mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-27 21:50:21 +00:00
deploy: 02d48c12c8
This commit is contained in:
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.7/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards.md",
|
||||
"tags": [],
|
||||
"version": "2.7",
|
||||
"lastUpdatedAt": 1686450196,
|
||||
"formattedLastUpdatedAt": "Jun 11, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Pod Security Standards (PSS) & Pod Security Admission (PSA)"
|
||||
},
|
||||
@@ -348,7 +348,7 @@ const toc = [
|
||||
},
|
||||
{
|
||||
value: 'Removing PodSecurityPolicies from Rancher-Maintained Apps & Marketplace Workloads',
|
||||
id: 'remove-psp-rancher-workloads',
|
||||
id: 'removing-podsecuritypolicies-from-rancher-maintained-apps--marketplace-workloads',
|
||||
level: 3
|
||||
},
|
||||
{
|
||||
@@ -373,7 +373,7 @@ const toc = [
|
||||
},
|
||||
{
|
||||
value: 'Pod Security Admission Configuration Templates',
|
||||
id: 'psa-config-templates',
|
||||
id: 'pod-security-admission-configuration-templates',
|
||||
level: 2
|
||||
},
|
||||
{
|
||||
@@ -430,7 +430,7 @@ They became available and were turned on by default in Kubernetes v1.23, and rep
|
||||
}, `You must add your new policy enforcement mechanisms `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
parentName: "p"
|
||||
}, `before`), ` you remove the PodSecurityPolicy objects. If you don't, you may create an opportunity for privilege escalation attacks within the cluster.`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h3", {
|
||||
"id": "remove-psp-rancher-workloads"
|
||||
"id": "removing-podsecuritypolicies-from-rancher-maintained-apps--marketplace-workloads"
|
||||
}, `Removing PodSecurityPolicies from Rancher-Maintained Apps & Marketplace Workloads`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `Rancher v2.7.2 offers a new major version of Rancher-maintained Helm charts. v102.x.y allows you to remove PSPs that were installed with previous versions of the chart. This new version replaces non-standard PSPs switches with the standardized `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `global.cattle.psp.enabled`), ` switch, which is turned off by default.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You must perform the following steps `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
@@ -441,7 +441,7 @@ They became available and were turned on by default in Kubernetes v1.23, and rep
|
||||
parentName: "li"
|
||||
}, `Configure the PSA controller to suit your needs. You can use one of Rancher's built-in `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#psa-config-templates"
|
||||
"href": "#pod-security-admission-configuration-templates"
|
||||
}, `PSA Configuration Templates`), `, or create a custom template and apply it to the clusters that you are migrating.`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
@@ -604,14 +604,14 @@ Flags:
|
||||
"id": "upgrading-charts-to-a-version-that-supports-kubernetes-v125"
|
||||
}, `Upgrading Charts to a Version That Supports Kubernetes v1.25`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You can proceed with your upgrade once any releases that had lingering PSPs are cleaned up. For Rancher-maintained workloads, follow the steps outlined in the `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#remove-psp-rancher-workloads"
|
||||
"href": "#removing-podsecuritypolicies-from-rancher-maintained-apps--marketplace-workloads"
|
||||
}, `Removing PodSecurityPolicies from Rancher-maintained Apps & Marketplace workloads`), ` section of this document.
|
||||
For workloads not maintained by Rancher, refer to the vendor documentation.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "caution"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "admonition"
|
||||
}, `Do not skip this step. Applications incompatible with Kubernetes v1.25 aren't guaranteed to work after a cleanup.`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h2", {
|
||||
"id": "psa-config-templates"
|
||||
"id": "pod-security-admission-configuration-templates"
|
||||
}, `Pod Security Admission Configuration Templates`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `Rancher offers PSA configuration templates. These are pre-defined security configurations that you can apply to a cluster. Rancher admins (or those with the right permissions) can `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "/v2.7/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/psa-config-templates"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.6/reference-guides/cluster-configuration/rancher-server-configuration/rke2-cluster-configuration.md",
|
||||
"tags": [],
|
||||
"version": "2.6",
|
||||
"lastUpdatedAt": 1701905748,
|
||||
"formattedLastUpdatedAt": "Dec 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "RKE2 Cluster Configuration Reference"
|
||||
},
|
||||
@@ -432,8 +432,8 @@ const toc = [
|
||||
level: 5
|
||||
},
|
||||
{
|
||||
value: 'Additional Configuration',
|
||||
id: 'dual-stack-additional-config',
|
||||
value: 'Dual-stack Additional Configuration',
|
||||
id: 'dual-stack-additional-configuration',
|
||||
level: 6
|
||||
},
|
||||
{
|
||||
@@ -771,8 +771,8 @@ function MDXContent(_param) {
|
||||
parentName: "p",
|
||||
"href": "#service-cidr"
|
||||
}, `Service CIDR`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h6", {
|
||||
"id": "dual-stack-additional-config"
|
||||
}, `Additional Configuration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `When using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
"id": "dual-stack-additional-configuration"
|
||||
}, `Dual-stack Additional Configuration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `When using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium`), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
@@ -872,7 +872,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `10.42.0.0/16,2001:cafe:42:0::/56`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#dual-stack-additional-config"
|
||||
"href": "#dual-stack-additional-configuration"
|
||||
}, `Additional configuration`), ` is required when using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium`), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
@@ -891,7 +891,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `10.42.0.0/16,2001:cafe:42:0::/56`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#dual-stack-additional-config"
|
||||
"href": "#dual-stack-additional-configuration"
|
||||
}, `Additional configuration`), ` is required when using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium `), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.8/reference-guides/cluster-configuration/rancher-server-configuration/k3s-cluster-configuration.md",
|
||||
"tags": [],
|
||||
"version": "2.8",
|
||||
"lastUpdatedAt": 1701905748,
|
||||
"formattedLastUpdatedAt": "Dec 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "K3s Cluster Configuration Reference"
|
||||
},
|
||||
@@ -627,7 +627,7 @@ function MDXContent(_param) {
|
||||
parentName: "ul"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "li",
|
||||
"href": "#cluster-config-file"
|
||||
"href": "#cluster-config-file-reference"
|
||||
}, `Cluster Config File`), `: Instead of using the Rancher UI to choose Kubernetes options for the cluster, advanced users can create a K3s config file. Using a config file allows you to set any of the `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "li",
|
||||
"href": "https://rancher.com/docs/k3s/latest/en/installation/install-options/"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.8/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/configure-microsoft-ad-federation-service-saml/configure-rancher-for-ms-adfs.md",
|
||||
"tags": [],
|
||||
"version": "2.8",
|
||||
"lastUpdatedAt": 1696627994,
|
||||
"formattedLastUpdatedAt": "Oct 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "2. Configuring Rancher for Microsoft AD FS"
|
||||
},
|
||||
@@ -345,6 +345,11 @@ const toc = [
|
||||
value: 'Configuration',
|
||||
id: 'configuration',
|
||||
level: 2
|
||||
},
|
||||
{
|
||||
value: 'Example Certificate Creation Command',
|
||||
id: 'example-certificate-creation-command',
|
||||
level: 3
|
||||
}
|
||||
];
|
||||
const layoutProps = {
|
||||
@@ -499,7 +504,7 @@ function MDXContent(_param) {
|
||||
"align": null
|
||||
}, `This is a key-certificate pair to create a secure shell between Rancher and your AD FS. Ensure you set the Common Name (CN) to your Rancher Server URL.`, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "td",
|
||||
"href": "#cert-command"
|
||||
"href": "#example-certificate-creation-command"
|
||||
}, `Certificate creation command`))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("tr", {
|
||||
parentName: "tbody"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
@@ -512,18 +517,12 @@ function MDXContent(_param) {
|
||||
parentName: "td"
|
||||
}, `federationmetadata.xml`), ` file exported from your AD FS server. `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), `You can find this file at `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `https://<AD_SERVER>/federationmetadata/2007-06/federationmetadata.xml`), `.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "cert-command"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "tip"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "admonition"
|
||||
}, `You can generate a certificate using an openssl command. For example:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("pre", {
|
||||
parentName: "admonition"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("code", {
|
||||
}, `https://<AD_SERVER>/federationmetadata/2007-06/federationmetadata.xml`), `.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h3", {
|
||||
"id": "example-certificate-creation-command"
|
||||
}, `Example Certificate Creation Command`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You can generate a certificate using an openssl command. For example:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("pre", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("code", {
|
||||
parentName: "pre"
|
||||
}, `openssl req -x509 -newkey rsa:2048 -keyout myservice.key -out myservice.cert -days 365 -nodes -subj "/CN=myservice.example.com"
|
||||
`))));
|
||||
`)));
|
||||
}
|
||||
MDXContent.isMDXComponent = true;
|
||||
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.5/getting-started/installation-and-upgrade/advanced-options/advanced-use-cases/enable-api-audit-log.md",
|
||||
"tags": [],
|
||||
"version": "2.5",
|
||||
"lastUpdatedAt": 1663953084,
|
||||
"formattedLastUpdatedAt": "Sep 23, 2022",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Enabling the API Audit Log to Record System Events"
|
||||
},
|
||||
@@ -463,9 +463,7 @@ function MDXContent(_param) {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "audit-level"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `AUDIT_LEVEL`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
@@ -531,7 +529,7 @@ function MDXContent(_param) {
|
||||
"id": "audit-log-levels"
|
||||
}, `Audit Log Levels`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `The following table displays what parts of API transactions are logged for each `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#audit-level"
|
||||
"href": "#api-audit-log-options"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "a"
|
||||
}, `AUDIT_LEVEL`)), ` setting.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("table", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("thead", {
|
||||
@@ -324,7 +324,7 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.7/integrations-in-rancher/monitoring-and-alerting/rbac-for-monitoring.md",
|
||||
"tags": [],
|
||||
"version": "2.7",
|
||||
"lastUpdatedAt": 1704823487,
|
||||
"lastUpdatedAt": 1704827852,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Role-based Access Control"
|
||||
@@ -767,9 +767,7 @@ function MDXContent(_param) {
|
||||
}, `monitoring-ui-view`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "monitoring-ui-view"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
parentName: "td"
|
||||
}, `Available as of Monitoring v2 14.5.100+`), ` This ClusterRole allows users with write access to the project to view metrics graphs for the specified cluster in the Rancher UI. This is done by granting Read-only access to external Monitoring UIs. Users with this role have permission to list the Prometheus, Alertmanager, and Grafana endpoints and make GET requests to Prometheus, Grafana, and Alertmanager UIs through the Rancher proxy.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "note"
|
||||
@@ -996,7 +994,7 @@ subjects:
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "td",
|
||||
"href": "#monitoring-ui-view"
|
||||
"href": "#additional-monitoring-clusterroles"
|
||||
}, `monitoring-ui-view`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/configure-microsoft-ad-federation-service-saml/configure-rancher-for-ms-adfs.md",
|
||||
"tags": [],
|
||||
"version": "current",
|
||||
"lastUpdatedAt": 1686447138,
|
||||
"formattedLastUpdatedAt": "Jun 11, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "2. Configuring Rancher for Microsoft AD FS"
|
||||
},
|
||||
@@ -345,6 +345,11 @@ const toc = [
|
||||
value: 'Configuration',
|
||||
id: 'configuration',
|
||||
level: 2
|
||||
},
|
||||
{
|
||||
value: 'Example Certificate Creation Command',
|
||||
id: 'example-certificate-creation-command',
|
||||
level: 3
|
||||
}
|
||||
];
|
||||
const layoutProps = {
|
||||
@@ -499,7 +504,7 @@ function MDXContent(_param) {
|
||||
"align": null
|
||||
}, `This is a key-certificate pair to create a secure shell between Rancher and your AD FS. Ensure you set the Common Name (CN) to your Rancher Server URL.`, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "td",
|
||||
"href": "#cert-command"
|
||||
"href": "#example-certificate-creation-command"
|
||||
}, `Certificate creation command`))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("tr", {
|
||||
parentName: "tbody"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
@@ -512,18 +517,12 @@ function MDXContent(_param) {
|
||||
parentName: "td"
|
||||
}, `federationmetadata.xml`), ` file exported from your AD FS server. `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), `You can find this file at `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `https://<AD_SERVER>/federationmetadata/2007-06/federationmetadata.xml`), `.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "cert-command"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "tip"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "admonition"
|
||||
}, `You can generate a certificate using an openssl command. For example:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("pre", {
|
||||
parentName: "admonition"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("code", {
|
||||
}, `https://<AD_SERVER>/federationmetadata/2007-06/federationmetadata.xml`), `.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h3", {
|
||||
"id": "example-certificate-creation-command"
|
||||
}, `Example Certificate Creation Command`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You can generate a certificate using an openssl command. For example:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("pre", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("code", {
|
||||
parentName: "pre"
|
||||
}, `openssl req -x509 -newkey rsa:2048 -keyout myservice.key -out myservice.cert -days 365 -nodes -subj "/CN=myservice.example.com"
|
||||
`))));
|
||||
`)));
|
||||
}
|
||||
MDXContent.isMDXComponent = true;
|
||||
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.6/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/configure-microsoft-ad-federation-service-saml/configure-rancher-for-ms-adfs.md",
|
||||
"tags": [],
|
||||
"version": "2.6",
|
||||
"lastUpdatedAt": 1686447138,
|
||||
"formattedLastUpdatedAt": "Jun 11, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "2. Configuring Rancher for Microsoft AD FS"
|
||||
},
|
||||
@@ -345,6 +345,11 @@ const toc = [
|
||||
value: 'Configuration',
|
||||
id: 'configuration',
|
||||
level: 2
|
||||
},
|
||||
{
|
||||
value: 'Example Certificate Creation Command',
|
||||
id: 'example-certificate-creation-command',
|
||||
level: 3
|
||||
}
|
||||
];
|
||||
const layoutProps = {
|
||||
@@ -499,7 +504,7 @@ function MDXContent(_param) {
|
||||
"align": null
|
||||
}, `This is a key-certificate pair to create a secure shell between Rancher and your AD FS. Ensure you set the Common Name (CN) to your Rancher Server URL.`, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "td",
|
||||
"href": "#cert-command"
|
||||
"href": "#example-certificate-creation-command"
|
||||
}, `Certificate creation command`))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("tr", {
|
||||
parentName: "tbody"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
@@ -512,18 +517,12 @@ function MDXContent(_param) {
|
||||
parentName: "td"
|
||||
}, `federationmetadata.xml`), ` file exported from your AD FS server. `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), `You can find this file at `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `https://<AD_SERVER>/federationmetadata/2007-06/federationmetadata.xml`), `.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "cert-command"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "tip"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "admonition"
|
||||
}, `You can generate a certificate using an openssl command. For example:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("pre", {
|
||||
parentName: "admonition"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("code", {
|
||||
}, `https://<AD_SERVER>/federationmetadata/2007-06/federationmetadata.xml`), `.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h3", {
|
||||
"id": "example-certificate-creation-command"
|
||||
}, `Example Certificate Creation Command`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You can generate a certificate using an openssl command. For example:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("pre", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("code", {
|
||||
parentName: "pre"
|
||||
}, `openssl req -x509 -newkey rsa:2048 -keyout myservice.key -out myservice.cert -days 365 -nodes -subj "/CN=myservice.example.com"
|
||||
`))));
|
||||
`)));
|
||||
}
|
||||
MDXContent.isMDXComponent = true;
|
||||
|
||||
@@ -324,7 +324,7 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/docs/integrations-in-rancher/monitoring-and-alerting/rbac-for-monitoring.md",
|
||||
"tags": [],
|
||||
"version": "current",
|
||||
"lastUpdatedAt": 1704823487,
|
||||
"lastUpdatedAt": 1704827852,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Role-based Access Control"
|
||||
@@ -767,9 +767,7 @@ function MDXContent(_param) {
|
||||
}, `monitoring-ui-view`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "monitoring-ui-view"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
parentName: "td"
|
||||
}, `Available as of Monitoring v2 14.5.100+`), ` This ClusterRole allows users with write access to the project to view metrics graphs for the specified cluster in the Rancher UI. This is done by granting Read-only access to external Monitoring UIs. Users with this role have permission to list the Prometheus, Alertmanager, and Grafana endpoints and make GET requests to Prometheus, Alertmanager, and Grafana UIs through the Rancher proxy.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "note"
|
||||
@@ -996,7 +994,7 @@ subjects:
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "td",
|
||||
"href": "#monitoring-ui-view"
|
||||
"href": "#additional-monitoring-clusterroles"
|
||||
}, `monitoring-ui-view`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.6/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-azure-ad.md",
|
||||
"tags": [],
|
||||
"version": "2.6",
|
||||
"lastUpdatedAt": 1686439683,
|
||||
"formattedLastUpdatedAt": "Jun 10, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Configure Azure AD"
|
||||
},
|
||||
@@ -508,9 +508,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `Name`), ` (something like `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `Rancher`), `).`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "3.2"
|
||||
})), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
}, `Rancher`), `).`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "li"
|
||||
@@ -1066,10 +1064,10 @@ If Rancher is still configured to use the Azure AD Graph API when it is retired,
|
||||
"href": "#global"
|
||||
}, `tables`), ` below for the full list of endpoint changes that Rancher performs. Admins do not need to do this manually.`))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"id": "air-gapped-environments"
|
||||
}, `Air-Gapped Environments`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `In air-gapped environments, admins should ensure that their endpoints are `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
}, `Air-Gapped Environments`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `In air-gapped environments, admins should ensure that their endpoints are whitelisted (see note on `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#3.2"
|
||||
}, `whitelisted`), ` since the Graph Endpoint URL is changing.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"href": "#1-register-rancher-with-azure"
|
||||
}, `Step 3.2 of Register Rancher with Azure`), `) since the Graph Endpoint URL is changing.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"id": "rolling-back-the-migration"
|
||||
}, `Rolling Back the Migration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `If you need to roll back your migration, please note the following:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("ol", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
@@ -324,7 +324,7 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.8/integrations-in-rancher/monitoring-and-alerting/rbac-for-monitoring.md",
|
||||
"tags": [],
|
||||
"version": "2.8",
|
||||
"lastUpdatedAt": 1704823487,
|
||||
"lastUpdatedAt": 1704827852,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Role-based Access Control"
|
||||
@@ -767,9 +767,7 @@ function MDXContent(_param) {
|
||||
}, `monitoring-ui-view`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "monitoring-ui-view"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
parentName: "td"
|
||||
}, `Available as of Monitoring v2 14.5.100+`), ` This ClusterRole allows users with write access to the project to view metrics graphs for the specified cluster in the Rancher UI. This is done by granting Read-only access to external Monitoring UIs. Users with this role have permission to list the Prometheus, Alertmanager, and Grafana endpoints and make GET requests to Prometheus, Grafana, and Alertmanager UIs through the Rancher proxy.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "note"
|
||||
@@ -996,7 +994,7 @@ subjects:
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "td",
|
||||
"href": "#monitoring-ui-view"
|
||||
"href": "#additional-monitoring-clusterroles"
|
||||
}, `monitoring-ui-view`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.7/how-to-guides/advanced-user-guides/enable-api-audit-log.md",
|
||||
"tags": [],
|
||||
"version": "2.7",
|
||||
"lastUpdatedAt": 1692993467,
|
||||
"formattedLastUpdatedAt": "Aug 25, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Enabling the API Audit Log to Record System Events"
|
||||
},
|
||||
@@ -461,9 +461,7 @@ function MDXContent(_param) {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "audit-level"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `AUDIT_LEVEL`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
@@ -529,7 +527,7 @@ function MDXContent(_param) {
|
||||
"id": "audit-log-levels"
|
||||
}, `Audit Log Levels`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `The following table displays what parts of API transactions are logged for each `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#audit-level"
|
||||
"href": "#api-audit-log-options"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "a"
|
||||
}, `AUDIT_LEVEL`)), ` setting.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("table", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("thead", {
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/docs/reference-guides/cluster-configuration/rancher-server-configuration/k3s-cluster-configuration.md",
|
||||
"tags": [],
|
||||
"version": "current",
|
||||
"lastUpdatedAt": 1701905748,
|
||||
"formattedLastUpdatedAt": "Dec 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "K3s Cluster Configuration Reference"
|
||||
},
|
||||
@@ -627,7 +627,7 @@ function MDXContent(_param) {
|
||||
parentName: "ul"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "li",
|
||||
"href": "#cluster-config-file"
|
||||
"href": "#cluster-config-file-reference"
|
||||
}, `Cluster Config File`), `: Instead of using the Rancher UI to choose Kubernetes options for the cluster, advanced users can create a K3s config file. Using a config file allows you to set any of the `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "li",
|
||||
"href": "https://rancher.com/docs/k3s/latest/en/installation/install-options/"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.8/reference-guides/cluster-configuration/rancher-server-configuration/rke2-cluster-configuration.md",
|
||||
"tags": [],
|
||||
"version": "2.8",
|
||||
"lastUpdatedAt": 1701905748,
|
||||
"formattedLastUpdatedAt": "Dec 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "RKE2 Cluster Configuration Reference"
|
||||
},
|
||||
@@ -437,8 +437,8 @@ const toc = [
|
||||
level: 6
|
||||
},
|
||||
{
|
||||
value: 'Additional Configuration',
|
||||
id: 'dual-stack-additional-config',
|
||||
value: 'Dual-stack Additional Configuration',
|
||||
id: 'dual-stack-additional-configuration',
|
||||
level: 6
|
||||
},
|
||||
{
|
||||
@@ -793,8 +793,8 @@ function MDXContent(_param) {
|
||||
parentName: "p",
|
||||
"href": "#service-cidr"
|
||||
}, `Service CIDR`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h6", {
|
||||
"id": "dual-stack-additional-config"
|
||||
}, `Additional Configuration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `When using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
"id": "dual-stack-additional-configuration"
|
||||
}, `Dual-stack Additional Configuration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `When using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium`), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
@@ -899,7 +899,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `10.42.0.0/16,2001:cafe:42:0::/56`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#dual-stack-additional-config"
|
||||
"href": "#dual-stack-additional-configuration"
|
||||
}, `Additional configuration`), ` is required when using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium`), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
@@ -918,7 +918,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `10.42.0.0/16,2001:cafe:42:0::/56`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#dual-stack-additional-config"
|
||||
"href": "#dual-stack-additional-configuration"
|
||||
}, `Additional configuration`), ` is required when using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium `), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.7/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/configure-microsoft-ad-federation-service-saml/configure-rancher-for-ms-adfs.md",
|
||||
"tags": [],
|
||||
"version": "2.7",
|
||||
"lastUpdatedAt": 1686447138,
|
||||
"formattedLastUpdatedAt": "Jun 11, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "2. Configuring Rancher for Microsoft AD FS"
|
||||
},
|
||||
@@ -345,6 +345,11 @@ const toc = [
|
||||
value: 'Configuration',
|
||||
id: 'configuration',
|
||||
level: 2
|
||||
},
|
||||
{
|
||||
value: 'Example Certificate Creation Command',
|
||||
id: 'example-certificate-creation-command',
|
||||
level: 3
|
||||
}
|
||||
];
|
||||
const layoutProps = {
|
||||
@@ -499,7 +504,7 @@ function MDXContent(_param) {
|
||||
"align": null
|
||||
}, `This is a key-certificate pair to create a secure shell between Rancher and your AD FS. Ensure you set the Common Name (CN) to your Rancher Server URL.`, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "td",
|
||||
"href": "#cert-command"
|
||||
"href": "#example-certificate-creation-command"
|
||||
}, `Certificate creation command`))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("tr", {
|
||||
parentName: "tbody"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
@@ -512,18 +517,12 @@ function MDXContent(_param) {
|
||||
parentName: "td"
|
||||
}, `federationmetadata.xml`), ` file exported from your AD FS server. `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("br", null), `You can find this file at `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `https://<AD_SERVER>/federationmetadata/2007-06/federationmetadata.xml`), `.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "cert-command"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "tip"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "admonition"
|
||||
}, `You can generate a certificate using an openssl command. For example:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("pre", {
|
||||
parentName: "admonition"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("code", {
|
||||
}, `https://<AD_SERVER>/federationmetadata/2007-06/federationmetadata.xml`), `.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h3", {
|
||||
"id": "example-certificate-creation-command"
|
||||
}, `Example Certificate Creation Command`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You can generate a certificate using an openssl command. For example:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("pre", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("code", {
|
||||
parentName: "pre"
|
||||
}, `openssl req -x509 -newkey rsa:2048 -keyout myservice.key -out myservice.cert -days 365 -nodes -subj "/CN=myservice.example.com"
|
||||
`))));
|
||||
`)));
|
||||
}
|
||||
MDXContent.isMDXComponent = true;
|
||||
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.8/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards.md",
|
||||
"tags": [],
|
||||
"version": "2.8",
|
||||
"lastUpdatedAt": 1696627994,
|
||||
"formattedLastUpdatedAt": "Oct 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Pod Security Standards (PSS) & Pod Security Admission (PSA)"
|
||||
},
|
||||
@@ -348,7 +348,7 @@ const toc = [
|
||||
},
|
||||
{
|
||||
value: 'Removing PodSecurityPolicies from Rancher-Maintained Apps & Marketplace Workloads',
|
||||
id: 'remove-psp-rancher-workloads',
|
||||
id: 'removing-podsecuritypolicies-from-rancher-maintained-apps--marketplace-workloads',
|
||||
level: 3
|
||||
},
|
||||
{
|
||||
@@ -373,7 +373,7 @@ const toc = [
|
||||
},
|
||||
{
|
||||
value: 'Pod Security Admission Configuration Templates',
|
||||
id: 'psa-config-templates',
|
||||
id: 'pod-security-admission-configuration-templates',
|
||||
level: 2
|
||||
},
|
||||
{
|
||||
@@ -430,7 +430,7 @@ They became available and were turned on by default in Kubernetes v1.23, and rep
|
||||
}, `You must add your new policy enforcement mechanisms `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
parentName: "p"
|
||||
}, `before`), ` you remove the PodSecurityPolicy objects. If you don't, you may create an opportunity for privilege escalation attacks within the cluster.`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h3", {
|
||||
"id": "remove-psp-rancher-workloads"
|
||||
"id": "removing-podsecuritypolicies-from-rancher-maintained-apps--marketplace-workloads"
|
||||
}, `Removing PodSecurityPolicies from Rancher-Maintained Apps & Marketplace Workloads`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `Rancher v2.7.2 offers a new major version of Rancher-maintained Helm charts. v102.x.y allows you to remove PSPs that were installed with previous versions of the chart. This new version replaces non-standard PSPs switches with the standardized `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `global.cattle.psp.enabled`), ` switch, which is turned off by default.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You must perform the following steps `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
@@ -441,7 +441,7 @@ They became available and were turned on by default in Kubernetes v1.23, and rep
|
||||
parentName: "li"
|
||||
}, `Configure the PSA controller to suit your needs. You can use one of Rancher's built-in `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#psa-config-templates"
|
||||
"href": "#pod-security-admission-configuration-templates"
|
||||
}, `PSA Configuration Templates`), `, or create a custom template and apply it to the clusters that you are migrating.`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
@@ -604,14 +604,14 @@ Flags:
|
||||
"id": "upgrading-charts-to-a-version-that-supports-kubernetes-v125"
|
||||
}, `Upgrading Charts to a Version That Supports Kubernetes v1.25`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You can proceed with your upgrade once any releases that had lingering PSPs are cleaned up. For Rancher-maintained workloads, follow the steps outlined in the `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#remove-psp-rancher-workloads"
|
||||
"href": "#removing-podsecuritypolicies-from-rancher-maintained-apps--marketplace-workloads"
|
||||
}, `Removing PodSecurityPolicies from Rancher-maintained Apps & Marketplace workloads`), ` section of this document.
|
||||
For workloads not maintained by Rancher, refer to the vendor documentation.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "caution"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "admonition"
|
||||
}, `Do not skip this step. Applications incompatible with Kubernetes v1.25 aren't guaranteed to work after a cleanup.`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h2", {
|
||||
"id": "psa-config-templates"
|
||||
"id": "pod-security-admission-configuration-templates"
|
||||
}, `Pod Security Admission Configuration Templates`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `Rancher offers PSA configuration templates. These are pre-defined security configurations that you can apply to a cluster. Rancher admins (or those with the right permissions) can `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "/v2.8/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/psa-config-templates"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/docs/reference-guides/cluster-configuration/rancher-server-configuration/rke2-cluster-configuration.md",
|
||||
"tags": [],
|
||||
"version": "current",
|
||||
"lastUpdatedAt": 1701905748,
|
||||
"formattedLastUpdatedAt": "Dec 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "RKE2 Cluster Configuration Reference"
|
||||
},
|
||||
@@ -437,8 +437,8 @@ const toc = [
|
||||
level: 6
|
||||
},
|
||||
{
|
||||
value: 'Additional Configuration',
|
||||
id: 'dual-stack-additional-config',
|
||||
value: 'Dual-stack Additional Configuration',
|
||||
id: 'dual-stack-additional-configuration',
|
||||
level: 6
|
||||
},
|
||||
{
|
||||
@@ -793,8 +793,8 @@ function MDXContent(_param) {
|
||||
parentName: "p",
|
||||
"href": "#service-cidr"
|
||||
}, `Service CIDR`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h6", {
|
||||
"id": "dual-stack-additional-config"
|
||||
}, `Additional Configuration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `When using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
"id": "dual-stack-additional-configuration"
|
||||
}, `Dual-stack Additional Configuration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `When using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium`), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
@@ -899,7 +899,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `10.42.0.0/16,2001:cafe:42:0::/56`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#dual-stack-additional-config"
|
||||
"href": "#dual-stack-additional-configuration"
|
||||
}, `Additional configuration`), ` is required when using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium`), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
@@ -918,7 +918,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `10.42.0.0/16,2001:cafe:42:0::/56`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#dual-stack-additional-config"
|
||||
"href": "#dual-stack-additional-configuration"
|
||||
}, `Additional configuration`), ` is required when using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium `), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.6/how-to-guides/advanced-user-guides/enable-api-audit-log.md",
|
||||
"tags": [],
|
||||
"version": "2.6",
|
||||
"lastUpdatedAt": 1692993467,
|
||||
"formattedLastUpdatedAt": "Aug 25, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Enabling the API Audit Log to Record System Events"
|
||||
},
|
||||
@@ -461,9 +461,7 @@ function MDXContent(_param) {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "audit-level"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `AUDIT_LEVEL`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
@@ -529,7 +527,7 @@ function MDXContent(_param) {
|
||||
"id": "audit-log-levels"
|
||||
}, `Audit Log Levels`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `The following table displays what parts of API transactions are logged for each `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#audit-level"
|
||||
"href": "#api-audit-log-options"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "a"
|
||||
}, `AUDIT_LEVEL`)), ` setting.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("table", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("thead", {
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.7/reference-guides/cluster-configuration/rancher-server-configuration/rke2-cluster-configuration.md",
|
||||
"tags": [],
|
||||
"version": "2.7",
|
||||
"lastUpdatedAt": 1701905748,
|
||||
"formattedLastUpdatedAt": "Dec 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "RKE2 Cluster Configuration Reference"
|
||||
},
|
||||
@@ -437,8 +437,8 @@ const toc = [
|
||||
level: 6
|
||||
},
|
||||
{
|
||||
value: 'Additional Configuration',
|
||||
id: 'dual-stack-additional-config',
|
||||
value: 'Dual-stack Additional Configuration',
|
||||
id: 'dual-stack-additional-configuration',
|
||||
level: 6
|
||||
},
|
||||
{
|
||||
@@ -793,8 +793,8 @@ function MDXContent(_param) {
|
||||
parentName: "p",
|
||||
"href": "#service-cidr"
|
||||
}, `Service CIDR`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h6", {
|
||||
"id": "dual-stack-additional-config"
|
||||
}, `Additional Configuration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `When using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
"id": "dual-stack-additional-configuration"
|
||||
}, `Dual-stack Additional Configuration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `When using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium`), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
@@ -899,7 +899,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `10.42.0.0/16,2001:cafe:42:0::/56`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#dual-stack-additional-config"
|
||||
"href": "#dual-stack-additional-configuration"
|
||||
}, `Additional configuration`), ` is required when using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium`), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
@@ -918,7 +918,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `10.42.0.0/16,2001:cafe:42:0::/56`), `.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#dual-stack-additional-config"
|
||||
"href": "#dual-stack-additional-configuration"
|
||||
}, `Additional configuration`), ` is required when using `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `cilium `), ` or `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.6/integrations-in-rancher/monitoring-and-alerting/rbac-for-monitoring.md",
|
||||
"tags": [],
|
||||
"version": "2.6",
|
||||
"lastUpdatedAt": 1701357034,
|
||||
"formattedLastUpdatedAt": "Nov 30, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Role-based Access Control"
|
||||
},
|
||||
@@ -767,9 +767,7 @@ function MDXContent(_param) {
|
||||
}, `monitoring-ui-view`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "monitoring-ui-view"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
parentName: "td"
|
||||
}, `Available as of Monitoring v2 14.5.100+`), ` Provides read-only access to external Monitoring UIs by giving a user permission to list the Prometheus, Alertmanager, and Grafana endpoints and make GET requests to Prometheus, Grafana, and Alertmanager UIs through the Rancher proxy.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h3", {
|
||||
"id": "assigning-roles-and-clusterroles-with-kubectl"
|
||||
@@ -986,7 +984,7 @@ subjects:
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "td",
|
||||
"href": "#monitoring-ui-view"
|
||||
"href": "#additional-monitoring-clusterroles"
|
||||
}, `monitoring-ui-view`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-azure-ad.md",
|
||||
"tags": [],
|
||||
"version": "current",
|
||||
"lastUpdatedAt": 1686439683,
|
||||
"formattedLastUpdatedAt": "Jun 10, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Configure Azure AD"
|
||||
},
|
||||
@@ -497,9 +497,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `Name`), ` (something like `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `Rancher`), `).`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "3.2"
|
||||
})), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
}, `Rancher`), `).`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "li"
|
||||
@@ -1035,10 +1033,10 @@ If Rancher is still configured to use the Azure AD Graph API when it is retired,
|
||||
"href": "#global"
|
||||
}, `tables`), ` below for the full list of endpoint changes that Rancher performs. Admins do not need to do this manually.`))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"id": "air-gapped-environments"
|
||||
}, `Air-Gapped Environments`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `In air-gapped environments, admins should ensure that their endpoints are `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
}, `Air-Gapped Environments`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `In air-gapped environments, admins should ensure that their endpoints are whitelisted (see note on `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#3.2"
|
||||
}, `whitelisted`), ` since the Graph Endpoint URL is changing.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"href": "#1-register-rancher-with-azure"
|
||||
}, `Step 3.2 of Register Rancher with Azure`), `) since the Graph Endpoint URL is changing.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"id": "rolling-back-the-migration"
|
||||
}, `Rolling Back the Migration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `If you need to roll back your migration, please note the following:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("ol", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.0-2.4/getting-started/installation-and-upgrade/advanced-options/advanced-use-cases/enable-api-audit-log.md",
|
||||
"tags": [],
|
||||
"version": "2.0-2.4",
|
||||
"lastUpdatedAt": 1663953084,
|
||||
"formattedLastUpdatedAt": "Sep 23, 2022",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Enabling the API Audit Log to Record System Events"
|
||||
},
|
||||
@@ -463,9 +463,7 @@ function MDXContent(_param) {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "audit-level"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `AUDIT_LEVEL`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
@@ -531,7 +529,7 @@ function MDXContent(_param) {
|
||||
"id": "audit-log-levels"
|
||||
}, `Audit Log Levels`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `The following table displays what parts of API transactions are logged for each `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#audit-level"
|
||||
"href": "#api-audit-log-options"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "a"
|
||||
}, `AUDIT_LEVEL`)), ` setting.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("table", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("thead", {
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.8/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-azure-ad.md",
|
||||
"tags": [],
|
||||
"version": "2.8",
|
||||
"lastUpdatedAt": 1696627994,
|
||||
"formattedLastUpdatedAt": "Oct 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Configure Azure AD"
|
||||
},
|
||||
@@ -497,9 +497,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `Name`), ` (something like `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `Rancher`), `).`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "3.2"
|
||||
})), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
}, `Rancher`), `).`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "li"
|
||||
@@ -1035,10 +1033,10 @@ If Rancher is still configured to use the Azure AD Graph API when it is retired,
|
||||
"href": "#global"
|
||||
}, `tables`), ` below for the full list of endpoint changes that Rancher performs. Admins do not need to do this manually.`))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"id": "air-gapped-environments"
|
||||
}, `Air-Gapped Environments`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `In air-gapped environments, admins should ensure that their endpoints are `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
}, `Air-Gapped Environments`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `In air-gapped environments, admins should ensure that their endpoints are whitelisted (see note on `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#3.2"
|
||||
}, `whitelisted`), ` since the Graph Endpoint URL is changing.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"href": "#1-register-rancher-with-azure"
|
||||
}, `Step 3.2 of Register Rancher with Azure`), `) since the Graph Endpoint URL is changing.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"id": "rolling-back-the-migration"
|
||||
}, `Rolling Back the Migration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `If you need to roll back your migration, please note the following:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("ol", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/pod-security-standards.md",
|
||||
"tags": [],
|
||||
"version": "current",
|
||||
"lastUpdatedAt": 1686450196,
|
||||
"formattedLastUpdatedAt": "Jun 11, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Pod Security Standards (PSS) & Pod Security Admission (PSA)"
|
||||
},
|
||||
@@ -348,7 +348,7 @@ const toc = [
|
||||
},
|
||||
{
|
||||
value: 'Removing PodSecurityPolicies from Rancher-Maintained Apps & Marketplace Workloads',
|
||||
id: 'remove-psp-rancher-workloads',
|
||||
id: 'removing-podsecuritypolicies-from-rancher-maintained-apps--marketplace-workloads',
|
||||
level: 3
|
||||
},
|
||||
{
|
||||
@@ -373,7 +373,7 @@ const toc = [
|
||||
},
|
||||
{
|
||||
value: 'Pod Security Admission Configuration Templates',
|
||||
id: 'psa-config-templates',
|
||||
id: 'pod-security-admission-configuration-templates',
|
||||
level: 2
|
||||
},
|
||||
{
|
||||
@@ -430,7 +430,7 @@ They became available and were turned on by default in Kubernetes v1.23, and rep
|
||||
}, `You must add your new policy enforcement mechanisms `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
parentName: "p"
|
||||
}, `before`), ` you remove the PodSecurityPolicy objects. If you don't, you may create an opportunity for privilege escalation attacks within the cluster.`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h3", {
|
||||
"id": "remove-psp-rancher-workloads"
|
||||
"id": "removing-podsecuritypolicies-from-rancher-maintained-apps--marketplace-workloads"
|
||||
}, `Removing PodSecurityPolicies from Rancher-Maintained Apps & Marketplace Workloads`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `Rancher v2.7.2 offers a new major version of Rancher-maintained Helm charts. v102.x.y allows you to remove PSPs that were installed with previous versions of the chart. This new version replaces non-standard PSPs switches with the standardized `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `global.cattle.psp.enabled`), ` switch, which is turned off by default.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You must perform the following steps `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
@@ -441,7 +441,7 @@ They became available and were turned on by default in Kubernetes v1.23, and rep
|
||||
parentName: "li"
|
||||
}, `Configure the PSA controller to suit your needs. You can use one of Rancher's built-in `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#psa-config-templates"
|
||||
"href": "#pod-security-admission-configuration-templates"
|
||||
}, `PSA Configuration Templates`), `, or create a custom template and apply it to the clusters that you are migrating.`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
@@ -604,14 +604,14 @@ Flags:
|
||||
"id": "upgrading-charts-to-a-version-that-supports-kubernetes-v125"
|
||||
}, `Upgrading Charts to a Version That Supports Kubernetes v1.25`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `You can proceed with your upgrade once any releases that had lingering PSPs are cleaned up. For Rancher-maintained workloads, follow the steps outlined in the `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#remove-psp-rancher-workloads"
|
||||
"href": "#removing-podsecuritypolicies-from-rancher-maintained-apps--marketplace-workloads"
|
||||
}, `Removing PodSecurityPolicies from Rancher-maintained Apps & Marketplace workloads`), ` section of this document.
|
||||
For workloads not maintained by Rancher, refer to the vendor documentation.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("admonition", {
|
||||
"type": "caution"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "admonition"
|
||||
}, `Do not skip this step. Applications incompatible with Kubernetes v1.25 aren't guaranteed to work after a cleanup.`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h2", {
|
||||
"id": "psa-config-templates"
|
||||
"id": "pod-security-admission-configuration-templates"
|
||||
}, `Pod Security Admission Configuration Templates`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `Rancher offers PSA configuration templates. These are pre-defined security configurations that you can apply to a cluster. Rancher admins (or those with the right permissions) can `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/psa-config-templates"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.8/how-to-guides/advanced-user-guides/enable-api-audit-log.md",
|
||||
"tags": [],
|
||||
"version": "2.8",
|
||||
"lastUpdatedAt": 1696627994,
|
||||
"formattedLastUpdatedAt": "Oct 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Enabling the API Audit Log to Record System Events"
|
||||
},
|
||||
@@ -461,9 +461,7 @@ function MDXContent(_param) {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "audit-level"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `AUDIT_LEVEL`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
@@ -529,7 +527,7 @@ function MDXContent(_param) {
|
||||
"id": "audit-log-levels"
|
||||
}, `Audit Log Levels`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `The following table displays what parts of API transactions are logged for each `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#audit-level"
|
||||
"href": "#api-audit-log-options"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "a"
|
||||
}, `AUDIT_LEVEL`)), ` setting.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("table", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("thead", {
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.6/reference-guides/cluster-configuration/rancher-server-configuration/k3s-cluster-configuration.md",
|
||||
"tags": [],
|
||||
"version": "2.6",
|
||||
"lastUpdatedAt": 1701905748,
|
||||
"formattedLastUpdatedAt": "Dec 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "K3s Cluster Configuration Reference"
|
||||
},
|
||||
@@ -532,7 +532,7 @@ function MDXContent(_param) {
|
||||
parentName: "ul"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "li",
|
||||
"href": "#cluster-config-file"
|
||||
"href": "#cluster-config-file-reference"
|
||||
}, `Cluster Config File`), `: Instead of using the Rancher UI to choose Kubernetes options for the cluster, advanced users can create a K3s config file. Using a config file allows you to set any of the `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "li",
|
||||
"href": "https://rancher.com/docs/k3s/latest/en/installation/install-options/"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.7/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-azure-ad.md",
|
||||
"tags": [],
|
||||
"version": "2.7",
|
||||
"lastUpdatedAt": 1686439683,
|
||||
"formattedLastUpdatedAt": "Jun 10, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Configure Azure AD"
|
||||
},
|
||||
@@ -497,9 +497,7 @@ function MDXContent(_param) {
|
||||
parentName: "p"
|
||||
}, `Name`), ` (something like `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "p"
|
||||
}, `Rancher`), `).`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "3.2"
|
||||
})), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
}, `Rancher`), `).`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", {
|
||||
parentName: "li"
|
||||
@@ -1035,10 +1033,10 @@ If Rancher is still configured to use the Azure AD Graph API when it is retired,
|
||||
"href": "#global"
|
||||
}, `tables`), ` below for the full list of endpoint changes that Rancher performs. Admins do not need to do this manually.`))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"id": "air-gapped-environments"
|
||||
}, `Air-Gapped Environments`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `In air-gapped environments, admins should ensure that their endpoints are `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
}, `Air-Gapped Environments`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `In air-gapped environments, admins should ensure that their endpoints are whitelisted (see note on `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#3.2"
|
||||
}, `whitelisted`), ` since the Graph Endpoint URL is changing.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"href": "#1-register-rancher-with-azure"
|
||||
}, `Step 3.2 of Register Rancher with Azure`), `) since the Graph Endpoint URL is changing.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h4", {
|
||||
"id": "rolling-back-the-migration"
|
||||
}, `Rolling Back the Migration`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `If you need to roll back your migration, please note the following:`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("ol", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("li", {
|
||||
parentName: "ol"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.7/reference-guides/cluster-configuration/rancher-server-configuration/k3s-cluster-configuration.md",
|
||||
"tags": [],
|
||||
"version": "2.7",
|
||||
"lastUpdatedAt": 1701905748,
|
||||
"formattedLastUpdatedAt": "Dec 6, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "K3s Cluster Configuration Reference"
|
||||
},
|
||||
@@ -627,7 +627,7 @@ function MDXContent(_param) {
|
||||
parentName: "ul"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "li",
|
||||
"href": "#cluster-config-file"
|
||||
"href": "#cluster-config-file-reference"
|
||||
}, `Cluster Config File`), `: Instead of using the Rancher UI to choose Kubernetes options for the cluster, advanced users can create a K3s config file. Using a config file allows you to set any of the `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "li",
|
||||
"href": "https://rancher.com/docs/k3s/latest/en/installation/install-options/"
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/docs/how-to-guides/advanced-user-guides/enable-api-audit-log.md",
|
||||
"tags": [],
|
||||
"version": "current",
|
||||
"lastUpdatedAt": 1692993467,
|
||||
"formattedLastUpdatedAt": "Aug 25, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Enabling the API Audit Log to Record System Events"
|
||||
},
|
||||
@@ -461,9 +461,7 @@ function MDXContent(_param) {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "audit-level"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "td"
|
||||
}, `AUDIT_LEVEL`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
@@ -529,7 +527,7 @@ function MDXContent(_param) {
|
||||
"id": "audit-log-levels"
|
||||
}, `Audit Log Levels`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("p", null, `The following table displays what parts of API transactions are logged for each `, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "p",
|
||||
"href": "#audit-level"
|
||||
"href": "#api-audit-log-options"
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("inlineCode", {
|
||||
parentName: "a"
|
||||
}, `AUDIT_LEVEL`)), ` setting.`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("table", null, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("thead", {
|
||||
@@ -324,8 +324,8 @@ const metadata = {
|
||||
"editUrl": "https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.5/explanations/integrations-in-rancher/monitoring-and-alerting/rbac-for-monitoring.md",
|
||||
"tags": [],
|
||||
"version": "2.5",
|
||||
"lastUpdatedAt": 1701357034,
|
||||
"formattedLastUpdatedAt": "Nov 30, 2023",
|
||||
"lastUpdatedAt": 1704760227,
|
||||
"formattedLastUpdatedAt": "Jan 9, 2024",
|
||||
"frontMatter": {
|
||||
"title": "Role-based Access Control"
|
||||
},
|
||||
@@ -675,9 +675,7 @@ function MDXContent(_param) {
|
||||
}, `monitoring-ui-view`), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
id: "monitoring-ui-view"
|
||||
}), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("em", {
|
||||
parentName: "td"
|
||||
}, `Available as of Monitoring v2 14.5.100+`), ` Provides read-only access to external Monitoring UIs by giving a user permission to list the Prometheus, Alertmanager, and Grafana endpoints and make GET requests to Prometheus, Grafana, and Alertmanager UIs through the Rancher proxy.`)))), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("h3", {
|
||||
"id": "assigning-roles-and-clusterroles-with-kubectl"
|
||||
@@ -830,7 +828,7 @@ subjects:
|
||||
"align": null
|
||||
}, /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("a", {
|
||||
parentName: "td",
|
||||
"href": "#monitoring-ui-view"
|
||||
"href": "#additional-monitoring-clusterroles"
|
||||
}, `monitoring-ui-view`)), /*#__PURE__*/ (0,_mdx_js_react__WEBPACK_IMPORTED_MODULE_1__/* .mdx */ .kt)("td", {
|
||||
parentName: "tr",
|
||||
"align": null
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
+4
-4
File diff suppressed because one or more lines are too long
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user