Commit Graph

186 Commits

Author SHA1 Message Date
Billy Tat 410ae2701a Remove 2.8 specific content and fix typo 2023-10-24 13:06:13 -07:00
Marty Hernandez Avedon 2651168190 Merge branch 'main' into add-rancher-security-best-practices 2023-10-19 17:00:23 -04:00
Jiaqi Luo 0940a22d46 Update the namespace exception list at multiple places (#926) 2023-10-18 12:30:02 -07:00
Billy Tat 5c083c320a Remove version-latest dir
Originally added due to some unexpected versioning behavior that's no longer reproducible

Apply suggestions from code review

Co-authored-by: Marty Hernandez Avedon <martyavedon@gmail.com>
2023-10-12 10:26:54 -07:00
Billy Tat e60feac44c Merge pull request #896 from moio/revise_hardware_recommendations
Revise hardware recommendations
2023-10-12 09:09:41 -07:00
Jiaqi Luo d2a00b73e4 call out the options that Rancher handles differently with the upstream RKE2 and K3s (#904) 2023-10-11 14:52:03 -07:00
Marty Hernandez Avedon e89fd0494f Apply suggestions from code review 2023-10-11 15:44:01 -04:00
Pietro Dell'Amore 1f1c43eccf Improve rancher security docs
This commit will improve the public documentation related to rancher-security.
2023-10-11 11:02:51 -03:00
Silvio Moioli 5c83f5a6cc Merge branch 'main' into revise_hardware_recommendations 2023-10-11 10:17:52 +02:00
pdellamore b9154c57d7 Update docs/reference-guides/rancher-security/rancher-security-best-practices.md
Co-authored-by: Paulo Gomes <paulo.gomes.uk@gmail.com>
2023-10-10 10:01:18 -03:00
Silvio Moioli 01dc68f1cb tuning-and-best-practices-for-rancher-at-scale: comma fixes
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-10 13:27:55 +02:00
Silvio Moioli d5b649a6ca uniform thousand numbers
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-10 13:26:08 +02:00
Pietro Dell'Amore aaf628caf6 Improve documentation
Add more context to endpoint exposure decisions and also add more details into
the documentation.
2023-10-09 11:45:38 -03:00
Pietro Dell'Amore 1aafb1b436 fix conflicts 2023-10-09 11:32:21 -03:00
Billy Tat 7467f99d89 Merge branch 'main' into 2023-Q4-2.8x 2023-10-06 10:19:22 -07:00
Silvio Moioli 6d77c45ff2 Merge branch 'main' into revise_hardware_recommendations 2023-10-06 10:01:50 +02:00
Silvio Moioli 586c109b17 Apply suggestions from code review
Co-authored-by: Billy Tat <btat@suse.com>
2023-10-06 09:53:58 +02:00
Billy Tat b27b00da87 Revert "Revert "Merge branch 'main' into main-to-2023-Q3-v2.7x""
This reverts commit 5eb3b2876f.
2023-10-05 16:32:09 -07:00
Silvio Moioli 6ea7053b23 tuning-and-best-practices-for-rancher-at-scale: reword title
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-05 08:53:49 +02:00
Silvio Moioli 2392110de5 tuning-and-best-practices-for-rancher-at-scale: move ACE configuration instructions in the reference guide
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-05 08:49:49 +02:00
Marty Hernandez Avedon 6b5aa5edfc Apply suggestions from code review
Co-authored-by: Silvio Moioli <moio@suse.com>
2023-10-04 15:28:16 -04:00
Pietro Dell'Amore b2b1262450 Add Rancher Security Best Practices section
This will add a new section at rancher-security section related to some best practices
recommended by the rancher security team.
2023-10-04 15:03:17 -03:00
Silvio Moioli 740202cd2b Apply suggestions from code review
Co-authored-by: Marty Hernandez Avedon <marty.avedon@suse.com>
2023-10-04 09:11:17 +02:00
Marty Hernandez Avedon 650579d391 Apply suggestions from code review 2023-10-03 15:49:12 -04:00
Marty Hernandez Avedon cead220aaf #420 Canonical links for Rancher-security (#895)
* canonicized k3s-self-assessment-guide

* canonicized rke1-hardening-guide

* canonicized rke2-self-assessment-guide

* canonicized selinux-rpm

* canonicized rancher-security
2023-10-02 10:47:31 -04:00
Silvio Moioli 16651823dd tuning-and-best-practices-for-rancher-at-scale: add more detailed RBAC considerations
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-02 11:14:19 +02:00
Silvio Moioli 234ae7be4d tuning-and-best-practices-for-rancher-at-scale: make language more assertive
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-02 11:13:50 +02:00
Silvio Moioli 1006603d73 tips-for-scaling-rancher: rename to tuning-and-best-practices-for-rancher-at-scale
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-02 11:13:48 +02:00
Silvio Moioli fa3e39189a tips-for-scaling-rancher: recommend unmanaged Kubernetes distros
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-02 11:12:41 +02:00
Silvio Moioli 3498a2f360 tips-for-scaling-rancher: clarify language on etcd recommendations
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-02 11:12:41 +02:00
Silvio Moioli 66adb074d5 tips-for-scaling-rancher: add suggestions to minimize RoleBindings
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-02 11:12:41 +02:00
Silvio Moioli 6e6864f2f0 tips-for-scaling-rancher: use correct capitalization for RoleBindings
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-02 11:12:40 +02:00
Silvio Moioli 4329a632ad tips-for-scaling-rancher: use correct capitalization for etcd
Signed-off-by: Silvio Moioli <silvio@moioli.net>
2023-10-02 11:12:40 +02:00
Colleen Murphy 70380d36a7 Add hardening guide for Rancher Webhook (#864) 2023-09-29 14:39:29 -04:00
Billy Tat 57bd584612 Merge pull request #891 from btat/reapply-pr788
Reapply PR #788
2023-09-28 11:23:19 -07:00
Colleen Murphy 9af9982d68 Add guide on Rancher impersonation (#873)
Customers often see issues with Rancher impersonation and want to
understand better what Rancher is doing and why. This change adds an
explanation for what impersonation means in Rancher and why it exists,
and discusses some of the resources it creates in order to aid in
troubleshooting.
2023-09-28 14:19:43 -04:00
Billy Tat 0eaaeef9bc Reapply PR #788 2023-09-28 10:49:18 -07:00
Billy Tat 5eb3b2876f Revert "Merge branch 'main' into main-to-2023-Q3-v2.7x"
This reverts commit 45aa5bb9bd, reversing
changes made to 5380fffa27.
2023-09-27 15:42:04 -07:00
Billy Tat f967061cd4 Revert "Merge pull request #884 from btat/main-to-2023-Q3-v2.7x"
This reverts commit 03d60e2851, reversing
changes made to bcfcf6f62c.
2023-09-27 15:41:42 -07:00
Billy Tat 45aa5bb9bd Merge branch 'main' into main-to-2023-Q3-v2.7x 2023-09-27 14:48:50 -07:00
Marty Hernandez Avedon c7c9caa3e6 fixed broken link syntax: #[...].md > .md# (#872) 2023-09-22 17:34:01 -04:00
Marty Hernandez Avedon 38959f4ba9 #420 Canonical links for hardening guides (#870)
* canonicized k3s hardening guides

* canonicized rke1 hardening guides

* canonicized rke2 hardening guides
2023-09-22 16:40:03 -04:00
Marty Hernandez Avedon 0baf42a3e9 canonicized reference-guides/prometheus + /rancher-manager-architecture (#869) 2023-09-22 16:18:55 -04:00
Andy Pitcher 250171d9e4 Rebase and modify cis-1.7 page to include 1.26/1.27 2023-09-20 23:48:07 -03:00
Andy Pitcher 61ff71e235 Remove leading backslash 2023-09-20 23:37:08 -03:00
Andy Pitcher 15606d6db1 Escape <txt> values with backslash
Avoids markdown compilation issues
2023-09-20 23:37:08 -03:00
Andy Pitcher 40cd732265 Update rke2-self-assessment-guide-with-cis-v1.7 2023-09-20 23:37:08 -03:00
Andy Pitcher 81464c73d6 Merge branch 'main' into rke1-self-assessment-guide-with-cis-1.7 2023-09-20 17:28:57 -04:00
Andy Pitcher 35f27f4130 Merge branch 'main' into k3s-self-assessment-guide-with-cis-1.24 2023-09-20 16:24:04 -04:00
Andy Pitcher 00c18c19cd Merge pull request #860 from andypitcher/rke2-self-assessment-guide-with-cis-1.24
[cis-1.24] update rke2-self-assessment-guide
2023-09-20 15:33:55 -04:00