try crowdsec
This commit is contained in:
2
.gitignore
vendored
2
.gitignore
vendored
@@ -1,5 +1,5 @@
|
|||||||
.DS_Store
|
.DS_Store
|
||||||
Chart.lock
|
Chart.lock
|
||||||
*/charts/*.tgz
|
*/charts/
|
||||||
.terraform
|
.terraform
|
||||||
.terraform.lock.hcl
|
.terraform.lock.hcl
|
||||||
@@ -3,3 +3,4 @@ tools:
|
|||||||
#- pgcat # trop contraignant: lister tous les databases/users et auth_type md5 uniquement
|
#- pgcat # trop contraignant: lister tous les databases/users et auth_type md5 uniquement
|
||||||
# - prometheus
|
# - prometheus
|
||||||
- hashicorp-vault
|
- hashicorp-vault
|
||||||
|
- crowdsec
|
||||||
23
crowdsec/.helmignore
Normal file
23
crowdsec/.helmignore
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
32
crowdsec/Chart.yaml
Normal file
32
crowdsec/Chart.yaml
Normal file
@@ -0,0 +1,32 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: crowdsec
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
dependencies:
|
||||||
|
- name: tool
|
||||||
|
version: 0.1.0
|
||||||
|
repository: https://gitea.arcodange.duckdns.org/api/packages/arcodange-org/helm
|
||||||
|
- name: crowdsec
|
||||||
|
version: 0.20.1
|
||||||
|
repository: https://crowdsecurity.github.io/helm-charts
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
# appVersion: "1.16.0"
|
||||||
3
crowdsec/templates/helm-chart-config.yaml
Normal file
3
crowdsec/templates/helm-chart-config.yaml
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
{{- if eq .Values.tool.kind "HelmChart" -}}
|
||||||
|
{{- include "tool.helm-chart-config.tpl" . -}}
|
||||||
|
{{- end -}}
|
||||||
3
crowdsec/templates/helm-chart.yaml
Normal file
3
crowdsec/templates/helm-chart.yaml
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
{{- if eq .Values.tool.kind "HelmChart" -}}
|
||||||
|
{{- include "tool.helm-chart.tpl" . -}}
|
||||||
|
{{- end -}}
|
||||||
41
crowdsec/values.yaml
Normal file
41
crowdsec/values.yaml
Normal file
@@ -0,0 +1,41 @@
|
|||||||
|
crowdsec: &crowdsec_config
|
||||||
|
# for raw logs format: json or cri (docker|containerd)
|
||||||
|
container_runtime: docker
|
||||||
|
agent:
|
||||||
|
# Specify each pod whose logs you want to process
|
||||||
|
acquisition:
|
||||||
|
# The namespace where the pod is located
|
||||||
|
- namespace: traefik
|
||||||
|
# The pod name
|
||||||
|
podName: traefik-*
|
||||||
|
# as in crowdsec configuration, we need to specify the program name to find a matching parser
|
||||||
|
program: traefik
|
||||||
|
env:
|
||||||
|
- name: COLLECTIONS
|
||||||
|
value: "crowdsecurity/traefik crowdsecurity/http-cve"
|
||||||
|
lapi:
|
||||||
|
env:
|
||||||
|
# To enroll the Security Engine to the console
|
||||||
|
- name: ENROLL_KEY
|
||||||
|
value: "cmieq72i3000802jr1wx8kply"
|
||||||
|
- name: ENROLL_INSTANCE_NAME
|
||||||
|
value: "homelab"
|
||||||
|
- name: ENROLL_TAGS
|
||||||
|
value: "k3s rpi test"
|
||||||
|
appsec:
|
||||||
|
enabled: true
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: "500m"
|
||||||
|
memory: "300Mi"
|
||||||
|
requests:
|
||||||
|
cpu: "100m"
|
||||||
|
memory: "200Mi"
|
||||||
|
|
||||||
|
tool:
|
||||||
|
# kind: 'SubChart' or 'HelmChart', if subchart then uncomment Chart.yaml dependency, else comment and use tool library with helm chart template
|
||||||
|
kind: 'SubChart'
|
||||||
|
repo: https://crowdsecurity.github.io/helm-charts
|
||||||
|
chart: crowdsec
|
||||||
|
version: 0.20.1
|
||||||
|
values: *crowdsec_config
|
||||||
Reference in New Issue
Block a user