
||||
#nav-dropdown {
|
||||
padding-left: 0;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,72 @@
|
||||
import React, { SyntheticEvent, useState } from 'react';
|
||||
import { Nav, Navbar, NavDropdown } from 'react-bootstrap';
|
||||
import './TopNavBar.scss';
|
||||
|
||||
type NavProps = {
|
||||
pageDisplay: string;
|
||||
setPageDisplay: React.Dispatch<React.SetStateAction<string>>;
|
||||
namespaces: string[];
|
||||
setSelected: React.Dispatch<React.SetStateAction<string>>;
|
||||
};
|
||||
|
||||
const TopNavBar = ({
|
||||
pageDisplay,
|
||||
setPageDisplay,
|
||||
namespaces,
|
||||
setSelected,
|
||||
}: NavProps): JSX.Element => {
|
||||
const [selectedNamespace, setSelectedNamespace] =
|
||||
useState<string>('All Namespaces');
|
||||
|
||||
const handleNamespaceSelection = (
|
||||
namespace: SyntheticEvent<HTMLDivElement, Event>
|
||||
): void => {
|
||||
if (namespace.toString() === 'All Namespaces') {
|
||||
setSelectedNamespace('All Namespace');
|
||||
} else if (namespace) {
|
||||
setSelectedNamespace(namespace.toString());
|
||||
}
|
||||
setPageDisplay('namespaces');
|
||||
setSelected(namespace.toString());
|
||||
};
|
||||
|
||||
const NavItems = (): JSX.Element => (
|
||||
<>
|
||||
{namespaces.map((item) => {
|
||||
return (
|
||||
<NavDropdown.Item key={item} eventKey={item}>
|
||||
{item}
|
||||
</NavDropdown.Item>
|
||||
);
|
||||
})}
|
||||
</>
|
||||
);
|
||||
|
||||
return (
|
||||
<header>
|
||||
<Navbar className="top-nav-bar" expand={true}>
|
||||
<Nav variant="tabs" className="top-nav">
|
||||
<NavDropdown
|
||||
title={selectedNamespace}
|
||||
id="nav-dropdown"
|
||||
active={pageDisplay === 'namespaces'}
|
||||
onSelect={handleNamespaceSelection}
|
||||
>
|
||||
<NavDropdown.Item
|
||||
key={'all-namespaces'}
|
||||
eventKey={'all-namespaces'}
|
||||
>
|
||||
All Namespaces
|
||||
</NavDropdown.Item>
|
||||
<NavItems />
|
||||
</NavDropdown>
|
||||
<Nav.Item onClick={() => setPageDisplay('dashboard')}>
|
||||
<Nav.Link active={pageDisplay === 'dashboard'}>Dashboard</Nav.Link>
|
||||
</Nav.Item>
|
||||
</Nav>
|
||||
</Navbar>
|
||||
</header>
|
||||
);
|
||||
};
|
||||
|
||||
export default TopNavBar;
|
||||
@@ -0,0 +1,13 @@
|
||||
body {
|
||||
margin: 0;
|
||||
font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', 'Roboto', 'Oxygen',
|
||||
'Ubuntu', 'Cantarell', 'Fira Sans', 'Droid Sans', 'Helvetica Neue',
|
||||
sans-serif;
|
||||
-webkit-font-smoothing: antialiased;
|
||||
-moz-osx-font-smoothing: grayscale;
|
||||
}
|
||||
|
||||
code {
|
||||
font-family: source-code-pro, Menlo, Monaco, Consolas, 'Courier New',
|
||||
monospace;
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
import React from 'react';
|
||||
import ReactDOM from 'react-dom';
|
||||
import './index.scss';
|
||||
import App from './App';
|
||||
import reportWebVitals from './reportWebVitals';
|
||||
|
||||
if (process.env.NODE_ENV !== 'production') {
|
||||
const axe = require('@axe-core/react');
|
||||
axe(React, ReactDOM, 1000);
|
||||
}
|
||||
|
||||
ReactDOM.render(
|
||||
<React.StrictMode>
|
||||
<App />
|
||||
</React.StrictMode>,
|
||||
document.getElementById('root')
|
||||
);
|
||||
|
||||
// If you want to start measuring performance in your app, pass a function
|
||||
// to log results (for example: reportWebVitals(console.log))
|
||||
// or send to an analytics endpoint. Learn more: https://bit.ly/CRA-vitals
|
||||
reportWebVitals();
|
||||
@@ -0,0 +1 @@
|
||||
/// <reference types="react-scripts" />
|
||||
@@ -0,0 +1,15 @@
|
||||
import { ReportHandler } from 'web-vitals';
|
||||
|
||||
const reportWebVitals = (onPerfEntry?: ReportHandler) => {
|
||||
if (onPerfEntry && onPerfEntry instanceof Function) {
|
||||
import('web-vitals').then(({ getCLS, getFID, getFCP, getLCP, getTTFB }) => {
|
||||
getCLS(onPerfEntry);
|
||||
getFID(onPerfEntry);
|
||||
getFCP(onPerfEntry);
|
||||
getLCP(onPerfEntry);
|
||||
getTTFB(onPerfEntry);
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
export default reportWebVitals;
|
||||
@@ -0,0 +1,5 @@
|
||||
// jest-dom adds custom jest matchers for asserting on DOM nodes.
|
||||
// allows you to do things like:
|
||||
// expect(element).toHaveTextContent(/react/i)
|
||||
// learn more: https://github.com/testing-library/jest-dom
|
||||
import '@testing-library/jest-dom';
|
||||
@@ -0,0 +1,26 @@
|
||||
{
|
||||
"compilerOptions": {
|
||||
"target": "es5",
|
||||
"lib": [
|
||||
"dom",
|
||||
"dom.iterable",
|
||||
"esnext"
|
||||
],
|
||||
"allowJs": true,
|
||||
"skipLibCheck": true,
|
||||
"esModuleInterop": true,
|
||||
"allowSyntheticDefaultImports": true,
|
||||
"strict": true,
|
||||
"forceConsistentCasingInFileNames": true,
|
||||
"noFallthroughCasesInSwitch": true,
|
||||
"module": "esnext",
|
||||
"moduleResolution": "node",
|
||||
"resolveJsonModule": true,
|
||||
"isolatedModules": true,
|
||||
"noEmit": true,
|
||||
"jsx": "react-jsx"
|
||||
},
|
||||
"include": [
|
||||
"src"
|
||||
]
|
||||
}
|
||||
@@ -31,6 +31,14 @@ rules:
|
||||
verbs:
|
||||
- 'get'
|
||||
- 'list'
|
||||
- apiGroups:
|
||||
- 'monitoring.coreos.com'
|
||||
resources:
|
||||
- 'prometheuses'
|
||||
- 'alertmanagers'
|
||||
verbs:
|
||||
- 'get'
|
||||
- 'list'
|
||||
---
|
||||
# Source: polaris/templates/rbac.yaml
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
@@ -49,7 +57,7 @@ subjects:
|
||||
namespace: polaris
|
||||
---
|
||||
# Source: polaris/templates/rbac.yaml
|
||||
apiVersion: rbac.authorization.k8s.io/v1beta1
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: polaris
|
||||
@@ -109,7 +117,9 @@ spec:
|
||||
- command:
|
||||
- polaris
|
||||
- dashboard
|
||||
image: 'quay.io/fairwinds/polaris:3.0'
|
||||
- --port
|
||||
- "8080"
|
||||
image: 'quay.io/fairwinds/polaris:4.2'
|
||||
imagePullPolicy: 'Always'
|
||||
name: dashboard
|
||||
ports:
|
||||
|
||||
@@ -31,6 +31,14 @@ rules:
|
||||
verbs:
|
||||
- 'get'
|
||||
- 'list'
|
||||
- apiGroups:
|
||||
- 'monitoring.coreos.com'
|
||||
resources:
|
||||
- 'prometheuses'
|
||||
- 'alertmanagers'
|
||||
verbs:
|
||||
- 'get'
|
||||
- 'list'
|
||||
---
|
||||
# Source: polaris/templates/rbac.yaml
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
@@ -49,7 +57,7 @@ subjects:
|
||||
namespace: polaris
|
||||
---
|
||||
# Source: polaris/templates/rbac.yaml
|
||||
apiVersion: rbac.authorization.k8s.io/v1beta1
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: polaris
|
||||
@@ -109,7 +117,7 @@ spec:
|
||||
command:
|
||||
- polaris
|
||||
- webhook
|
||||
image: 'quay.io/fairwinds/polaris:3.0'
|
||||
image: 'quay.io/fairwinds/polaris:4.2'
|
||||
imagePullPolicy: 'Always'
|
||||
ports:
|
||||
- containerPort: 9876
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
/*
|
||||
* This file is generated from FairwindsOps/documentation-template
|
||||
* DO NOT EDIT MANUALLY
|
||||
*/
|
||||
|
||||
var llcookieless = true;
|
||||
var sf14gv = 32793;
|
||||
(function() {
|
||||
var sf14g = document.createElement('script');
|
||||
sf14g.src = 'https://lltrck.com/lt-v2.min.js';
|
||||
var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(sf14g, s);
|
||||
})();
|
||||
@@ -1,66 +0,0 @@
|
||||
#### CLI Options
|
||||
|
||||
```
|
||||
# top-level commands
|
||||
audit
|
||||
Runs a one-time audit.
|
||||
dashboard
|
||||
Runs the webserver for Polaris dashboard.
|
||||
help
|
||||
Prints help, if you give it a command then it will print help for that command. Same as -h
|
||||
version
|
||||
Prints the version of Polaris
|
||||
webhook
|
||||
Runs the webhook webserver
|
||||
|
||||
# high-level flags
|
||||
-c, --config string
|
||||
Location of Polaris configuration file
|
||||
--disallow-exemptions
|
||||
Disallow any exemptions from configuration file.
|
||||
-h, --help
|
||||
Help for Polaris (same as help command)
|
||||
--kubeconfig string
|
||||
Path to a kubeconfig. Only required if out-of-cluster.
|
||||
--log-level string
|
||||
Logrus log level (default "info")
|
||||
--master string
|
||||
The address of the Kubernetes API server. Overrides any value in kubeconfig. Only required if out-of-cluster.
|
||||
|
||||
# dashboard flags
|
||||
--audit-path string
|
||||
If specified, audits one or more YAML files instead of a cluster
|
||||
--base-path string
|
||||
Path on which the dashboard is served (default "/")
|
||||
--display-name string
|
||||
An optional identifier for the audit
|
||||
--load-audit-file string
|
||||
Runs the dashboard with data saved from a past audit.
|
||||
-p, --port int
|
||||
Port for the dashboard webserver (default 8080)
|
||||
|
||||
# audit flags
|
||||
--audit-path string
|
||||
If specified, audits one or more YAML files instead of a cluster
|
||||
--resource string
|
||||
If specified, audit a specific resource, in the format namespace/kind/version/name, e.g. nginx-ingress/Deployment.apps/v1/default-backend
|
||||
--display-name string
|
||||
An optional identifier for the audit
|
||||
--format string
|
||||
Output format for results - json, yaml, or score (default "json")
|
||||
--output-file string
|
||||
Destination file for audit results
|
||||
--output-url string
|
||||
Destination URL to send audit results
|
||||
--set-exit-code-below-score int
|
||||
Set an exit code of 4 when the score is below this threshold (1-100)
|
||||
--set-exit-code-on-danger
|
||||
Set an exit code of 3 when the audit contains danger-level issues.
|
||||
|
||||
# webhook flags
|
||||
--disable-webhook-config-installer
|
||||
disable the installer in the webhook server, so it won't install webhook configuration resources during bootstrapping
|
||||
-p, --port int
|
||||
Port for the webhook webserver (default 9876)
|
||||
```
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
# Custom Checks
|
||||
If you'd like to create your own checks, you can use [JSON Schema](https://json-schema.org/). For example,
|
||||
to disallow images from quay.io:
|
||||
|
||||
```yaml
|
||||
checks:
|
||||
imageRegistry: warning
|
||||
customChecks:
|
||||
imageRegistry:
|
||||
successMessage: Image comes from allowed registries
|
||||
failureMessage: Image should not be from disallowed registry
|
||||
category: Images
|
||||
target: Container # target can be "Container" or "Pod"
|
||||
schema:
|
||||
'$schema': http://json-schema.org/draft-07/schema
|
||||
type: object
|
||||
properties:
|
||||
image:
|
||||
type: string
|
||||
not:
|
||||
pattern: ^quay.io
|
||||
```
|
||||
|
||||
Schemas can also be specified as JSON strings instead of YAML, for easier copy/pasting:
|
||||
```yaml
|
||||
customChecks:
|
||||
foo:
|
||||
jsonSchema: |
|
||||
{
|
||||
"$schema": "http://json-schema.org/draft-07/schema",
|
||||
"type": "object"
|
||||
}
|
||||
```
|
||||
|
||||
We extend JSON Schema with `resourceMinimum` and `resourceMaximum` fields to help compare memory and CPU resource
|
||||
strings like `1000m` and `1G`. You can see an example in [the extended config](https://github.com/FairwindsOps/polaris/tree/master/examples/config-full.yaml)
|
||||
|
||||
There are additional examples in the [checks folder](https://github.com/FairwindsOps/polaris/tree/master/checks).
|
||||
|
||||
@@ -1,29 +0,0 @@
|
||||
# Infrastructure as Code
|
||||
Polaris can be used on the command line to audit local Kubernetes manifests stored in YAML files.
|
||||
This is particularly helpful for running Polaris against your infrastructure-as-code as part of a
|
||||
CI/CD pipeline. Use the available [command line flags](#running-in-a-ci-pipeline)
|
||||
to cause CI/CD to fail if your Polaris score drops below a certain threshold, or if any danger-level issues arise.
|
||||
|
||||
|
||||
## Install the CLI
|
||||
To run Polaris against your YAML manifests, e.g. as part of a Continuous Integration process,
|
||||
you'll need to install the CLI.
|
||||
|
||||
Binary releases can be downloaded from the [releases page](https://github.com/fairwindsops/polaris/releases)
|
||||
or can be installed with [Homebrew](https://brew.sh/):
|
||||
```bash
|
||||
brew tap FairwindsOps/tap
|
||||
brew install FairwindsOps/tap/polaris
|
||||
polaris version
|
||||
```
|
||||
|
||||
## Running in a CI pipeline
|
||||
You can tell the CLI to set an exit code if it detects certain issues with your
|
||||
YAML files.
|
||||
For example, to fail if polaris detects *any* danger-level issues, or if the score drops below 90%:
|
||||
```bash
|
||||
polaris audit --audit-path ./deploy/ \
|
||||
--set-exit-code-on-danger \
|
||||
--set-exit-code-below-score 90
|
||||
```
|
||||
|
||||
@@ -33,6 +33,13 @@ module.exports = {
|
||||
"/infrastructure-as-code",
|
||||
],
|
||||
},
|
||||
{
|
||||
title: "Usage",
|
||||
collapsable: false,
|
||||
children: [
|
||||
"/cli",
|
||||
],
|
||||
},
|
||||
{
|
||||
title: "Customization",
|
||||
collapsable: false,
|
||||
@@ -38,11 +38,11 @@ const baseConfig = {
|
||||
head: [
|
||||
['link', { rel: 'icon', href: '/favicon.png' }],
|
||||
['script', { src: '/scripts/modify.js' }],
|
||||
['script', { src: '/scripts/leadlander.js' }],
|
||||
['script', { src: '/scripts/marketing.js' }],
|
||||
],
|
||||
themeConfig: {
|
||||
docsRepo: "",
|
||||
docsDir: 'docs-md',
|
||||
docsDir: 'docs',
|
||||
editLinks: true,
|
||||
editLinkText: "Help us improve this page",
|
||||
logo: '/img/fairwinds-logo.svg',
|
||||
|
Before Width: | Height: | Size: 400 B After Width: | Height: | Size: 400 B |
|
Before Width: | Height: | Size: 34 KiB After Width: | Height: | Size: 34 KiB |
|
Before Width: | Height: | Size: 139 KiB After Width: | Height: | Size: 139 KiB |
|
Before Width: | Height: | Size: 186 KiB After Width: | Height: | Size: 186 KiB |
|
Before Width: | Height: | Size: 3.8 KiB After Width: | Height: | Size: 3.8 KiB |
|
After Width: | Height: | Size: 66 KiB |
|
Before Width: | Height: | Size: 13 KiB After Width: | Height: | Size: 13 KiB |
@@ -0,0 +1,29 @@
|
||||
/*
|
||||
* This file is generated from FairwindsOps/documentation-template
|
||||
* DO NOT EDIT MANUALLY
|
||||
*/
|
||||
|
||||
var llcookieless = true;
|
||||
var sf14gv = 32793;
|
||||
(function() {
|
||||
var sf14g = document.createElement('script');
|
||||
sf14g.src = 'https://lltrck.com/lt-v2.min.js';
|
||||
var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(sf14g, s);
|
||||
})();
|
||||
|
||||
!function(f,b,e,v,n,t,s)
|
||||
{if(f.fbq)return;n=f.fbq=function(){n.callMethod?
|
||||
n.callMethod.apply(n,arguments):n.queue.push(arguments)};
|
||||
if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';
|
||||
n.queue=[];t=b.createElement(e);t.async=!0;
|
||||
t.src=v;s=b.getElementsByTagName(e)[0];
|
||||
s.parentNode.insertBefore(t,s)}(window,document,'script',
|
||||
'https://connect.facebook.net/en_US/fbevents.js');
|
||||
fbq('init', '521127644762074');
|
||||
fbq('track', 'PageView');
|
||||
|
||||
(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':
|
||||
new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],
|
||||
j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src=
|
||||
'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);
|
||||
})(window,document,'script','dataLayer','GTM-TM95WXQ');
|
||||
@@ -23,6 +23,13 @@
|
||||
color: $successColor;
|
||||
}
|
||||
|
||||
blockquote {
|
||||
border-left: 0.2rem solid $warningColor;
|
||||
}
|
||||
blockquote p {
|
||||
color: $warningColor;
|
||||
}
|
||||
|
||||
.theme-default-content:not(.custom),
|
||||
.page-nav,
|
||||
.page-edit,
|
||||
@@ -1,22 +0,0 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en-US">
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<meta name="viewport" content="width=device-width,initial-scale=1">
|
||||
<title>Fairwinds Polaris Documentation</title>
|
||||
<meta name="generator" content="VuePress 1.7.1">
|
||||
<link rel="icon" href="/favicon.png">
|
||||
<script src="/scripts/modify.js"></script>
|
||||
<script src="/scripts/leadlander.js"></script>
|
||||
<meta name="description" content="Documentation for Fairwinds Polaris - audit and enforce Kubernetes best practices for your workloads">
|
||||
|
||||
<link rel="preload" href="/assets/css/0.styles.db69974e.css" as="style"><link rel="preload" href="/assets/js/app.65b94829.js" as="script"><link rel="preload" href="/assets/js/7.dbd47d64.js" as="script"><link rel="prefetch" href="/assets/js/10.9d1a1701.js"><link rel="prefetch" href="/assets/js/11.d7eadcf0.js"><link rel="prefetch" href="/assets/js/12.85c0eab0.js"><link rel="prefetch" href="/assets/js/13.0487faf0.js"><link rel="prefetch" href="/assets/js/14.60ea393e.js"><link rel="prefetch" href="/assets/js/15.00f25aaa.js"><link rel="prefetch" href="/assets/js/16.cb0515ce.js"><link rel="prefetch" href="/assets/js/17.013e9969.js"><link rel="prefetch" href="/assets/js/18.a0fcb2d2.js"><link rel="prefetch" href="/assets/js/19.9fe045af.js"><link rel="prefetch" href="/assets/js/2.28adca5d.js"><link rel="prefetch" href="/assets/js/20.5bcacf34.js"><link rel="prefetch" href="/assets/js/21.2f58615f.js"><link rel="prefetch" href="/assets/js/22.90ebc6b9.js"><link rel="prefetch" href="/assets/js/3.0cb25b42.js"><link rel="prefetch" href="/assets/js/4.be9896b6.js"><link rel="prefetch" href="/assets/js/5.665b3e6a.js"><link rel="prefetch" href="/assets/js/6.a5e340ed.js"><link rel="prefetch" href="/assets/js/8.5a82b7c2.js"><link rel="prefetch" href="/assets/js/9.4f55b6b3.js">
|
||||
<link rel="stylesheet" href="/assets/css/0.styles.db69974e.css">
|
||||
</head>
|
||||
<body>
|
||||
<div id="app" data-server-rendered="true"><div class="theme-container"><div class="theme-default-content"><h1>404</h1> <blockquote>Looks like we've got some broken links.</blockquote> <a href="/" class="router-link-active">
|
||||
Take me home.
|
||||
</a></div></div><div class="global-ui"></div></div>
|
||||
<script src="/assets/js/app.65b94829.js" defer></script><script src="/assets/js/7.dbd47d64.js" defer></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -1 +0,0 @@
|
||||
polaris.docs.fairwinds.com
|
||||
@@ -3,7 +3,7 @@
|
||||
<br>
|
||||
<h3>Best Practices for Kubernetes Workload Configuration</h3>
|
||||
<a href="https://github.com/FairwindsOps/polaris">
|
||||
<img src="https://img.shields.io/static/v1.svg?label=Version&message=3.0.0&color=239922">
|
||||
<img src="https://img.shields.io/static/v1.svg?label=Version&message=3.1.6&color=239922">
|
||||
</a>
|
||||
<a href="https://goreportcard.com/report/github.com/FairwindsOps/polaris">
|
||||
<img src="https://goreportcard.com/badge/github.com/FairwindsOps/polaris">
|
||||
@@ -11,11 +11,14 @@
|
||||
<a href="https://circleci.com/gh/FairwindsOps/polaris.svg">
|
||||
<img src="https://circleci.com/gh/FairwindsOps/polaris.svg?style=svg">
|
||||
</a>
|
||||
<a href="https://insights.fairwinds.com/gh/FairwindsOps/polaris">
|
||||
<img src="https://insights.fairwinds.com/v0/gh/FairwindsOps/polaris/badge.svg">
|
||||
</a>
|
||||
</div>
|
||||
|
||||
Fairwinds' Polaris keeps your clusters sailing smoothly. It runs a variety of checks to ensure that
|
||||
Kubernetes pods and controllers are configured using best practices, helping you avoid
|
||||
problems in the future. Polaris can be run in a few different modes:
|
||||
problems in the future.
|
||||
|
||||
Polaris can be run in three different modes:
|
||||
* As a [dashboard](/dashboard), so you can audit what's running inside your cluster.
|
||||
@@ -35,7 +38,7 @@ Polaris can be run in three different modes:
|
||||
<img src="/img/FW_Insights_Polaris.svg" alt="Fairwinds Insights" width="550"/>
|
||||
</p>
|
||||
|
||||
[Fairwinds Insights](https://www.fairwinds.com/insights?utm_campaign=Hosted%20Polaris%20&utm_source=polaris&utm_term=polaris&utm_content=polaris)
|
||||
[Fairwinds Insights](https://www.fairwinds.com/fairwinds-polaris-upgrade)
|
||||
is a platform for auditing Kubernetes clusters and enforcing policy. If you'd like to:
|
||||
* manage Polaris across a fleet of clusters
|
||||
* track findings over time
|
||||
@@ -1,4 +1,12 @@
|
||||
---
|
||||
meta:
|
||||
- name: description
|
||||
content: "Fairwinds Polaris | Documentation: Polaris can be run as an admission controller that acts as a validating webhook."
|
||||
---
|
||||
# Admission Controller
|
||||
> Want to manage the Admission Controller across multiple clusters? Check out
|
||||
> [Fairwinds Insights](https://www.fairwinds.com/fairwinds-polaris-upgrade)
|
||||
|
||||
Polaris can be run as an admission controller that acts as a validating webhook.
|
||||
This accepts the same configuration as the dashboard, and can run the same validations.
|
||||
|
||||
@@ -25,7 +33,7 @@ kubectl apply -f https://github.com/fairwindsops/polaris/releases/latest/downloa
|
||||
### Helm
|
||||
```bash
|
||||
helm repo add fairwinds-stable https://charts.fairwinds.com/stable
|
||||
helm upgrade --install polaris fairwinds-stable/polaris --namespace polaris \
|
||||
helm upgrade --install polaris fairwinds-stable/polaris --namespace polaris --create-namespace \
|
||||
--set webhook.enable=true --set dashboard.enable=false
|
||||
```
|
||||
|
||||
@@ -1,45 +0,0 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en-US">
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<meta name="viewport" content="width=device-width,initial-scale=1">
|
||||
<title>Admission Controller | Fairwinds Polaris Documentation</title>
|
||||
<meta name="generator" content="VuePress 1.7.1">
|
||||
<link rel="icon" href="/favicon.png">
|
||||
<script src="/scripts/modify.js"></script>
|
||||
<script src="/scripts/leadlander.js"></script>
|
||||
<meta name="description" content="Documentation for Fairwinds Polaris - audit and enforce Kubernetes best practices for your workloads">
|
||||
|
||||
<link rel="preload" href="/assets/css/0.styles.db69974e.css" as="style"><link rel="preload" href="/assets/js/app.65b94829.js" as="script"><link rel="preload" href="/assets/js/3.0cb25b42.js" as="script"><link rel="preload" href="/assets/js/2.28adca5d.js" as="script"><link rel="preload" href="/assets/js/9.4f55b6b3.js" as="script"><link rel="prefetch" href="/assets/js/10.9d1a1701.js"><link rel="prefetch" href="/assets/js/11.d7eadcf0.js"><link rel="prefetch" href="/assets/js/12.85c0eab0.js"><link rel="prefetch" href="/assets/js/13.0487faf0.js"><link rel="prefetch" href="/assets/js/14.60ea393e.js"><link rel="prefetch" href="/assets/js/15.00f25aaa.js"><link rel="prefetch" href="/assets/js/16.cb0515ce.js"><link rel="prefetch" href="/assets/js/17.013e9969.js"><link rel="prefetch" href="/assets/js/18.a0fcb2d2.js"><link rel="prefetch" href="/assets/js/19.9fe045af.js"><link rel="prefetch" href="/assets/js/20.5bcacf34.js"><link rel="prefetch" href="/assets/js/21.2f58615f.js"><link rel="prefetch" href="/assets/js/22.90ebc6b9.js"><link rel="prefetch" href="/assets/js/4.be9896b6.js"><link rel="prefetch" href="/assets/js/5.665b3e6a.js"><link rel="prefetch" href="/assets/js/6.a5e340ed.js"><link rel="prefetch" href="/assets/js/7.dbd47d64.js"><link rel="prefetch" href="/assets/js/8.5a82b7c2.js">
|
||||
<link rel="stylesheet" href="/assets/css/0.styles.db69974e.css">
|
||||
</head>
|
||||
<body>
|
||||
<div id="app" data-server-rendered="true"><div class="theme-container"><header class="navbar"><div class="sidebar-button"><svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" role="img" viewBox="0 0 448 512" class="icon"><path fill="currentColor" d="M436 124H12c-6.627 0-12-5.373-12-12V80c0-6.627 5.373-12 12-12h424c6.627 0 12 5.373 12 12v32c0 6.627-5.373 12-12 12zm0 160H12c-6.627 0-12-5.373-12-12v-32c0-6.627 5.373-12 12-12h424c6.627 0 12 5.373 12 12v32c0 6.627-5.373 12-12 12zm0 160H12c-6.627 0-12-5.373-12-12v-32c0-6.627 5.373-12 12-12h424c6.627 0 12 5.373 12 12v32c0 6.627-5.373 12-12 12z"></path></svg></div> <a href="/" class="home-link router-link-active"><img src="/img/fairwinds-logo.svg" alt="Fairwinds Polaris Documentation" class="logo"> <span class="site-name can-hide">Fairwinds Polaris Documentation</span></a> <div class="links"><div class="search-box"><input aria-label="Search" autocomplete="off" spellcheck="false" value=""> <!----></div> <nav class="nav-links can-hide"><div class="nav-item"><a href="https://github.com/FairwindsOps/polaris" target="_blank" rel="noopener noreferrer" class="nav-link external">
|
||||
View on GitHub
|
||||
<span><svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" focusable="false" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg> <span class="sr-only">(opens new window)</span></span></a></div> <!----></nav></div></header> <div class="sidebar-mask"></div> <aside class="sidebar"><nav class="nav-links"><div class="nav-item"><a href="https://github.com/FairwindsOps/polaris" target="_blank" rel="noopener noreferrer" class="nav-link external">
|
||||
View on GitHub
|
||||
<span><svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" focusable="false" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg> <span class="sr-only">(opens new window)</span></span></a></div> <!----></nav> <ul class="sidebar-links"><li><section class="sidebar-group depth-0"><a href="/" class="sidebar-heading clickable router-link-active"><span>Polaris</span> <!----></a> <ul class="sidebar-links sidebar-group-items"><li><a href="/changelog/" class="sidebar-link">Changelog</a></li><li><a href="/code-of-conduct/" class="sidebar-link">Code of Conduct</a></li><li><a href="/contributing/" class="sidebar-link">Contributing</a></li></ul></section></li><li><section class="sidebar-group depth-0"><p class="sidebar-heading open"><span>Ways to Run Polaris</span> <!----></p> <ul class="sidebar-links sidebar-group-items"><li><a href="/dashboard/" class="sidebar-link">Dashboard</a></li><li><a href="/admission-controller/" aria-current="page" class="active sidebar-link">Admission Controller</a><ul class="sidebar-sub-headers"><li class="sidebar-sub-header"><a href="/admission-controller/#installation" class="sidebar-link">Installation</a></li><li class="sidebar-sub-header"><a href="/admission-controller/#workload-types" class="sidebar-link">Workload Types</a></li><li class="sidebar-sub-header"><a href="/admission-controller/#warnings" class="sidebar-link">Warnings</a></li></ul></li><li><a href="/infrastructure-as-code/" class="sidebar-link">Infrastructure as Code</a></li></ul></section></li><li><section class="sidebar-group depth-0"><p class="sidebar-heading"><span>Customization</span> <!----></p> <ul class="sidebar-links sidebar-group-items"><li><a href="/customization/configuration/" class="sidebar-link">Configuration</a></li><li><a href="/customization/checks/" class="sidebar-link">Check Settings</a></li><li><a href="/customization/custom-checks/" class="sidebar-link">Custom Checks</a></li><li><a href="/customization/exemptions/" class="sidebar-link">Exemptions</a></li></ul></section></li><li><section class="sidebar-group depth-0"><p class="sidebar-heading"><span>Checks</span> <!----></p> <ul class="sidebar-links sidebar-group-items"><li><a href="/checks/security/" class="sidebar-link">Security</a></li><li><a href="/checks/efficiency/" class="sidebar-link">Efficiency</a></li><li><a href="/checks/reliability/" class="sidebar-link">Reliability</a></li></ul></section></li></ul> </aside> <main class="page"> <div class="theme-default-content content__default"><h1 id="admission-controller"><a href="#admission-controller" class="header-anchor">#</a> Admission Controller</h1> <p>Polaris can be run as an admission controller that acts as a validating webhook.
|
||||
This accepts the same configuration as the dashboard, and can run the same validations.</p> <p>The webhook will reject any workloads that trigger a danger-level check.
|
||||
This is indicative of the greater goal of Polaris, not just to encourage better
|
||||
configuration through dashboard visibility, but to actually enforce it with this webhook.</p> <p>Note that Polaris will not alter your workloads, only block workloads that don't conform to the configured policies.</p> <h2 id="installation"><a href="#installation" class="header-anchor">#</a> Installation</h2> <h3 id="kubectl"><a href="#kubectl" class="header-anchor">#</a> kubectl</h3> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl apply -f https://github.com/fairwindsops/polaris/releases/latest/download/webhook.yaml
|
||||
</code></pre></div><h3 id="helm"><a href="#helm" class="header-anchor">#</a> Helm</h3> <div class="language-bash extra-class"><pre class="language-bash"><code>helm repo <span class="token function">add</span> fairwindsops-stable https://charts.fairwindsops.com/stable
|
||||
helm upgrade --install polaris fairwindsops-stable/polaris --namespace polaris <span class="token punctuation">\</span>
|
||||
--set webhook.enable<span class="token operator">=</span>true --set dashboard.enable<span class="token operator">=</span>false
|
||||
</code></pre></div><h2 id="workload-types"><a href="#workload-types" class="header-anchor">#</a> Workload Types</h2> <p>The webhook comes with built-in support for a handful of known controller types,
|
||||
such as Deployments, Jobs, and DaemonSets. To add new controller types,
|
||||
you can set <code>webhook.rules</code> in the
|
||||
<a href="https://github.com/FairwindsOps/charts/tree/master/stable/polaris" target="_blank" rel="noopener noreferrer">Helm chart<span><svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" focusable="false" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg> <span class="sr-only">(opens new window)</span></span></a></p> <h2 id="warnings"><a href="#warnings" class="header-anchor">#</a> Warnings</h2> <p>Unfortunately we have not found a way to display warnings as part of <code>kubectl</code>
|
||||
output unless we are rejecting a workload altogether.</p> <p>This means that any checks with a severity of <code>warning</code> will still pass webhook validation,
|
||||
and the only evidence of that warning will either be in the Polaris dashboard or the
|
||||
Polaris webhook logs. This will change in a future version of Kubernetes.</p></div> <footer class="page-edit"><div class="edit-link"><a href="https://github.com/FairwindsOps/polaris/edit/master/docs-md/admission-controller.md" target="_blank" rel="noopener noreferrer">Help us improve this page</a> <span><svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" focusable="false" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg> <span class="sr-only">(opens new window)</span></span></div> <!----></footer> <div class="page-nav"><p class="inner"><span class="prev">
|
||||
←
|
||||
<a href="/dashboard/" class="prev">
|
||||
Dashboard
|
||||
</a></span> <span class="next"><a href="/infrastructure-as-code/">
|
||||
Infrastructure as Code
|
||||
</a>
|
||||
→
|
||||
</span></p></div> <div class="custom-footer"><div class="left-footer"><a href="https://fairwinds.com" target="_blank">Learn more about Fairwinds</a> <a href="https://fairwinds.com/insights" target="_blank">Try Fairwinds Insights</a></div> <div class="right-footer"><a href="https://www.fairwinds.com/privacy-policy" target="_blank">Privacy Policy</a></div></div></main></div><div class="global-ui"></div></div>
|
||||
<script src="/assets/js/app.65b94829.js" defer></script><script src="/assets/js/3.0cb25b42.js" defer></script><script src="/assets/js/2.28adca5d.js" defer></script><script src="/assets/js/9.4f55b6b3.js" defer></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -1 +0,0 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?><svg xmlns="http://www.w3.org/2000/svg" width="12" height="13"><g stroke-width="2" stroke="#aaa" fill="none"><path d="M11.29 11.71l-4-4"/><circle cx="5" cy="5" r="4"/></g></svg>
|
||||
|
Before Width: | Height: | Size: 216 B |
@@ -1 +0,0 @@
|
||||
(window.webpackJsonp=window.webpackJsonp||[]).push([[11],{373:function(e,t,r){"use strict";r.r(t);var s=r(42),o=Object(s.a)({},(function(){var e=this,t=e.$createElement,r=e._self._c||t;return r("ContentSlotsDistributor",{attrs:{"slot-key":e.$parent.slotKey}},[r("h1",{attrs:{id:"efficiency"}},[r("a",{staticClass:"header-anchor",attrs:{href:"#efficiency"}},[e._v("#")]),e._v(" Efficiency")]),e._v(" "),r("p",[e._v("These checks ensure that CPU and memory settings are configured, so that\nKubernetes can schedule your workload effectively.")]),e._v(" "),r("h2",{attrs:{id:"presence-checks"}},[r("a",{staticClass:"header-anchor",attrs:{href:"#presence-checks"}},[e._v("#")]),e._v(" Presence Checks")]),e._v(" "),r("p",[e._v("To simplify ensure that these values have been set, the following attributes are available:")]),e._v(" "),r("table",[r("thead",[r("tr",[r("th",[e._v("key")]),e._v(" "),r("th",[e._v("default")]),e._v(" "),r("th",[e._v("description")])])]),e._v(" "),r("tbody",[r("tr",[r("td",[r("code",[e._v("resources.cpuRequestsMissing")])]),e._v(" "),r("td",[r("code",[e._v("warning")])]),e._v(" "),r("td",[e._v("Fails when "),r("code",[e._v("resources.requests.cpu")]),e._v(" attribute is not configured.")])]),e._v(" "),r("tr",[r("td",[r("code",[e._v("resources.memoryRequestsMissing")])]),e._v(" "),r("td",[r("code",[e._v("warning")])]),e._v(" "),r("td",[e._v("Fails when "),r("code",[e._v("resources.requests.memory")]),e._v(" attribute is not configured.")])]),e._v(" "),r("tr",[r("td",[r("code",[e._v("resources.cpuLimitsMissing")])]),e._v(" "),r("td",[r("code",[e._v("warning")])]),e._v(" "),r("td",[e._v("Fails when "),r("code",[e._v("resources.limits.cpu")]),e._v(" attribute is not configured.")])]),e._v(" "),r("tr",[r("td",[r("code",[e._v("resources.memoryLimitsMissing")])]),e._v(" "),r("td",[r("code",[e._v("warning")])]),e._v(" "),r("td",[e._v("Fails when "),r("code",[e._v("resources.limits.memory")]),e._v(" attribute is not configured.")])])])]),e._v(" "),r("h2",{attrs:{id:"background"}},[r("a",{staticClass:"header-anchor",attrs:{href:"#background"}},[e._v("#")]),e._v(" Background")]),e._v(" "),r("p",[e._v("Configuring resource requests and limits for containers running in Kubernetes is an important best practice to follow. Setting appropriate resource requests will ensure that all your applications have sufficient compute resources. Setting appropriate resource limits will ensure that your applications do not consume too many resources.")]),e._v(" "),r("p",[e._v("Having these values appropriately configured ensures that:")]),e._v(" "),r("ul",[r("li",[r("p",[e._v("Cluster autoscaling can function as intended. New nodes are scheduled once pods are unable to be scheduled on an existing node due to insufficient resources. This will not happen if resource requests are not configured.")])]),e._v(" "),r("li",[r("p",[e._v("Each container has sufficient access to compute resources. Without resource requests, a pod may be scheduled on a node that is already overutilized. Without resource limits, a single poorly behaving pod could utilize the majority of resources on a node, significantly impacting the performance of other pods on the same node.")])])]),e._v(" "),r("h2",{attrs:{id:"further-reading"}},[r("a",{staticClass:"header-anchor",attrs:{href:"#further-reading"}},[e._v("#")]),e._v(" Further Reading")]),e._v(" "),r("ul",[r("li",[r("a",{attrs:{href:"https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/",target:"_blank",rel:"noopener noreferrer"}},[e._v("Kubernetes Docs: Managing Compute Resources for Containers"),r("OutboundLink")],1)]),e._v(" "),r("li",[r("a",{attrs:{href:"https://cloud.google.com/blog/products/gcp/kubernetes-best-practices-resource-requests-and-limits",target:"_blank",rel:"noopener noreferrer"}},[e._v("Kubernetes best practices: Resource requests and limits"),r("OutboundLink")],1)]),e._v(" "),r("li",[r("a",{attrs:{href:"https://github.com/kubernetes/autoscaler/tree/master/vertical-pod-autoscaler",target:"_blank",rel:"noopener noreferrer"}},[e._v("Vertical Pod Autoscaler (can automatically set resource requests and limits)"),r("OutboundLink")],1)])])])}),[],!1,null,null,null);t.default=o.exports}}]);
|
||||
@@ -1 +0,0 @@
|
||||
(window.webpackJsonp=window.webpackJsonp||[]).push([[14],{371:function(e,n,t){"use strict";t.r(n);var s=t(42),i=Object(s.a)({},(function(){var e=this.$createElement,n=this._self._c||e;return n("ContentSlotsDistributor",{attrs:{"slot-key":this.$parent.slotKey}},[n("h4",{attrs:{id:"cli-options"}},[n("a",{staticClass:"header-anchor",attrs:{href:"#cli-options"}},[this._v("#")]),this._v(" CLI Options")]),this._v(" "),n("div",{staticClass:"language- extra-class"},[n("pre",{pre:!0,attrs:{class:"language-text"}},[n("code",[this._v('# top-level commands\naudit\n Runs a one-time audit.\ndashboard\n Runs the webserver for Polaris dashboard.\nhelp\n Prints help, if you give it a command then it will print help for that command. Same as -h\nversion\n Prints the version of Polaris\nwebhook\n Runs the webhook webserver\n\n# high-level flags\n-c, --config string\n Location of Polaris configuration file\n--disallow-exemptions\n Disallow any exemptions from configuration file.\n-h, --help\n Help for Polaris (same as help command)\n--kubeconfig string\n Path to a kubeconfig. Only required if out-of-cluster.\n--log-level string\n Logrus log level (default "info")\n--master string\n The address of the Kubernetes API server. Overrides any value in kubeconfig. Only required if out-of-cluster.\n\n# dashboard flags\n--audit-path string\n If specified, audits one or more YAML files instead of a cluster\n--base-path string\n Path on which the dashboard is served (default "/")\n--display-name string\n An optional identifier for the audit\n--load-audit-file string\n Runs the dashboard with data saved from a past audit.\n-p, --port int\n Port for the dashboard webserver (default 8080)\n\n# audit flags\n--audit-path string\n If specified, audits one or more YAML files instead of a cluster\n--resource string\n If specified, audit a specific resource, in the format namespace/kind/version/name, e.g. nginx-ingress/Deployment.apps/v1/default-backend\n--display-name string\n An optional identifier for the audit\n--format string\n Output format for results - json, yaml, or score (default "json")\n--output-file string\n Destination file for audit results\n--output-url string\n Destination URL to send audit results\n--set-exit-code-below-score int\n Set an exit code of 4 when the score is below this threshold (1-100)\n--set-exit-code-on-danger\n Set an exit code of 3 when the audit contains danger-level issues.\n\n# webhook flags\n--disable-webhook-config-installer\n disable the installer in the webhook server, so it won\'t install webhook configuration resources during bootstrapping\n-p, --port int\n Port for the webhook webserver (default 9876)\n')])])])])}),[],!1,null,null,null);n.default=i.exports}}]);
|
||||
@@ -1 +0,0 @@
|
||||
(window.webpackJsonp=window.webpackJsonp||[]).push([[17],{368:function(e,t,a){"use strict";a.r(t);var s=a(42),n=Object(s.a)({},(function(){var e=this,t=e.$createElement,a=e._self._c||t;return a("ContentSlotsDistributor",{attrs:{"slot-key":e.$parent.slotKey}},[a("h1",{attrs:{id:"check-settings"}},[a("a",{staticClass:"header-anchor",attrs:{href:"#check-settings"}},[e._v("#")]),e._v(" Check Settings")]),e._v(" "),a("p",[e._v("Each check can be assigned a "),a("code",[e._v("severity")]),e._v(". Only checks with a severity of "),a("code",[e._v("danger")]),e._v(" or "),a("code",[e._v("warning")]),e._v(" will be validated. The results of these validations are visible on the dashboard. In the case of the validating webhook, only failures with a severity of "),a("code",[e._v("danger")]),e._v(" will result in a change being rejected.")]),e._v(" "),a("p",[e._v("Polaris validation checks fall into several different categories:")]),e._v(" "),a("ul",[a("li",[a("RouterLink",{attrs:{to:"/checks/security.html"}},[e._v("Security")])],1),e._v(" "),a("li",[a("RouterLink",{attrs:{to:"/checks/reliability.html"}},[e._v("Reliability")])],1),e._v(" "),a("li",[a("RouterLink",{attrs:{to:"/checks/efficiency.html"}},[e._v("Efficiency")])],1)]),e._v(" "),a("p",[e._v("To change the default severity levels, or to turn checks on or off, you can create your own "),a("code",[e._v("config.yaml")]),e._v(":")]),e._v(" "),a("div",{staticClass:"language-yaml extra-class"},[a("pre",{pre:!0,attrs:{class:"language-yaml"}},[a("code",[a("span",{pre:!0,attrs:{class:"token key atrule"}},[e._v("checks")]),a("span",{pre:!0,attrs:{class:"token punctuation"}},[e._v(":")]),e._v("\n "),a("span",{pre:!0,attrs:{class:"token key atrule"}},[e._v("tagNotSpecified")]),a("span",{pre:!0,attrs:{class:"token punctuation"}},[e._v(":")]),e._v(" ignore\n "),a("span",{pre:!0,attrs:{class:"token key atrule"}},[e._v("runAsRootAllowed")]),a("span",{pre:!0,attrs:{class:"token punctuation"}},[e._v(":")]),e._v(" danger\n "),a("span",{pre:!0,attrs:{class:"token key atrule"}},[e._v("pullPolicyNotAlways")]),a("span",{pre:!0,attrs:{class:"token punctuation"}},[e._v(":")]),e._v(" warning\n")])])])])}),[],!1,null,null,null);t.default=n.exports}}]);
|
||||
@@ -1 +0,0 @@
|
||||
(window.webpackJsonp=window.webpackJsonp||[]).push([[18],{369:function(t,o,e){"use strict";e.r(o);var n=e(42),i=Object(n.a)({},(function(){var t=this,o=t.$createElement,e=t._self._c||o;return e("ContentSlotsDistributor",{attrs:{"slot-key":t.$parent.slotKey}},[e("h1",{attrs:{id:"configuration"}},[e("a",{staticClass:"header-anchor",attrs:{href:"#configuration"}},[t._v("#")]),t._v(" Configuration")]),t._v(" "),e("p",[t._v("The default Polaris configuration can be "),e("a",{attrs:{href:"https://github.com/FairwindsOps/polaris/blob/master/examples/config.yaml",target:"_blank",rel:"noopener noreferrer"}},[t._v("seen here"),e("OutboundLink")],1),t._v(".")]),t._v(" "),e("p",[t._v("You can customize the configuration to do things like:")]),t._v(" "),e("ul",[e("li",[t._v("Turn checks "),e("RouterLink",{attrs:{to:"/customization/checks.html"}},[t._v("on and off")])],1),t._v(" "),e("li",[t._v("Change the "),e("RouterLink",{attrs:{to:"/customization/checks.html"}},[t._v("severity level")]),t._v(" of checks")],1),t._v(" "),e("li",[t._v("Add new "),e("RouterLink",{attrs:{to:"/customization/custom-checks.html"}},[t._v("custom checks")])],1),t._v(" "),e("li",[t._v("Add "),e("RouterLink",{attrs:{to:"/customization/exemptions.html"}},[t._v("exemptions")]),t._v(" for particular workloads or namespaces")],1)]),t._v(" "),e("p",[t._v("To pass in your custom configuration, follow the instructions for your environment:")]),t._v(" "),e("ul",[e("li",[t._v("CLI - set the "),e("code",[t._v("--config")]),t._v(" argument to point to your "),e("code",[t._v("config.yaml")])]),t._v(" "),e("li",[t._v("Helm - set the "),e("code",[t._v("config")]),t._v(" variable in your values file")]),t._v(" "),e("li",[t._v("kubectl - create a ConfigMap with your "),e("code",[t._v("config.yaml")]),t._v(", mount it as a volume, and use the "),e("code",[t._v("--config")]),t._v(" argument in your Deployment")])])])}),[],!1,null,null,null);o.default=i.exports}}]);
|
||||
@@ -1 +0,0 @@
|
||||
(window.webpackJsonp=window.webpackJsonp||[]).push([[20],{376:function(t,a,e){"use strict";e.r(a);var s=e(42),n=Object(s.a)({},(function(){var t=this,a=t.$createElement,e=t._self._c||a;return e("ContentSlotsDistributor",{attrs:{"slot-key":t.$parent.slotKey}},[e("h1",{attrs:{id:"exemptions"}},[e("a",{staticClass:"header-anchor",attrs:{href:"#exemptions"}},[t._v("#")]),t._v(" Exemptions")]),t._v(" "),e("p",[t._v("Sometimes a workload really does need to do things that Polaris considers insecure. For instance,\nmany of the "),e("code",[t._v("kube-system")]),t._v(" workloads need to run as root, or need access to the host network. In these\ncases, we can add "),e("strong",[t._v("exemptions")]),t._v(" to allow the workload to pass Polaris checks.")]),t._v(" "),e("p",[t._v("Exemptions can be added two ways: by annotating a controller, or editing the Polaris config.")]),t._v(" "),e("h2",{attrs:{id:"annotations"}},[e("a",{staticClass:"header-anchor",attrs:{href:"#annotations"}},[t._v("#")]),t._v(" Annotations")]),t._v(" "),e("p",[t._v("To exempt a controller from all checks via annotations, use the annotation "),e("code",[t._v("polaris.fairwinds.com/exempt=true")]),t._v(", e.g.")]),t._v(" "),e("div",{staticClass:"language- extra-class"},[e("pre",{pre:!0,attrs:{class:"language-text"}},[e("code",[t._v("kubectl annotate deployment my-deployment polaris.fairwinds.com/exempt=true\n")])])]),e("p",[t._v("To exempt a controller from a particular check via annotations, use an annotation in the form of "),e("code",[t._v("polaris.fairwinds.com/<check>-exempt=true")]),t._v(", e.g.")]),t._v(" "),e("div",{staticClass:"language- extra-class"},[e("pre",{pre:!0,attrs:{class:"language-text"}},[e("code",[t._v("kubectl annotate deployment my-deployment polaris.fairwinds.com/cpuRequestsMissing-exempt=true\n")])])]),e("h2",{attrs:{id:"config"}},[e("a",{staticClass:"header-anchor",attrs:{href:"#config"}},[t._v("#")]),t._v(" Config")]),t._v(" "),e("p",[t._v("To exempt a controller via the config, you have to specify a namespace (optional), a list of controller names and a list of rules, e.g.")]),t._v(" "),e("div",{staticClass:"language-yaml extra-class"},[e("pre",{pre:!0,attrs:{class:"language-yaml"}},[e("code",[e("span",{pre:!0,attrs:{class:"token key atrule"}},[t._v("exemptions")]),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v(":")]),t._v("\n "),e("span",{pre:!0,attrs:{class:"token comment"}},[t._v("# exemption valid for kube-system namespace")]),t._v("\n "),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v("-")]),t._v(" "),e("span",{pre:!0,attrs:{class:"token key atrule"}},[t._v("namespace")]),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v(":")]),t._v(" kube"),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v("-")]),t._v("system\n "),e("span",{pre:!0,attrs:{class:"token key atrule"}},[t._v("controllerNames")]),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v(":")]),t._v("\n "),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v("-")]),t._v(" dns"),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v("-")]),t._v("controller\n "),e("span",{pre:!0,attrs:{class:"token key atrule"}},[t._v("rules")]),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v(":")]),t._v("\n "),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v("-")]),t._v(" hostNetworkSet\n "),e("span",{pre:!0,attrs:{class:"token comment"}},[t._v("# exemption valid in all namespaces")]),t._v("\n "),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v("-")]),t._v(" "),e("span",{pre:!0,attrs:{class:"token key atrule"}},[t._v("controllerNames")]),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v(":")]),t._v("\n "),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v("-")]),t._v(" dns"),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v("-")]),t._v("controller\n "),e("span",{pre:!0,attrs:{class:"token key atrule"}},[t._v("rules")]),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v(":")]),t._v("\n "),e("span",{pre:!0,attrs:{class:"token punctuation"}},[t._v("-")]),t._v(" hostNetworkSet\n")])])])])}),[],!1,null,null,null);a.default=n.exports}}]);
|
||||
@@ -1 +0,0 @@
|
||||
(window.webpackJsonp=window.webpackJsonp||[]).push([[22],{372:function(e,a,s){"use strict";s.r(a);var t=s(42),n=Object(t.a)({},(function(){var e=this,a=e.$createElement,s=e._self._c||a;return s("ContentSlotsDistributor",{attrs:{"slot-key":e.$parent.slotKey}},[s("h1",{attrs:{id:"infrastructure-as-code"}},[s("a",{staticClass:"header-anchor",attrs:{href:"#infrastructure-as-code"}},[e._v("#")]),e._v(" Infrastructure as Code")]),e._v(" "),s("p",[e._v("Polaris can be used on the command line to audit local Kubernetes manifests stored in YAML files.\nThis is particularly helpful for running Polaris against your infrastructure-as-code as part of a\nCI/CD pipeline. Use the available "),s("a",{attrs:{href:"#running-in-a-ci-pipeline"}},[e._v("command line flags")]),e._v("\nto cause CI/CD to fail if your Polaris score drops below a certain threshold, or if any danger-level issues arise.")]),e._v(" "),s("h2",{attrs:{id:"install-the-cli"}},[s("a",{staticClass:"header-anchor",attrs:{href:"#install-the-cli"}},[e._v("#")]),e._v(" Install the CLI")]),e._v(" "),s("p",[e._v("To run Polaris against your YAML manifests, e.g. as part of a Continuous Integration process,\nyou'll need to install the CLI.")]),e._v(" "),s("p",[e._v("Binary releases can be downloaded from the "),s("a",{attrs:{href:"https://github.com/fairwindsops/polaris/releases",target:"_blank",rel:"noopener noreferrer"}},[e._v("releases page"),s("OutboundLink")],1),e._v("\nor can be installed with "),s("a",{attrs:{href:"https://brew.sh/",target:"_blank",rel:"noopener noreferrer"}},[e._v("Homebrew"),s("OutboundLink")],1),e._v(":")]),e._v(" "),s("div",{staticClass:"language-bash extra-class"},[s("pre",{pre:!0,attrs:{class:"language-bash"}},[s("code",[e._v("brew tap FairwindsOps/tap\nbrew "),s("span",{pre:!0,attrs:{class:"token function"}},[e._v("install")]),e._v(" FairwindsOps/tap/polaris\npolaris version\n")])])]),s("h2",{attrs:{id:"running-in-a-ci-pipeline"}},[s("a",{staticClass:"header-anchor",attrs:{href:"#running-in-a-ci-pipeline"}},[e._v("#")]),e._v(" Running in a CI pipeline")]),e._v(" "),s("p",[e._v("You can tell the CLI to set an exit code if it detects certain issues with your\nYAML files.\nFor example, to fail if polaris detects "),s("em",[e._v("any")]),e._v(" danger-level issues, or if the score drops below 90%:")]),e._v(" "),s("div",{staticClass:"language-bash extra-class"},[s("pre",{pre:!0,attrs:{class:"language-bash"}},[s("code",[e._v("polaris audit --audit-path ./deploy/ "),s("span",{pre:!0,attrs:{class:"token punctuation"}},[e._v("\\")]),e._v("\n --set-exit-code-on-danger "),s("span",{pre:!0,attrs:{class:"token punctuation"}},[e._v("\\")]),e._v("\n --set-exit-code-below-score "),s("span",{pre:!0,attrs:{class:"token number"}},[e._v("90")]),e._v("\n")])])])])}),[],!1,null,null,null);a.default=n.exports}}]);
|
||||