Commit Graph

82 Commits

Author SHA1 Message Date
pdellamore
854582ad8e Update Rancher CVE Status (#1493)
* Update Rancher CVE Status

* Update versioned docs

* Update versioned_docs/version-2.9/reference-guides/rancher-security/security-advisories-and-cves.md

---------

Co-authored-by: Guilherme Macedo <guilherme@gmacedo.com>
2024-10-01 13:32:38 -07:00
martyav
40901b29f7 fixed rancher-security.md 2024-09-17 16:25:05 -04:00
martyav
3552897924 fixed kubernetes-security-best-practices.md 2024-09-17 16:18:39 -04:00
Marty Hernandez Avedon
e53d68026e Apply suggestions from code review 2024-06-18 11:44:51 -04:00
Pietro Dell'Amore
ec6abe391e Add Rancher Security Release (Jun-2024) CVEs to latest/2.8/2.7 2024-06-18 11:55:32 -03:00
martyav
71a2179f29 resolving merging conflict 2024-06-11 10:24:10 -04:00
martyav
a4f1a2a9f4 #1287 - ports listed also relevant for rke 2024-06-10 12:30:40 -04:00
Billy Tat
42989a7850 Merge pull request #1315 from btat/link-fixes
Fix external links
2024-06-04 10:46:16 -07:00
Marty Hernandez Avedon
e1634c61fd #1283 update Rancher security best practices to address public IP exposure (#1287)
* 1283 update Rancher security best practices to address public IP exposure

* link and bullet points

* Update docs/reference-guides/rancher-security/rancher-security-best-practices.md

* versioning

* typo
2024-06-03 14:39:44 -04:00
Billy Tat
d06d7d9663 Fix external links 2024-05-31 15:08:12 -07:00
martyav
06b16e2103 typo 2024-05-16 12:39:02 -04:00
Marty Hernandez Avedon
f08108947d Update docs/reference-guides/rancher-security/rancher-security-best-practices.md 2024-05-16 12:08:53 -04:00
martyav
d4af47a378 link and bullet points 2024-05-14 16:16:12 -04:00
martyav
35d5a5d9a1 1283 update Rancher security best practices to address public IP exposure 2024-05-14 16:07:44 -04:00
Marty Hernandez Avedon
6ccd0b7b6c Syncing sidebar with page titles and disambiguating brief titles (#1197)
* Syncing sidebar labels with page titles

Deploying Rancher Server: Update sidebar label to match title

* Installing/Upgrading Rancher: Update title to match sidebar

This is a reference/hub page for install guides with no step-by-step instructions, so we're breaking the -ing rule to match other reference pages as well as the current sidebar label

* Cluster Access: Update title to match sidebar

* Kubernetes Persistent Storage: Volumes and Storage Classes - Update title to match sidebar

* Don't have a Kubernetes cluster? Try one of these tutorials: Update title to match sidebar and make old title intro to page

* Don't have infrastructure for your Kubernetes cluster? Try one of these tutorials: Update title to match sidebar and make old title intro to page

* versioning Deploying Rancher Server update to other sidebars

* Setting Up Kubernetes Clusters in Rancher: Update sidebars to match title and other sidebar labels

* capitalization

* Creating a vSphere Cluster: Update sidebar to match title and other labels

* Creating a Nutanix AOS Cluster: Update sidebar to match title and other labels

* Kubernetes Clusters in Rancher Setup across the board for title and sidebar, to match convention in sidebar

* Kubernetes Resources: Updated title to match sidebar and distinguish from identically-titled page in troubleshooting section

* The Horizontal Pod Autoscaler: Updated title to match sidebar

* Backups and Disaster Recovery: Update title to match sidebar

* typo fix

* revert to Installation and Upgrade of Rancher

fix typo in title: Create Kubernetes Persistent files

* fix typo in Persistent Storage files

* Configuration: Update title to match sidebar item Monitoring V2 Configuration Guides

* Setup Guide: Make both sidebar + title Istio Setup guides to match other sidebar labels

* Best Practices: Update both to Best Practice Guides

* Architecture: Update to match sidebar Rancher Architecture.

Note that there are multiple pages with identical titles, one is on Fleet and another on some other subject

* Architecture: Retitle logging-architecture.md files Logging Architecture

* Architecture: Retitle fleet/architecture.md files Fleet Architecture

* GKE Cluster Configuration: Update sidebar to match title and other labels in same section

* Security: Update both to Rancher Security Guides

* RKE Hardening Guide: Update to match sidebar

* typo

* RKE2 Hardening Guide: Update to match sidebar

* K3s Hardening Guide: Update to match sidebar

* various FAQ pages: Add FAQ to title to disambiguate content

* Cloud Native Storage with Longhorn: Versioning so older pages match current title

* rm international pages for now

* typo in metadata killed build

* updated sidebar: plural Istio Setup Guides

* updating Monitoring Config Guides title/label and distinguishing from similar section under References

* monitoring V2 config examples: rm 'V2'

* Kubernetes Cluster Setup > Setting up a Kubernetes Cluster for Rancher Server
2024-04-09 17:10:29 -04:00
Billy Tat
6c24fdb4f7 Replace links to deploy-across-clusters/fleet.md 2024-04-08 18:42:40 -07:00
Paulo Gomes
755080de3d Update CVE page 2024-02-16 15:58:27 +00:00
Andy Pitcher
77a86a5acc Add Rancher Security Release (Feb-2024) CVEs to latest/2.8/2.7/2.6
- CVE-2023-32193
	- CVE-2023-32192
        - CVE-2023-22649
        - CVE-2023-32194
2024-02-09 12:45:37 -05:00
Billy Tat
dae1b76dc6 Update canonical links 2024-01-29 10:07:22 -08:00
Billy Tat
6d59b46f70 Merge remote-tracking branch 'upstream/main' into move-pages-for-subheaders-latest 2024-01-19 13:42:58 -08:00
Andy Pitcher
ef01bf25ee Add rancher-selinux's rpm install guide for EL9 2023-12-29 11:50:33 +01:00
Billy Tat
dd46955d9c [latest] Move files out of pages-for-subheaders 2023-12-22 13:33:02 -08:00
Billy Tat
03ea6163fb Port version-2.8 updates to latest (/docs) (#1013)
* Port version-2.8 updates to latest (/docs)

Includes changes from 1b6d9506 (2023-10-06) to 1f39a6ff (2023-11-30)

* Fix redirects
2023-12-06 14:48:27 -05:00
pdellamore
25771e2843 Add session management section (#981)
* Add note regarding rancher pentest reports public availability

This PR will add a note regarding third-party penetration test reports
public disclosure.

* Add session management section to rancher security best practices

This PR will create a new section inside Rancher Security Best Practices
adding security recommendations for RM deployments that might need additional
security controls.

* Apply suggestions from code review

Co-authored-by: Paulo Gomes <paulo.gomes.uk@gmail.com>

* Update docs/reference-guides/rancher-security/rancher-security-best-practices.md

* Update docs/reference-guides/rancher-security/rancher-security-best-practices.md

Co-authored-by: Guilherme Macedo <guilherme@gmacedo.com>

* versioned docs

---------

Co-authored-by: Pietro Dell'Amore <pdellamore@MacBook-Pro-de-Pietro.local>
Co-authored-by: Marty Hernandez Avedon <marty.avedon@suse.com>
Co-authored-by: Paulo Gomes <paulo.gomes.uk@gmail.com>
Co-authored-by: Guilherme Macedo <guilherme@gmacedo.com>
2023-11-16 11:35:02 -05:00
Billy Tat
410ae2701a Remove 2.8 specific content and fix typo 2023-10-24 13:06:13 -07:00
Marty Hernandez Avedon
2651168190 Merge branch 'main' into add-rancher-security-best-practices 2023-10-19 17:00:23 -04:00
Jiaqi Luo
0940a22d46 Update the namespace exception list at multiple places (#926) 2023-10-18 12:30:02 -07:00
Billy Tat
5c083c320a Remove version-latest dir
Originally added due to some unexpected versioning behavior that's no longer reproducible

Apply suggestions from code review

Co-authored-by: Marty Hernandez Avedon <martyavedon@gmail.com>
2023-10-12 10:26:54 -07:00
Marty Hernandez Avedon
e89fd0494f Apply suggestions from code review 2023-10-11 15:44:01 -04:00
Pietro Dell'Amore
1f1c43eccf Improve rancher security docs
This commit will improve the public documentation related to rancher-security.
2023-10-11 11:02:51 -03:00
pdellamore
b9154c57d7 Update docs/reference-guides/rancher-security/rancher-security-best-practices.md
Co-authored-by: Paulo Gomes <paulo.gomes.uk@gmail.com>
2023-10-10 10:01:18 -03:00
Pietro Dell'Amore
aaf628caf6 Improve documentation
Add more context to endpoint exposure decisions and also add more details into
the documentation.
2023-10-09 11:45:38 -03:00
Pietro Dell'Amore
1aafb1b436 fix conflicts 2023-10-09 11:32:21 -03:00
Billy Tat
7467f99d89 Merge branch 'main' into 2023-Q4-2.8x 2023-10-06 10:19:22 -07:00
Billy Tat
b27b00da87 Revert "Revert "Merge branch 'main' into main-to-2023-Q3-v2.7x""
This reverts commit 5eb3b2876f.
2023-10-05 16:32:09 -07:00
Pietro Dell'Amore
b2b1262450 Add Rancher Security Best Practices section
This will add a new section at rancher-security section related to some best practices
recommended by the rancher security team.
2023-10-04 15:03:17 -03:00
Marty Hernandez Avedon
cead220aaf #420 Canonical links for Rancher-security (#895)
* canonicized k3s-self-assessment-guide

* canonicized rke1-hardening-guide

* canonicized rke2-self-assessment-guide

* canonicized selinux-rpm

* canonicized rancher-security
2023-10-02 10:47:31 -04:00
Colleen Murphy
70380d36a7 Add hardening guide for Rancher Webhook (#864) 2023-09-29 14:39:29 -04:00
Billy Tat
5eb3b2876f Revert "Merge branch 'main' into main-to-2023-Q3-v2.7x"
This reverts commit 45aa5bb9bd, reversing
changes made to 5380fffa27.
2023-09-27 15:42:04 -07:00
Marty Hernandez Avedon
38959f4ba9 #420 Canonical links for hardening guides (#870)
* canonicized k3s hardening guides

* canonicized rke1 hardening guides

* canonicized rke2 hardening guides
2023-09-22 16:40:03 -04:00
Andy Pitcher
250171d9e4 Rebase and modify cis-1.7 page to include 1.26/1.27 2023-09-20 23:48:07 -03:00
Andy Pitcher
61ff71e235 Remove leading backslash 2023-09-20 23:37:08 -03:00
Andy Pitcher
15606d6db1 Escape <txt> values with backslash
Avoids markdown compilation issues
2023-09-20 23:37:08 -03:00
Andy Pitcher
40cd732265 Update rke2-self-assessment-guide-with-cis-v1.7 2023-09-20 23:37:08 -03:00
Andy Pitcher
81464c73d6 Merge branch 'main' into rke1-self-assessment-guide-with-cis-1.7 2023-09-20 17:28:57 -04:00
Andy Pitcher
35f27f4130 Merge branch 'main' into k3s-self-assessment-guide-with-cis-1.24 2023-09-20 16:24:04 -04:00
Andy Pitcher
00c18c19cd Merge pull request #860 from andypitcher/rke2-self-assessment-guide-with-cis-1.24
[cis-1.24] update rke2-self-assessment-guide
2023-09-20 15:33:55 -04:00
Andy Pitcher
1c2b3f3cce Merge pull request #854 from andypitcher/k3s-self-assessment-guide-with-cis-1.7
[cis-1.7] update k3s-self-assessment-guide
2023-09-20 15:33:40 -04:00
Guilherme Macedo
484a832dff Update k3s-self-assessment-guide-with-cis-v1.24
Signed-off-by: Guilherme Macedo <guilherme@gmacedo.com>
2023-09-20 13:25:51 -03:00
Andy Pitcher
f7e17a5885 Update rke2-self-assessment-guide-with-cis-v1.24 2023-09-20 13:18:43 -03:00