Skip to content

Commit 4d5254f

Browse files
IgorEulaliomavimodraios-jenkinsdraios-jenkinsaroberts87
authored
feat(cluster-scanner): add verify registry as option in values (#1516)
Co-authored-by: Marco Vito Moscaritolo <[email protected]> Co-authored-by: draios-jenkins <[email protected]> Co-authored-by: draios-jenkins <[email protected]> Co-authored-by: aroberts87 <[email protected]> Co-authored-by: chen-shmilovich-sysdig <[email protected]> Co-authored-by: Fede Barcelona <[email protected]> Co-authored-by: hayk99 <[email protected]>
1 parent 96ead14 commit 4d5254f

File tree

6 files changed

+19
-7
lines changed

6 files changed

+19
-7
lines changed

charts/cluster-scanner/Chart.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Sysdig Cluster Scanner
44

55
type: application
66

7-
version: 0.8.4
7+
version: 0.8.5
88

99
appVersion: "0.1.0"
1010
home: https://www.sysdig.com/

charts/cluster-scanner/README.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ $ pre-commit run -a
2525
$ helm repo add sysdig https://charts.sysdig.com
2626
$ helm repo update
2727
$ helm upgrade --install sysdig-cluster-scanner sysdig/cluster-scanner \
28-
--create-namespace -n sysdig --version=0.8.4 \
28+
--create-namespace -n sysdig --version=0.8.5 \
2929
--set global.clusterConfig.name=CLUSTER_NAME \
3030
--set global.sysdig.region=SYSDIG_REGION \
3131
--set global.sysdig.accessKey=YOUR-KEY-HERE
@@ -55,7 +55,7 @@ To install the chart with the release name `cluster-scanner`, run:
5555

5656
```console
5757
$ helm upgrade --install sysdig-cluster-scanner sysdig/cluster-scanner \
58-
--create-namespace -n sysdig --version=0.8.4 \
58+
--create-namespace -n sysdig --version=0.8.5 \
5959
--set global.clusterConfig.name=CLUSTER_NAME \
6060
--set global.sysdig.region=SYSDIG_REGION \
6161
--set global.sysdig.accessKey=YOUR-KEY-HERE
@@ -107,6 +107,7 @@ The following table lists the configurable parameters of the `cluster-scanner` c
107107
| replicaCount | | <code>2</code> |
108108
| scannerMode | The scannerMode of the Cluster Scanner. Supported values are `local` or `multi`. Please refer to docs.sysdig.com for further documentation. | <code>"local"</code> |
109109
| sslVerifyCertificate | Optional parameter used to check the compatibility of cluster-scanner component versions with the on-premised backend version. If you are running an on-prem version of the Sysdig backend, you MUST set this parameter with the version of Sysdig backend you are using. If you are runinng on SaaS, do NOT provide this parameter. E.g. if `onPremCompatibilityVersion=6.2`, we ensure that the image tag is < 0.5.0 for both the Runtime Status Integrator and the Image SBOM Extractor. onPremCompatibilityVersion: "6.2" Can be set to false to allow insecure connections to the Sysdig backend, such as for on-premise installs that use self-signed certificates. By default, certificates are always verified. | <code>true</code> |
110+
| sslVerifyRegistryCertificate | Can be set to false to allow insecure connections registries, Such as for registries with self-signed or private certificates. By default, certificates are always verified. | <code>true</code> |
110111
| runtimeStatusIntegrator.image.registry | The image registry to use for the Runtime Status Integrator component of Cluster Scanner | <code>quay.io</code> |
111112
| runtimeStatusIntegrator.image.repository | The image repository to use for pulling the Runtime Status Integrator image | <code>sysdig/runtime-status-integrator</code> |
112113
| runtimeStatusIntegrator.image.tag | | <code>"0.5.3"</code> |
@@ -161,7 +162,7 @@ Specify each parameter using the **`--set key=value[,key=value]`** argument to `
161162

162163
```console
163164
$ helm upgrade --install sysdig-cluster-scanner sysdig/cluster-scanner \
164-
--create-namespace -n sysdig --version=0.8.4 \
165+
--create-namespace -n sysdig --version=0.8.5 \
165166
--set global.sysdig.region="us1"
166167
```
167168

@@ -170,7 +171,7 @@ installing the chart. For example:
170171

171172
```console
172173
$ helm upgrade --install sysdig-cluster-scanner sysdig/cluster-scanner \
173-
--create-namespace -n sysdig --version=0.8.4 \
174+
--create-namespace -n sysdig --version=0.8.5 \
174175
--values values.yaml
175176
```
176177

charts/cluster-scanner/templates/configmap.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ data:
1212
sysdig_host: https://{{ include "cluster-scanner.apiHost" . }}
1313
{{ end -}}
1414
sysdig_verify_certificate: {{ .Values.sslVerifyCertificate | quote }}
15+
sysdig_verify_registry_certificate: {{ .Values.sslVerifyRegistryCertificate | quote }}
1516
cluster_name: {{ .Values.global.clusterConfig.name }}
1617
root_namespace: {{ .Values.rootNamespace }}
1718
eve_enabled: {{ .Values.eveEnabled | quote }}

charts/cluster-scanner/templates/deployment.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -394,6 +394,12 @@ spec:
394394
name: {{ include "cluster-scanner.fullname" . }}
395395
key: sysdig_verify_certificate
396396
optional: true
397+
- name: REGISTRY_VERIFY_CERTIFICATE
398+
valueFrom:
399+
configMapKeyRef:
400+
name: {{ include "cluster-scanner.fullname" . }}
401+
key: sysdig_verify_registry_certificate
402+
optional: true
397403
- name: NATS_URL
398404
valueFrom:
399405
configMapKeyRef:

charts/cluster-scanner/values.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -96,6 +96,10 @@ scannerMode: "local"
9696
# By default, certificates are always verified.
9797
sslVerifyCertificate: true
9898

99+
# Can be set to false to allow insecure connections registries,
100+
# Such as for registries with self-signed or private certificates.
101+
# By default, certificates are always verified.
102+
sslVerifyRegistryCertificate: true
99103
runtimeStatusIntegrator:
100104
image:
101105
# The image registry to use for the Runtime Status Integrator component of

charts/sysdig-deploy/Chart.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ apiVersion: v2
22
name: sysdig-deploy
33
description: A chart with various Sysdig components for Kubernetes
44
type: application
5-
version: 1.32.0
5+
version: 1.32.1
66
maintainers:
77
- name: AlbertoBarba
88
@@ -42,7 +42,7 @@ dependencies:
4242
- name: cluster-scanner
4343
# repository: https://charts.sysdig.com
4444
repository: file://../cluster-scanner
45-
version: ~0.8.4
45+
version: ~0.8.5
4646
alias: clusterScanner
4747
condition: clusterScanner.enabled
4848
- name: kspm-collector

0 commit comments

Comments
 (0)