Skip to content

Commit 16d4ea1

Browse files
authored
Merge pull request #9522 from zalando-incubator/vthupili
feat: WIZ Helm upgrade to recent version
2 parents 24bc9ac + 010bab7 commit 16d4ea1

11 files changed

+55
-44
lines changed

cluster/manifests/wiz/002-connector-broker-serviceaccount.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ metadata:
88
name: wiz-broker
99
namespace: "wiz"
1010
labels:
11-
helm.sh/chart: wiz-broker-2.1.0
11+
helm.sh/chart: wiz-broker-2.3.8
1212
application: "wiz"
1313
component: "connector"
1414
---
@@ -19,7 +19,7 @@ metadata:
1919
name: wiz-cluster-reader
2020
namespace: "wiz"
2121
labels:
22-
helm.sh/chart: wiz-broker-2.1.0
22+
helm.sh/chart: wiz-kubernetes-connector-3.3.11
2323
application: "wiz"
2424
component: "connector"
2525
{{end}}

cluster/manifests/wiz/002-connector-job-serviceaccount.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
name: wiz-auto-modify-connector
88
namespace: "wiz"
99
labels:
10-
helm.sh/chart: wiz-broker-2.1.0
10+
helm.sh/chart: wiz-kubernetes-connector-3.3.11
1111
application: "wiz"
1212
component: "connector"
13-
{{ end }}
13+
{{ end }}

cluster/manifests/wiz/002-sensor-serviceaccount.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
name: wiz-sensor
88
namespace: wiz
99
labels:
10-
helm.sh/chart: wiz-sensor-1.0.4760
10+
helm.sh/chart: wiz-sensor-1.0.6440
1111
application: "wiz"
1212
component: "connector"
1313
{{end}}

cluster/manifests/wiz/003-connector-broker-clusterrole.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ kind: ClusterRoleBinding
88
metadata:
99
name: wiz-cluster-reader
1010
labels:
11-
helm.sh/chart: wiz-broker-2.1.0
11+
helm.sh/chart: wiz-kubernetes-connector-3.3.11
1212
application: "wiz"
1313
component: "connector"
1414
roleRef:

cluster/manifests/wiz/003-connector-job-role.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
name: wiz-auto-modify-connector
88
namespace: "wiz"
99
labels:
10-
helm.sh/chart: wiz-broker-2.1.0
10+
helm.sh/chart: wiz-kubernetes-connector-3.3.11
1111
application: "wiz"
1212
component: "connector"
1313
rules:
@@ -29,7 +29,7 @@ metadata:
2929
name: wiz-auto-modify-connector
3030
namespace: "wiz"
3131
labels:
32-
helm.sh/chart: wiz-broker-2.1.0
32+
helm.sh/chart: wiz-kubernetes-connector-3.3.11
3333
application: "wiz"
3434
component: "connector"
3535
roleRef:

cluster/manifests/wiz/003-sensor-clusterrole.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ kind: ClusterRole
66
metadata:
77
name: wiz-sensor
88
labels:
9-
helm.sh/chart: wiz-sensor-1.0.4760
9+
helm.sh/chart: wiz-sensor-1.0.6440
1010
application: "wiz"
1111
component: "sensor"
1212
rules:
@@ -28,7 +28,7 @@ kind: ClusterRoleBinding
2828
metadata:
2929
name: wiz-sensor
3030
labels:
31-
helm.sh/chart: wiz-sensor-1.0.4760
31+
helm.sh/chart: wiz-sensor-1.0.6440
3232
application: "wiz"
3333
component: "sensor"
3434
subjects:

cluster/manifests/wiz/004-connector-broker-secrets.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ metadata:
99
name: wiz-connector-connector
1010
namespace: "wiz"
1111
labels:
12-
helm.sh/chart: wiz-broker-2.1.0
12+
helm.sh/chart: wiz-kubernetes-connector-3.3.11
1313
application: "wiz"
1414
component: "connector"
1515
type: Opaque
@@ -25,21 +25,21 @@ metadata:
2525
name: wiz-cluster-reader-token
2626
namespace: "wiz"
2727
labels:
28-
helm.sh/chart: wiz-broker-2.1.0
28+
helm.sh/chart: wiz-kubernetes-connector-3.3.11
2929
application: "wiz"
3030
component: "connector"
3131
annotations:
3232
kubernetes.io/service-account.name: wiz-cluster-reader
3333
type: kubernetes.io/service-account-token
3434
---
35-
# Source: wiz-sensor/templates/apikeysecret.yaml
35+
# Source: wiz-sensor/templates/secrets-wiz-api-token.yaml
3636
apiVersion: v1
3737
kind: Secret
3838
metadata:
3939
name: wiz-api-token
4040
namespace: wiz
4141
labels:
42-
helm.sh/chart: wiz-broker-2.1.0
42+
helm.sh/chart: wiz-kubernetes-integration-0.2.91
4343
application: "wiz"
4444
component: "connector"
4545
type: Opaque

cluster/manifests/wiz/004-sensor-secrets.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{{ if eq .Cluster.ConfigItems.wiz_enable_runtime_sensor "true"}}
22
---
3-
# Source: wiz-sensor/templates/apikeysecret.yaml
3+
# Source: wiz-sensor/templates/secrets-wiz-api-token.yaml
44
apiVersion: v1
55
kind: Secret
66
metadata:
77
name: wiz-sensor-apikey
88
namespace: wiz
99
labels:
10-
helm.sh/chart: wiz-sensor-1.0.4760
10+
helm.sh/chart: wiz-kubernetes-integration-0.2.91
1111
application: "wiz"
1212
component: "sensor"
1313
type: Opaque

cluster/manifests/wiz/005-connector-job.yaml

Lines changed: 12 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
name: wiz-kubernetes-connector-create-connector
88
namespace: "wiz"
99
labels:
10-
helm.sh/chart: wiz-broker-2.1.0
10+
helm.sh/chart: wiz-kubernetes-connector-3.3.11
1111
application: "wiz"
1212
component: "connector"
1313
job: "wiz-connector-agent"
@@ -21,7 +21,7 @@ spec:
2121
template:
2222
metadata:
2323
labels:
24-
helm.sh/chart: wiz-broker-2.1.0
24+
helm.sh/chart: wiz-kubernetes-connector-3.3.11
2525
application: "wiz"
2626
component: "connector"
2727
job: "wiz-connector-agent"
@@ -31,6 +31,10 @@ spec:
3131
securityContext:
3232
runAsNonRoot: true
3333
runAsUser: 1000
34+
volumes:
35+
- name: api-client
36+
secret:
37+
secretName: wiz-api-token
3438
containers:
3539
- name: wiz-connector-creator
3640
securityContext:
@@ -58,20 +62,10 @@ spec:
5862
- --connector-name
5963
- {{.Cluster.Alias}}
6064
env:
65+
- name: CLI_FILES_AS_ARGS
66+
value: "/var/api-client/clientToken,/var/api-client/clientId"
6167
- name: LOG_LEVEL
6268
value: info
63-
- name: WIZ_CLIENT_ID
64-
valueFrom:
65-
secretKeyRef:
66-
name: wiz-api-token
67-
key: clientId
68-
optional: false
69-
- name: WIZ_CLIENT_TOKEN
70-
valueFrom:
71-
secretKeyRef:
72-
name: wiz-api-token
73-
key: clientToken
74-
optional: false
7569
- name: WIZ_ENV
7670
value:
7771
resources:
@@ -81,4 +75,8 @@ spec:
8175
requests:
8276
cpu: {{ .Cluster.ConfigItems.wiz_connector_cpu }}
8377
memory: {{ .Cluster.ConfigItems.wiz_connector_memory }}
78+
volumeMounts:
79+
- name: api-client
80+
mountPath: /var/api-client
81+
readOnly: true
8482
{{end}}

cluster/manifests/wiz/connector-deployment.yaml

Lines changed: 10 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
name: wiz-connector-agent
88
namespace: "wiz"
99
labels:
10-
helm.sh/chart: wiz-broker-2.1.0
10+
helm.sh/chart: wiz-broker-2.3.8
1111
application: "wiz"
1212
component: "connector"
1313
deployment: "wiz-connector-agent"
@@ -19,7 +19,7 @@ spec:
1919
template:
2020
metadata:
2121
labels:
22-
helm.sh/chart: wiz-broker-2.1.0
22+
helm.sh/chart: wiz-broker-2.3.8
2323
application: "wiz"
2424
component: "connector"
2525
deployment: "wiz-connector-agent"
@@ -29,6 +29,9 @@ spec:
2929
runAsNonRoot: true
3030
runAsUser: 1000
3131
volumes:
32+
- name: api-client
33+
secret:
34+
secretName: wiz-api-token
3235
- name: connector-data
3336
secret:
3437
secretName: wiz-connector-connector
@@ -44,6 +47,9 @@ spec:
4447
image: "container-registry.zalando.net/secops-systems/wiz-broker:2.7-main-4"
4548
imagePullPolicy: IfNotPresent
4649
volumeMounts:
50+
- name: api-client
51+
mountPath: /var/api-client
52+
readOnly: true
4753
- name: connector-data
4854
mountPath: /etc/connectorData
4955
readOnly: true
@@ -54,16 +60,8 @@ spec:
5460
value: info
5561
- name: WIZ_ENV
5662
value:
57-
- name: WIZ_CLIENT_ID
58-
valueFrom:
59-
secretKeyRef:
60-
name: wiz-api-token
61-
key: clientId
62-
- name: WIZ_CLIENT_TOKEN
63-
valueFrom:
64-
secretKeyRef:
65-
name: wiz-api-token
66-
key: clientToken
63+
- name: CLI_FILES_AS_ARGS
64+
value: "/var/api-client/clientToken,/var/api-client/clientId"
6765
- name: TARGET_IP
6866
value: kubernetes.default.svc.cluster.local
6967
- name: TARGET_PORT

0 commit comments

Comments
 (0)