Merge pull request #22 from btat/fix-tabs

Convert Hugo tabs
This commit is contained in:
Catherine Luse
2022-09-09 20:46:12 -07:00
committed by GitHub
6 changed files with 148 additions and 148 deletions
@@ -3,6 +3,9 @@ title: Installing the Adapter
weight: 2
---
import Tabs from '@theme/Tabs';
import TabItem from '@theme/TabItem';
> **Important:** If you are attempting to re-install the adapter, you may experience errant out-of-compliance messages for up to an hour.
### 1. Gain Access to the Local Cluster
@@ -63,62 +66,62 @@ For the below instructions, replace `$MY_ACC_NUM` with your AWS account number a
> **Note:** It is important that you follow the instructions below exactly. In particular, the command to install version 1.0.1 of the adapter (by using --set image.tag=v1.0.1) is key to ensure that node counts are accurate.
{{% tabs %}}
{{% tab "Let's Encrypt/ Public Certificate Authority" %}}
<Tabs>
<TabItem value="Let's Encrypt/ Public Certificate Authority">
```bash
helm install rancher-csp-adapter rancher-charts/rancher-csp-adapter --namespace cattle-csp-adapter-system --set aws.enabled=true --set aws.roleName=$MY_ROLE_NAME --set-string aws.accountNumber=$MY_ACC_NUM --set image.tag=v1.0.1
```
```bash
helm install rancher-csp-adapter rancher-charts/rancher-csp-adapter --namespace cattle-csp-adapter-system --set aws.enabled=true --set aws.roleName=$MY_ROLE_NAME --set-string aws.accountNumber=$MY_ACC_NUM --set image.tag=v1.0.1
```
Alternatively, you can use a `values.yaml` and specify options like below:
Alternatively, you can use a `values.yaml` and specify options like below:
```yaml
image:
```yaml
image:
tag: v1.0.1
aws:
aws:
enabled: true
accountNumber: "$MY_ACC_NUM"
roleName: $MY_ROLE_NAME
```
```
> **Note:** The account number needs to be specified in a string format, like the above, or the installation will fail.
> **Note:** The account number needs to be specified in a string format, like the above, or the installation will fail.
You can then install the adapter with the following command:
You can then install the adapter with the following command:
```bash
helm install rancher-csp-adapter rancher-charts/rancher-csp-adapter -f values.yaml
```
```bash
helm install rancher-csp-adapter rancher-charts/rancher-csp-adapter -f values.yaml
```
{{% /tab %}}
{{% tab "Private CA Authority / Rancher-generated Certificates" %}}
</TabItem>
<TabItem value="Private CA Authority / Rancher-generated Certificates">
```bash
helm install rancher-csp-adapter rancher-charts/rancher-csp-adapter --namespace cattle-csp-adapter-system --set aws.enabled=true --set aws.roleName=$MY_ROLE_NAME --set-string aws.accountNumber=$MY_ACC_NUM --set additionalTrustedCAs=true --set image.tag=v1.0.1
```
```bash
helm install rancher-csp-adapter rancher-charts/rancher-csp-adapter --namespace cattle-csp-adapter-system --set aws.enabled=true --set aws.roleName=$MY_ROLE_NAME --set-string aws.accountNumber=$MY_ACC_NUM --set additionalTrustedCAs=true --set image.tag=v1.0.1
```
Alternatively, you can use a `values.yaml` and specify options the below:
Alternatively, you can use a `values.yaml` and specify options the below:
```yaml
image:
```yaml
image:
tag: v1.0.1
aws:
aws:
enabled: true
accountNumber: "$MY_ACC_NUM"
roleName: $MY_ROLE_NAME
additionalTrustedCAs: true
```
additionalTrustedCAs: true
```
> **Note:** The account number needs to be specified in a string format, like the above, or the installation will fail.
> **Note:** The account number needs to be specified in a string format, like the above, or the installation will fail.
You can then install the adapter with the following command:
You can then install the adapter with the following command:
```bash
helm install rancher-csp-adapter rancher-charts/rancher-csp-adapter -f values.yaml
```
```bash
helm install rancher-csp-adapter rancher-charts/rancher-csp-adapter -f values.yaml
```
{{% /tab %}}
{{% /tabs %}}
</TabItem>
</Tabs>
### 5. Managing Certificate Updates
@@ -3,6 +3,9 @@ title: NeuVector Integration
weight: 22
---
import Tabs from '@theme/Tabs';
import TabItem from '@theme/TabItem';
### NeuVector Integration in Rancher
New in Rancher v2.6.5, [NeuVector 5.x](https://open-docs.neuvector.com/) is an open-source container-centric security platform that is now integrated into Rancher. NeuVector offers real-time compliance, visibility, and protection for critical applications and data during runtime. NeuVector provides a firewall, container process/file system monitoring, security auditing with CIS benchmarks, and vulnerability scanning. For more information on Rancher security, please see the [security documentation](../../pages-for-subheaders/rancher-security.md).
@@ -11,13 +14,13 @@ NeuVector can be enabled through a Helm chart that may be installed either throu
### Installing NeuVector with Rancher
The Harvester Helm Chart is used to manage access to the NeuVector UI in Rancher where users can navigate directly to deploy and manage their NeuVector clusters.
The Harvester Helm Chart is used to manage access to the NeuVector UI in Rancher where users can navigate directly to deploy and manage their NeuVector clusters.
**To navigate to and install the NeuVector chart through Apps & Marketplace:**
1. Click **☰ > Cluster Management**.
1. On the Clusters page, go to the cluster where you want to deploy NeuVector, and click **Explore**.
1. Go to **Apps & Marketplace > Charts**, and install **NeuVector** from the chart repo.
1. Go to **Apps & Marketplace > Charts**, and install **NeuVector** from the chart repo.
1. Different cluster types require different container runtimes. When configuring Helm chart values, go to the **Container Runtime** section, and select your runtime in accordance with the cluster type. Finally, click **Install** again.
Some examples are as follows:
@@ -29,11 +32,11 @@ Some examples are as follows:
- GKE: `containerd` (see the [Google docs](https://cloud.google.com/kubernetes-engine/docs/concepts/using-containerd) for more)
:::note
Only one container runtime engine may be selected at a time during installation.
:::
**To navigate to and install the NeuVector chart through Cluster Tools:**
1. Click **☰ > Cluster Management**.
@@ -102,63 +105,63 @@ Below are the minimum recommended computing resources for the NeuVector chart in
### Hardened Cluster Support - Calico and Canal
{{% tabs %}}
{{% tab "RKE1" %}}
<Tabs>
<TabItem value="RKE1">
- All NeuVector components are deployable if PSP is set to true.
- All NeuVector components are deployable if PSP is set to true.
**_New in v2.6.7_**
**_New in v2.6.7_**
You will need to set additional configuration for your hardened cluster environment as follows:
You will need to set additional configuration for your hardened cluster environment as follows:
1. Click **☰ > Cluster Management**.
1. Go to the cluster that you created and click **Explore**.
1. In the left navigation bar, click **Apps & Marketplace**.
1. Install (or upgrade to) NeuVector version `100.0.1+up2.2.2`.
1. Click **☰ > Cluster Management**.
1. Go to the cluster that you created and click **Explore**.
1. In the left navigation bar, click **Apps & Marketplace**.
1. Install (or upgrade to) NeuVector version `100.0.1+up2.2.2`.
- Under **Edit Options** > **Other Configuration**, enable **Pod Security Policy** by checking the box (no other config needed):
- Under **Edit Options** > **Other Configuration**, enable **Pod Security Policy** by checking the box (no other config needed):
![Enable PSP for RKE1 Hardened Cluster](/img/psp-nv-rke.png)
![Enable PSP for RKE1 Hardened Cluster](/img/psp-nv-rke.png)
1. Click **Install** at the bottom-right to complete.
1. Click **Install** at the bottom-right to complete.
{{% /tab %}}
{{% tab "RKE2" %}}
</TabItem>
<TabItem value="RKE2">
- NeuVector components Controller and Enforcer are deployable if PSP is set to true.
- NeuVector components Controller and Enforcer are deployable if PSP is set to true.
**Applicable to NeuVector chart version 100.0.0+up2.2.0 only:**
**Applicable to NeuVector chart version 100.0.0+up2.2.0 only:**
- For Manager, Scanner, and Updater components, additional configuration is required as shown below:
- For Manager, Scanner, and Updater components, additional configuration is required as shown below:
```
kubectl patch deploy neuvector-manager-pod -n cattle-neuvector-system --patch '{"spec":{"template":{"spec":{"securityContext":{"runAsUser": 5400}}}}}'
kubectl patch deploy neuvector-scanner-pod -n cattle-neuvector-system --patch '{"spec":{"template":{"spec":{"securityContext":{"runAsUser": 5400}}}}}'
kubectl patch cronjob neuvector-updater-pod -n cattle-neuvector-system --patch '{"spec":{"jobTemplate":{"spec":{"template":{"spec":{"securityContext":{"runAsUser": 5400}}}}}}}'
```
<br/>
```
kubectl patch deploy neuvector-manager-pod -n cattle-neuvector-system --patch '{"spec":{"template":{"spec":{"securityContext":{"runAsUser": 5400}}}}}'
kubectl patch deploy neuvector-scanner-pod -n cattle-neuvector-system --patch '{"spec":{"template":{"spec":{"securityContext":{"runAsUser": 5400}}}}}'
kubectl patch cronjob neuvector-updater-pod -n cattle-neuvector-system --patch '{"spec":{"jobTemplate":{"spec":{"template":{"spec":{"securityContext":{"runAsUser": 5400}}}}}}}'
```
<br/>
**_New in v2.6.7_**
**_New in v2.6.7_**
You will need to set additional configuration for your hardened cluster environment.
You will need to set additional configuration for your hardened cluster environment.
>**Note:** You must update your config in both RKE2 and K3s hardened clusters as shown below.
>**Note:** You must update your config in both RKE2 and K3s hardened clusters as shown below.
1. Click **☰ > Cluster Management**.
1. Go to the cluster that you created and click **Explore**.
1. In the left navigation bar, click **Apps & Marketplace**.
1. Install (or upgrade to) NeuVector version `100.0.1+up2.2.2`.
1. Click **☰ > Cluster Management**.
1. Go to the cluster that you created and click **Explore**.
1. In the left navigation bar, click **Apps & Marketplace**.
1. Install (or upgrade to) NeuVector version `100.0.1+up2.2.2`.
- Under **Edit Options** > **Other Configuration**, enable **Pod Security Policy** by checking the box. Note that you must also enter a value greater than `zero` for `Manager runAsUser ID`, `Scanner runAsUser ID`, and `Updater runAsUser ID`:
- Under **Edit Options** > **Other Configuration**, enable **Pod Security Policy** by checking the box. Note that you must also enter a value greater than `zero` for `Manager runAsUser ID`, `Scanner runAsUser ID`, and `Updater runAsUser ID`:
![Enable PSP for RKE2 and K3s Hardened Clusters](/img/psp-nv-rke2.png)
![Enable PSP for RKE2 and K3s Hardened Clusters](/img/psp-nv-rke2.png)
1. Click **Install** at the bottom-right to complete.
1. Click **Install** at the bottom-right to complete.
{{% /tab %}}
{{% /tabs %}}
</TabItem>
</Tabs>
### SELinux-enabled Cluster Support - Calico and Canal
@@ -75,17 +75,17 @@ To install `gcloud` and `kubectl`, perform the following steps:
<Tabs>
<TabItem value="Using gcloud init">
1. Run gcloud init and follow the directions:
1. Run gcloud init and follow the directions:
```
gcloud init
```
If you are using SSH on a remote server, use the --console-only flag to prevent the command from launching a browser:
```
gcloud init
```
If you are using SSH on a remote server, use the --console-only flag to prevent the command from launching a browser:
```
gcloud init --console-only
```
2. Follow the instructions to authorize gcloud to use your Google Cloud account and select the new project that you created.
```
gcloud init --console-only
```
2. Follow the instructions to authorize gcloud to use your Google Cloud account and select the new project that you created.
</TabItem>
@@ -96,14 +96,10 @@ From the Azure portal, create a client secret. Rancher will use this key to auth
1. From the navigation pane on left, click **Certificates and Secrets**.
1. Click **New client secret**.
![Create new client secret](/img/new-client-secret.png)
1. Enter a **Description** (something like `Rancher`).
1. Select duration for the key from the options under **Expires**. This drop-down sets the expiration date for the key. Shorter durations are more secure, but require you to create a new key after expiration.
1. Click **Add** (you don't need to enter a value—it will automatically populate after you save).
![Create new client secret](/img/new-client-secret.png)
1. Enter a **Description** (something like `Rancher`).
1. Select duration for the key from the options under **Expires**. This drop-down sets the expiration date for the key. Shorter durations are more secure, but require you to create a new key after expiration.
1. Click **Add** (you don't need to enter a value—it will automatically populate after you save).
<a id="secret"></a>
1. Copy the key value and save it to an [empty text file](#tip).
@@ -174,21 +170,20 @@ As your final step in Azure, copy the data that you'll use to configure Rancher
![Standard Endpoint Options](/img/tenant-application-id-secret.png)
>**For Custom Endpoints:**
>
>**Warning:** Custom Endpoints are not supported nor fully tested by Rancher.
>
> You will need to also manually enter the Graph, Token, and Auth Endpoints.
>
>- From <b>App registrations</b>, click <b>Endpoints</b>:
>
>![Click Endpoints](/img/endpoints.png)
>
>- Copy the following endpoints to your clipboard and paste them into your [text file](#tip) (these values will be your Rancher endpoint values). Make sure to copy the v1 version of the endpoints.
>
> - **Microsoft Graph API endpoint** (Graph Endpoint)
> - **OAuth 2.0 token endpoint (v1)** (Token Endpoint)
> - **OAuth 2.0 authorization endpoint (v1)** (Auth Endpoint)
**For Custom Endpoints:**
**Warning:** Custom Endpoints are not supported nor fully tested by Rancher.
You will need to also manually enter the Graph, Token, and Auth Endpoints.
- From <b>App registrations</b>, click <b>Endpoints</b>:
![Click Endpoints](/img/endpoints.png)
- Copy the following endpoints to your clipboard and paste them into your [text file](#tip) (these values will be your Rancher endpoint values). Make sure to copy the v1 version of the endpoints.
- **Microsoft Graph API endpoint** (Graph Endpoint)
- **OAuth 2.0 token endpoint (v1)** (Token Endpoint)
- **OAuth 2.0 authorization endpoint (v1)** (Auth Endpoint)
#### 5. Configure Azure AD in Rancher
@@ -212,19 +207,19 @@ Enter the values that you copied to your [text file](#tip).
| Endpoint | https://login.microsoftonline.com/ |
>**For Custom Endpoints:**
><br/>
>The following table maps the custom config values you copied in the Azure portal to the fields in Rancher:
>
>| Rancher Field | Azure Value |
>| ------------------ | ------------------------------------- |
>| Graph Endpoint | Microsoft Graph API Endpoint |
>| Token Endpoint | OAuth 2.0 Token Endpoint |
>| Auth Endpoint | OAuth 2.0 Authorization Endpoint |
><br/>
>**Important:** When entering the Graph Endpoint in a custom config, remove the tenant ID from the URL, like below:
>
><code>http<span>s://g</span>raph.microsoft.com/<del>abb5adde-bee8-4821-8b03-e63efdc7701c</del></code>
**For Custom Endpoints:**
The following table maps the custom config values you copied in the Azure portal to the fields in Rancher:
| Rancher Field | Azure Value |
| ------------------ | ------------------------------------- |
| Graph Endpoint | Microsoft Graph API Endpoint |
| Token Endpoint | OAuth 2.0 Token Endpoint |
| Auth Endpoint | OAuth 2.0 Authorization Endpoint |
**Important:** When entering the Graph Endpoint in a custom config, remove the tenant ID from the URL, like below:
<code>http<span>s://g</span>raph.microsoft.com/<del>abb5adde-bee8-4821-8b03-e63efdc7701c</del></code>
1. Click **Enable**.
@@ -72,7 +72,7 @@ From the Azure portal, create a client secret. Rancher will use this key to auth
1. Click **New client secret**.
![Create new client secret](/img/select-client-secret.png)
![Create new client secret](/img/select-client-secret.png)
1. Enter a **Description** (something like `Rancher`).
@@ -3,8 +3,11 @@ title: Configuring Azure AD
weight: 1115
---
{{% tabs %}}
{{% tab "Rancher v2.5.16+" %}}
import Tabs from '@theme/Tabs';
import TabItem from '@theme/TabItem';
<Tabs>
<TabItem value="Rancher v2.5.16+">
## Microsoft Graph API
@@ -73,20 +76,16 @@ From the Azure portal, create a client secret. Rancher will use this key to auth
1. Use search to open **App registrations** services. Then open the entry for Rancher that you created in the last procedure.
![Open Rancher Registration](/img/open-rancher-app-reg.png)
![Open Rancher Registration](/img/open-rancher-app-reg.png)
1. From the navigation pane on left, click **Certificates and Secrets**.
1. Click **New client secret**.
![Create new client secret](/img//new-client-secret.png)
3.1. Enter a **Description** (something like `Rancher`).
3.2. Select duration for the key from the options under **Expires**. This drop-down sets the expiration date for the key. Shorter durations are more secure, but require you to create a new key after expiration.
3.3. Click **Add** (you don't need to enter a value—it will automatically populate after you save).
<a id="secret"></a>
![Create new client secret](/img//new-client-secret.png)
- 3.1. Enter a **Description** (something like `Rancher`).
- 3.2. Select duration for the key from the options under **Expires**. This drop-down sets the expiration date for the key. Shorter durations are more secure, but require you to create a new key after expiration.
- 3.3. Click **Add** (you don't need to enter a value—it will automatically populate after you save).
<a id="secret"></a>
1. Copy the key value and save it to an [empty text file](#tip).
@@ -114,7 +113,7 @@ Ensure that you set the permissions of type Application and NOT Delegated. Other
- `Group.Read.All`
- `User.Read.All`
![Select API Permissions]/img/api-permissions.png)
<!-- ![Select API Permissions]/img/api-permissions.png) -->
1. Return to **API permissions** in the left nav bar. From there, click **Grant admin consent**. Then click **Yes**.
@@ -194,19 +193,19 @@ Enter the values that you copied to your [text file](#tip).
| Endpoint | https://login.microsoftonline.com/ |
>**For Custom Endpoints:**
><br/>
>The following table maps the custom config values you copied in the Azure portal to the fields in Rancher:
>
>| Rancher Field | Azure Value |
>| ------------------ | ------------------------------------- |
>| Graph Endpoint | Microsoft Graph API Endpoint |
>| Token Endpoint | OAuth 2.0 Token Endpoint |
>| Auth Endpoint | OAuth 2.0 Authorization Endpoint |
><br/>
>**Important:** When entering the Graph Endpoint in a custom config, remove the tenant ID from the URL, like below:
>
><code>http<span>s://g</span>raph.microsoft.com/<del>abb5adde-bee8-4821-8b03-e63efdc7701c</del></code>
>**For Custom Endpoints:**
><br/>
>The following table maps the custom config values you copied in the Azure portal to the fields in Rancher:
>
>| Rancher Field | Azure Value |
>| ------------------ | ------------------------------------- |
>| Graph Endpoint | Microsoft Graph API Endpoint |
>| Token Endpoint | OAuth 2.0 Token Endpoint |
>| Auth Endpoint | OAuth 2.0 Authorization Endpoint |
><br/>
>**Important:** When entering the Graph Endpoint in a custom config, remove the tenant ID from the URL, like below:
>
><code>http<span>s://g</span>raph.microsoft.com/<del>abb5adde-bee8-4821-8b03-e63efdc7701c</del></code>
1. Click **Enable**.
@@ -291,8 +290,8 @@ Graph Endpoint | https://microsoftgraph.chinacloudapi.cn
Token Endpoint | https://login.partner.microsoftonline.cn/{tenantID}/oauth2/v2.0/token
{{% /tab %}}
{{% tab "Rancher v2.5.0 - v2.5.15" %}}
</TabItem>
<TabItem value="Rancher v2.5.0 - v2.5.15">
## Azure AD Graph API
@@ -309,5 +308,5 @@ Token Endpoint | https://login.partner.microsoftonline.cn/{tenantID}/oauth2/v2
- Use another third-party auth system and set that up in Rancher. Please see the [authentication docs](../../../../../pages-for-subheaders/about-authentication.md) to learn how to configure other open authentication providers.
{{% /tab %}}
{{% /tabs %}}
</TabItem>
</Tabs>