Files
rancher-docs/integrations-in-rancher/neuvector.html
T

26 lines
38 KiB
HTML
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!doctype html>
<html lang="en" dir="ltr" class="docs-wrapper docs-doc-page docs-version-current plugin-docs plugin-id-default docs-doc-id-integrations-in-rancher/neuvector">
<head>
<meta charset="UTF-8">
<meta name="generator" content="Docusaurus v2.3.1">
<title data-rh="true">NeuVector Integration | Rancher</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="http://ranchermanager.docs.rancher.com/integrations-in-rancher/neuvector"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="current"><meta data-rh="true" name="docusaurus_tag" content="docs-default-current"><meta data-rh="true" name="docsearch:version" content="current"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-current"><meta data-rh="true" property="og:title" content="NeuVector Integration | Rancher"><meta data-rh="true" name="description" content="NeuVector Integration in Rancher"><meta data-rh="true" property="og:description" content="NeuVector Integration in Rancher"><link data-rh="true" rel="icon" href="/img/favicon.png"><link data-rh="true" rel="canonical" href="http://ranchermanager.docs.rancher.com/integrations-in-rancher/neuvector"><link data-rh="true" rel="alternate" href="http://ranchermanager.docs.rancher.com/integrations-in-rancher/neuvector" hreflang="en"><link data-rh="true" rel="alternate" href="http://ranchermanager.docs.rancher.com/zh/integrations-in-rancher/neuvector" hreflang="zh"><link data-rh="true" rel="alternate" href="http://ranchermanager.docs.rancher.com/integrations-in-rancher/neuvector" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link rel="preconnect" href="https://www.googletagmanager.com">
<script>window.dataLayer=window.dataLayer||[]</script>
<script>!function(e,t,a,n,g){e[n]=e[n]||[],e[n].push({"gtm.start":(new Date).getTime(),event:"gtm.js"});var m=t.getElementsByTagName(a)[0],r=t.createElement(a);r.async=!0,r.src="https://www.googletagmanager.com/gtm.js?id=GTM-57KS2MW",m.parentNode.insertBefore(r,m)}(window,document,"script","dataLayer")</script>
<link rel="search" type="application/opensearchdescription+xml" title="Rancher" href="/opensearch.xml">
<script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" charset="UTF-8" data-domain-script="0f98beb0-fc4c-417d-a42e-564e2cae42d2" async></script>
<script src="/scripts/optanonwrapper.js" async></script><link rel="stylesheet" href="/assets/css/styles.35be4547.css">
<link rel="preload" href="/assets/js/runtime~main.2b85fd7f.js" as="script">
<link rel="preload" href="/assets/js/main.d8782442.js" as="script">
</head>
<body class="navigation-with-keyboard">
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-57KS2MW" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
<div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/">v2.7</a><ul class="dropdown__menu"><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/integrations-in-rancher/neuvector">v2.7</a></li><li><a class="dropdown__link" href="/v2.6/integrations-in-rancher/neuvector">v2.6</a></li><li><a class="dropdown__link" href="/v2.5">v2.5</a></li><li><a class="dropdown__link" href="/v2.0-v2.4">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/versions">All versions</a></li></ul></div></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link"><svg viewBox="0 0 24 24" width="20" height="20" aria-hidden="true" class="iconLanguage_nlXk"><path fill="currentColor" d="M12.87 15.07l-2.54-2.51.03-.03c1.74-1.94 2.98-4.17 3.71-6.53H17V4h-7V2H8v2H1v1.99h11.17C11.5 7.92 10.44 9.75 9 11.35 8.07 10.32 7.3 9.19 6.69 8h-2c.73 1.63 1.73 3.17 2.98 4.56l-5.09 5.02L4 19l5-5 3.11 3.11.76-2.04zM18.5 10h-2L12 22h2l1.12-3h4.75L21 22h2l-4.5-12zm-2.62 7l1.62-4.33L19.12 17h-3.24z"></path></svg>English</a><ul class="dropdown__menu"><li><a href="/integrations-in-rancher/neuvector" target="_self" rel="noopener noreferrer" class="dropdown__link dropdown__link--active" lang="en">English</a></li><li><a href="/zh/integrations-in-rancher/neuvector" target="_self" rel="noopener noreferrer" class="dropdown__link" lang="zh">简体中文</a></li></ul></div><a href="https://github.com/rancher/rancher-docs" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link navbar__github">GitHub<svg width="13.5" height="13.5" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a><a href="https://rancher.com" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link">Rancher Home<svg width="13.5" height="13.5" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="Search"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">Search</span></span><span class="DocSearch-Button-Keys"></span></button></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0 docsWrapper_BCFX"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebarViewport_Xe31"><div class="sidebar_njMd"><nav aria-label="Docs sidebar" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/">What is Rancher?</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/getting-started/overview">Getting Started</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/pages-for-subheaders/new-user-guides">How-to Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/pages-for-subheaders/best-practices">Reference Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" href="/pages-for-subheaders/cloud-marketplace">Integrations in Rancher</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/cloud-marketplace">Cloud Marketplace Integration</a><button aria-label="Toggle the collapsible sidebar category &#x27;Cloud Marketplace Integration&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/cis-scans">CIS Scans</a><button aria-label="Toggle the collapsible sidebar category &#x27;CIS Scans&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/fleet-gitops-at-scale">Continuous Delivery with Fleet</a><button aria-label="Toggle the collapsible sidebar category &#x27;Continuous Delivery with Fleet&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/harvester">Harvester Integration</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/istio">Istio</a><button aria-label="Toggle the collapsible sidebar category &#x27;Istio&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/longhorn">Longhorn - Cloud native distributed block storage for Kubernetes</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/logging">Logging</a><button aria-label="Toggle the collapsible sidebar category &#x27;Logging&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/monitoring-and-alerting">Monitoring and Alerting</a><button aria-label="Toggle the collapsible sidebar category &#x27;Monitoring and Alerting&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/integrations-in-rancher/neuvector">NeuVector Integration</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/opa-gatekeeper">OPA Gatekeeper</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/rancher-extensions">Rancher Extensions</a></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/faq/general-faq">FAQ</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/troubleshooting/general-troubleshooting">Troubleshooting</a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/contribute-to-rancher">Contributing to Rancher</a></li></ul></nav></div></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Integrations in Rancher</span><meta itemprop="position" content="1"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">NeuVector Integration</span><meta itemprop="position" content="2"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">Version: v2.7</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>NeuVector Integration</h1></header><h3 class="anchor anchorWithStickyNavbar_LWe7" id="neuvector-integration-in-rancher">NeuVector Integration in Rancher<a href="#neuvector-integration-in-rancher" class="hash-link" aria-label="Direct link to NeuVector Integration in Rancher" title="Direct link to NeuVector Integration in Rancher">​</a></h3><p>New in Rancher v2.6.5, <a href="https://open-docs.neuvector.com/" target="_blank" rel="noopener noreferrer">NeuVector 5.x</a> is an open-source container-centric security platform that is now integrated into Rancher. NeuVector offers real-time compliance, visibility, and protection for critical applications and data during runtime. NeuVector provides a firewall, container process/file system monitoring, security auditing with CIS benchmarks, and vulnerability scanning. For more information on Rancher security, please see the <a href="/pages-for-subheaders/rancher-security">security documentation</a>.</p><p>NeuVector can be enabled through a Helm chart that may be installed either through <strong>Apps</strong> or through the <strong>Cluster Tools</strong> button in the Rancher UI. Once the Helm chart is installed, users can easily <a href="https://open-docs.neuvector.com/deploying/rancher#deploy-and-manage-neuvector-through-rancher-apps-marketplace" target="_blank" rel="noopener noreferrer">deploy and manage NeuVector clusters within Rancher</a>.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="installing-neuvector-with-rancher">Installing NeuVector with Rancher<a href="#installing-neuvector-with-rancher" class="hash-link" aria-label="Direct link to Installing NeuVector with Rancher" title="Direct link to Installing NeuVector with Rancher">​</a></h3><p>The Harvester Helm Chart is used to manage access to the NeuVector UI in Rancher where users can navigate directly to deploy and manage their NeuVector clusters.</p><p><strong>To navigate to and install the NeuVector chart through Apps:</strong></p><ol><li>Click <strong>☰ &gt; Cluster Management</strong>.</li><li>On the Clusters page, go to the cluster where you want to deploy NeuVector, and click <strong>Explore</strong>.</li><li>Go to <strong>Apps &gt; Charts</strong>, and install <strong>NeuVector</strong> from the chart repo.</li><li>Different cluster types require different container runtimes. When configuring Helm chart values, go to the <strong>Container Runtime</strong> section, and select your runtime in accordance with the cluster type. Finally, click <strong>Install</strong> again.</li></ol><p>Some examples are as follows:</p><ul><li><p>RKE1: <code>docker</code></p></li><li><p>K3s and RKE2: <code>k3scontainerd</code></p></li><li><p>AKS: <code>containerd</code> for v1.19 and up</p></li><li><p>EKS: <code>docker</code> for v1.22 and below; <code>containerd</code> for v1.23 and up</p></li><li><p>GKE: <code>containerd</code> (see the <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/using-containerd" target="_blank" rel="noopener noreferrer">Google docs</a> for more)</p><div class="theme-admonition theme-admonition-note alert alert--secondary admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_S0QG"><p>Only one container runtime engine may be selected at a time during installation.</p></div></div></li></ul><p><strong>To navigate to and install the NeuVector chart through Cluster Tools:</strong></p><ol><li>Click <strong>☰ &gt; Cluster Management</strong>.</li><li>On the Clusters page, go to the cluster where you want to deploy NeuVector, and click <strong>Explore</strong>.</li><li>Click on <strong>Cluster Tools</strong> at the bottom of the left navigation bar.</li><li>Repeat step 4 above to select your container runtime accordingly, then click <strong>Install</strong> again.</li></ol><h3 class="anchor anchorWithStickyNavbar_LWe7" id="accessing-neuvector-from-the-rancher-ui">Accessing NeuVector from the Rancher UI<a href="#accessing-neuvector-from-the-rancher-ui" class="hash-link" aria-label="Direct link to Accessing NeuVector from the Rancher UI" title="Direct link to Accessing NeuVector from the Rancher UI">​</a></h3><ol><li>Navigate to the cluster explorer of the cluster where NeuVector is installed. In the left navigation bar, click <strong>NeuVector</strong>.</li><li>Click the external link to go to the NeuVector UI. Once the link is selected, users must accept the <code>END USER LICENSE AGREEMENT</code> to access the NeuVector UI.</li></ol><h3 class="anchor anchorWithStickyNavbar_LWe7" id="uninstalling-neuvector-from-the-rancher-ui">Uninstalling NeuVector from the Rancher UI<a href="#uninstalling-neuvector-from-the-rancher-ui" class="hash-link" aria-label="Direct link to Uninstalling NeuVector from the Rancher UI" title="Direct link to Uninstalling NeuVector from the Rancher UI">​</a></h3><p><strong>To uninstall from Apps:</strong></p><ol><li>Click <strong>☰ &gt; Cluster Management</strong>.</li><li>Under <strong>Apps</strong>, click <strong>Installed Apps</strong>.</li><li>Under <code>cattle-neuvector-system</code>, select both the NeuVector app (and the associated CRD if desired), then click <strong>Delete</strong>.</li></ol><p><strong>To uninstall from Cluster Tools:</strong></p><ol><li>Click <strong>☰ &gt; Cluster Management</strong>.</li><li>Click on <strong>Cluster Tools</strong> at the bottom-left of the screen, then click on the trash can icon under the NeuVector chart. Select <code>Delete the CRD associated with this app</code> if desired, then click <strong>Delete</strong>.</li></ol><h3 class="anchor anchorWithStickyNavbar_LWe7" id="github-repository">GitHub Repository<a href="#github-repository" class="hash-link" aria-label="Direct link to GitHub Repository" title="Direct link to GitHub Repository">​</a></h3><p>The NeuVector project is available <a href="https://github.com/neuvector/neuvector" target="_blank" rel="noopener noreferrer">here</a>.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="documentation">Documentation<a href="#documentation" class="hash-link" aria-label="Direct link to Documentation" title="Direct link to Documentation">​</a></h3><p>The NeuVector documentation is <a href="https://open-docs.neuvector.com/" target="_blank" rel="noopener noreferrer">here</a>.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="architecture">Architecture<a href="#architecture" class="hash-link" aria-label="Direct link to Architecture" title="Direct link to Architecture">​</a></h3><p>The NeuVector security solution contains four types of security containers: Controllers, Enforcers, Managers, and Scanners. A special container called an All-in-One is also provided to combine the Controller, Enforcer, and Manager functions all in one container, primarily for Docker-native deployments. There is also an Updater which, when run, will update the CVE database.</p><ul><li><strong>Controller:</strong> Manages the NeuVector Enforcer container; provides REST APIs for the management console.</li><li><strong>Enforcer:</strong> Enforces security policies.</li><li><strong>Manager:</strong> Provides a web-UI and CLI console to manage the NeuVector platform.</li><li><strong>All-in-One:</strong> Includes the Controller, Enforcer, and Manager.</li><li><strong>Scanner:</strong> Performs the vulnerability and compliance scanning for images, containers, and nodes.</li><li><strong>Updater:</strong> Updates the CVE database for Neuvector (when run); redeploys scanner pods.</li></ul><figcaption>**NeuVector Security Containers:**</figcaption><p><img loading="lazy" alt="NeuVector Security Containers" src="/assets/images/neuvector-security-containers-06d127dd89635663657feecb3310dfd5.png" width="850" height="395" class="img_ev3q"></p><figcaption>**NeuVector Architecture:**</figcaption><p><img loading="lazy" alt="NeuVector Architecture" src="/assets/images/neuvector-architecture-a985ec6ea53faf5c7d808055f8d64be5.png" width="1243" height="836" class="img_ev3q"></p><p>To learn more about NeuVector&#x27;s architecture, please refer <a href="https://open-docs.neuvector.com/basics/overview#architecture" target="_blank" rel="noopener noreferrer">here</a>.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="cpu-and-memory-allocations">CPU and Memory Allocations<a href="#cpu-and-memory-allocations" class="hash-link" aria-label="Direct link to CPU and Memory Allocations" title="Direct link to CPU and Memory Allocations">​</a></h3><p>Below are the minimum recommended computing resources for the NeuVector chart installation in a default deployment. Note that the resource limit is not set.</p><table><thead><tr><th>Container</th><th>CPU - Request</th><th>Memory - Request</th></tr></thead><tbody><tr><td>Controller</td><td>3 (1GB 1vCPU needed per controller)</td><td>*</td></tr><tr><td>Enforcer</td><td>On all nodes (500MB .5vCPU)</td><td>1GB</td></tr><tr><td>Manager</td><td>1 (500MB .5vCPU)</td><td>*</td></tr><tr><td>Scanner</td><td>3 (100MB .5vCPU)</td><td>*</td></tr></tbody></table><p>*<!-- --> Minimum 1GB of memory total required for Controller, Manager, and Scanner containers combined.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="hardened-cluster-support---calico-and-canal">Hardened Cluster Support - Calico and Canal<a href="#hardened-cluster-support---calico-and-canal" class="hash-link" aria-label="Direct link to Hardened Cluster Support - Calico and Canal" title="Direct link to Hardened Cluster Support - Calico and Canal">​</a></h3><div class="tabs-container tabList__CuJ"><ul role="tablist" aria-orientation="horizontal" class="tabs"><li role="tab" tabindex="0" aria-selected="true" class="tabs__item tabItem_LNqP tabs__item--active">RKE1</li><li role="tab" tabindex="-1" aria-selected="false" class="tabs__item tabItem_LNqP">RKE2</li></ul><div class="margin-top--md"><div role="tabpanel" class="tabItem_Ymn6"><ul><li><p>All NeuVector components are deployable if PSP is set to true.</p><p><strong><em>New in v2.6.7</em></strong></p><p>You will need to set additional configuration for your hardened cluster environment as follows:</p></li></ul><ol><li>Click <strong>☰ &gt; Cluster Management</strong>.</li><li>Go to the cluster that you created and click <strong>Explore</strong>.</li><li>In the left navigation bar, click <strong>Apps</strong>.</li><li>Install (or upgrade to) NeuVector version <code>100.0.1+up2.2.2</code>.</li></ol><ul><li><p>Under <strong>Edit Options</strong> &gt; <strong>Other Configuration</strong>, enable <strong>Pod Security Policy</strong> by checking the box (no other config needed):</p><p> <img loading="lazy" alt="Enable PSP for RKE1 Hardened Cluster" src="/assets/images/psp-nv-rke-d87045c466a93d8487507a469d32d0db.png" width="946" height="557" class="img_ev3q"></p></li></ul><ol><li>Click <strong>Install</strong> at the bottom-right to complete.</li></ol></div><div role="tabpanel" class="tabItem_Ymn6" hidden=""><ul><li>NeuVector components Controller and Enforcer are deployable if PSP is set to true.</li></ul><p> <strong>Applicable to NeuVector chart version 100.0.0+up2.2.0 only:</strong></p><ul><li><p>For Manager, Scanner, and Updater components, additional configuration is required as shown below:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">kubectl patch deploy neuvector-manager-pod -n cattle-neuvector-system --patch &#x27;{&quot;spec&quot;:{&quot;template&quot;:{&quot;spec&quot;:{&quot;securityContext&quot;:{&quot;runAsUser&quot;: 5400}}}}}&#x27;</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">kubectl patch deploy neuvector-scanner-pod -n cattle-neuvector-system --patch &#x27;{&quot;spec&quot;:{&quot;template&quot;:{&quot;spec&quot;:{&quot;securityContext&quot;:{&quot;runAsUser&quot;: 5400}}}}}&#x27;</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">kubectl patch cronjob neuvector-updater-pod -n cattle-neuvector-system --patch &#x27;{&quot;spec&quot;:{&quot;jobTemplate&quot;:{&quot;spec&quot;:{&quot;template&quot;:{&quot;spec&quot;:{&quot;securityContext&quot;:{&quot;runAsUser&quot;: 5400}}}}}}}&#x27;</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><br><p><strong><em>New in v2.6.7</em></strong></p><p>You will need to set additional configuration for your hardened cluster environment.</p><blockquote><p><strong>Note:</strong> You must update your config in both RKE2 and K3s hardened clusters as shown below.</p></blockquote></li></ul><ol><li>Click <strong>☰ &gt; Cluster Management</strong>.</li><li>Go to the cluster that you created and click <strong>Explore</strong>.</li><li>In the left navigation bar, click <strong>Apps</strong>.</li><li>Install (or upgrade to) NeuVector version <code>100.0.1+up2.2.2</code>.</li></ol><ul><li><p>Under <strong>Edit Options</strong> &gt; <strong>Other Configuration</strong>, enable <strong>Pod Security Policy</strong> by checking the box. Note that you must also enter a value greater than <code>zero</code> for <code>Manager runAsUser ID</code>, <code>Scanner runAsUser ID</code>, and <code>Updater runAsUser ID</code>:</p><p> <img loading="lazy" alt="Enable PSP for RKE2 and K3s Hardened Clusters" src="/assets/images/psp-nv-rke2-a0eabc8b8a5e8d0476d885c29ca55017.png" width="942" height="562" class="img_ev3q"></p></li></ul><ol><li>Click <strong>Install</strong> at the bottom-right to complete.</li></ol></div></div></div><h3 class="anchor anchorWithStickyNavbar_LWe7" id="selinux-enabled-cluster-support---calico-and-canal">SELinux-enabled Cluster Support - Calico and Canal<a href="#selinux-enabled-cluster-support---calico-and-canal" class="hash-link" aria-label="Direct link to SELinux-enabled Cluster Support - Calico and Canal" title="Direct link to SELinux-enabled Cluster Support - Calico and Canal">​</a></h3><p>To enable SELinux on RKE2 clusters, follow the steps below:</p><ul><li>NeuVector components Controller and Enforcer are deployable if PSP is set to true.</li></ul><p><strong>Applicable to NeuVector chart version 100.0.0+up2.2.0 only:</strong></p><ul><li>For Manager, Scanner, and Updater components, additional configuration is required as shown below:</li></ul><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">kubectl patch deploy neuvector-manager-pod -n cattle-neuvector-system --patch &#x27;{&quot;spec&quot;:{&quot;template&quot;:{&quot;spec&quot;:{&quot;securityContext&quot;:{&quot;runAsUser&quot;: 5400}}}}}&#x27;</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">kubectl patch deploy neuvector-scanner-pod -n cattle-neuvector-system --patch &#x27;{&quot;spec&quot;:{&quot;template&quot;:{&quot;spec&quot;:{&quot;securityContext&quot;:{&quot;runAsUser&quot;: 5400}}}}}&#x27;</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">kubectl patch cronjob neuvector-updater-pod -n cattle-neuvector-system --patch &#x27;{&quot;spec&quot;:{&quot;jobTemplate&quot;:{&quot;spec&quot;:{&quot;template&quot;:{&quot;spec&quot;:{&quot;securityContext&quot;:{&quot;runAsUser&quot;: 5400}}}}}}}&#x27;</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg class="copyButtonIcon_y97N" viewBox="0 0 24 24"><path d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg class="copyButtonSuccessIcon_LjdS" viewBox="0 0 24 24"><path d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><h3 class="anchor anchorWithStickyNavbar_LWe7" id="cluster-support-in-an-air-gapped-environment">Cluster Support in an Air-Gapped Environment<a href="#cluster-support-in-an-air-gapped-environment" class="hash-link" aria-label="Direct link to Cluster Support in an Air-Gapped Environment" title="Direct link to Cluster Support in an Air-Gapped Environment">​</a></h3><ul><li>All NeuVector components are deployable on a cluster in an air-gapped environment without any additional configuration needed.</li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="support-limitations">Support Limitations<a href="#support-limitations" class="hash-link" aria-label="Direct link to Support Limitations" title="Direct link to Support Limitations">​</a></h3><ul><li><p>Only admins and cluster owners are currently supported.</p></li><li><p>Fleet multi-cluster deployment is not supported.</p></li><li><p>NeuVector is not supported on a Windows cluster.</p></li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="other-limitations">Other Limitations<a href="#other-limitations" class="hash-link" aria-label="Direct link to Other Limitations" title="Direct link to Other Limitations">​</a></h3><ul><li><p>Currently, NeuVector feature chart installation fails when a NeuVector partner chart already exists. To work around this issue, uninstall the NeuVector partner chart and reinstall the NeuVector feature chart.</p></li><li><p>Sometimes when the controllers are not ready, the NeuVector UI is not accessible from the Rancher UI. During this time, controllers will try to restart, and it takes a few minutes for the controllers to be active.</p></li><li><p>Container runtime is not auto-detected for different cluster types when installing the NeuVector chart. To work around this, you can specify the runtime manually.</p></li></ul></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/docs/integrations-in-rancher/neuvector.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>Edit this page</a></div><div class="col lastUpdated_vwxv"><span class="theme-last-updated">Last updated<!-- --> on <b><time datetime="2022-12-09T01:26:28.000Z">Dec 9, 2022</time></b></span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="Docs pages navigation"><a class="pagination-nav__link pagination-nav__link--prev" href="/integrations-in-rancher/monitoring-and-alerting/promql-expressions"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">PromQL Expression Reference</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/integrations-in-rancher/opa-gatekeeper"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">OPA Gatekeeper</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#neuvector-integration-in-rancher" class="table-of-contents__link toc-highlight">NeuVector Integration in Rancher</a></li><li><a href="#installing-neuvector-with-rancher" class="table-of-contents__link toc-highlight">Installing NeuVector with Rancher</a></li><li><a href="#accessing-neuvector-from-the-rancher-ui" class="table-of-contents__link toc-highlight">Accessing NeuVector from the Rancher UI</a></li><li><a href="#uninstalling-neuvector-from-the-rancher-ui" class="table-of-contents__link toc-highlight">Uninstalling NeuVector from the Rancher UI</a></li><li><a href="#github-repository" class="table-of-contents__link toc-highlight">GitHub Repository</a></li><li><a href="#documentation" class="table-of-contents__link toc-highlight">Documentation</a></li><li><a href="#architecture" class="table-of-contents__link toc-highlight">Architecture</a></li><li><a href="#cpu-and-memory-allocations" class="table-of-contents__link toc-highlight">CPU and Memory Allocations</a></li><li><a href="#hardened-cluster-support---calico-and-canal" class="table-of-contents__link toc-highlight">Hardened Cluster Support - Calico and Canal</a></li><li><a href="#selinux-enabled-cluster-support---calico-and-canal" class="table-of-contents__link toc-highlight">SELinux-enabled Cluster Support - Calico and Canal</a></li><li><a href="#cluster-support-in-an-air-gapped-environment" class="table-of-contents__link toc-highlight">Cluster Support in an Air-Gapped Environment</a></li><li><a href="#support-limitations" class="table-of-contents__link toc-highlight">Support Limitations</a></li><li><a href="#other-limitations" class="table-of-contents__link toc-highlight">Other Limitations</a></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2023 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
<script src="/assets/js/runtime~main.2b85fd7f.js"></script>
<script src="/assets/js/main.d8782442.js"></script>
</body>
</html>