gatekeeper-library icon indicating copy to clipboard operation
gatekeeper-library copied to clipboard

Helm chart

Open kfox1111 opened this issue 4 years ago • 4 comments

It would be nice if the library could compile into an easy to use helm chart.

kfox1111 avatar Jan 27 '21 23:01 kfox1111

Maybe related to #47

kfox1111 avatar Jan 27 '21 23:01 kfox1111

Are you looking for helm chart for PSPs? In the past, we discussed aligning them into default, restricted buckets that's detailed under https://kubernetes.io/docs/concepts/security/pod-security-standards/. Is this close to what you are looking for?

sozercan avatar Jan 27 '21 23:01 sozercan

Yeah.

Maybe a chart that includes all the ConstraintTemplate's and then maybe some default disabled but easily enable-able default restricted buckets like those? That way its easy to load the library of ConstraintTemplates and enable them as you need them with some sane defaults?

kfox1111 avatar Jan 27 '21 23:01 kfox1111

Maybe useful to https://github.com/kubernetes/community/tree/master/wg-multitenancy as well.

kfox1111 avatar Jan 27 '21 23:01 kfox1111

This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

stale[bot] avatar Feb 01 '23 03:02 stale[bot]

Not stale, and related to #47 .

sathieu avatar Feb 01 '23 07:02 sathieu

This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

stale[bot] avatar Apr 02 '23 07:04 stale[bot]

not stale.

Having an helm chart would help installation.

sathieu avatar Apr 05 '23 05:04 sathieu

@kfox1111 @sathieu are you looking for specific groups of policies that can be part of a helm chart? Currently for validating policies, we have psp and general. are you looking for 1 helm chart for all psps (maybe filtered by PSS profile level) and 1 for all general policies or just a single helm chart for all?

Another concern: because each policy has its own version, it would be hard to determine how to update the chart's version whenever one of the policies bumps the version.

ritazh avatar Apr 05 '23 05:04 ritazh

@ritazh I think only one chart is needed (but I'm ok with having two).

On the versioning maybe we could use the max as chart version, and bump all policies to this same version?

Alternatively, the chart version can be independant, and bumped according to semantic versioning.

sathieu avatar Apr 05 '23 05:04 sathieu

I agree with the chart version being independent. Usually the Helm chart version is not tied to the application/library version. In a Chart.yaml file, you will typically find the arguments version and appVersion.

starlightromero avatar Jun 02 '23 03:06 starlightromero

This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

stale[bot] avatar Aug 01 '23 03:08 stale[bot]

another approach we discussed in the past was a CLI (similar to krew or brew), where users can add/remove/sync policies.

sozercan avatar Aug 02 '23 17:08 sozercan

CLI's are harder to integrate into CI/CD systems.

kfox1111 avatar Aug 02 '23 17:08 kfox1111

@kfox1111 would you elaborate more in your concerns? isn't helm a cli?

sozercan avatar Aug 02 '23 17:08 sozercan

It isn't when your using a tool such as https://fluxcd.io/ (like: https://fluxcd.io/flux/guides/helmreleases/) or argocd (like: https://argo-cd.readthedocs.io/en/stable/user-guide/helm/)

Kubernetes objects are how you are causing deployment of the charts.

kfox1111 avatar Aug 02 '23 18:08 kfox1111

Or in my case, using the Helm Terraform provider, the policies can be codified and on VCS push, a Terraform run is triggered in Terraform Cloud.

starlightromero avatar Sep 02 '23 02:09 starlightromero

@kfox1111 Would appreciate your feedback on PR #356

starlightromero avatar Sep 03 '23 05:09 starlightromero

This issue/PR has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.

stale[bot] avatar Nov 02 '23 08:11 stale[bot]

/repoen /notcompleted

kfox1111 avatar Nov 16 '23 21:11 kfox1111