diff --git a/calico-cloud/compliance/compliance-reports-cis.mdx b/calico-cloud/compliance/compliance-reports-cis.mdx index ed22ba3225..0306866931 100644 --- a/calico-cloud/compliance/compliance-reports-cis.mdx +++ b/calico-cloud/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports for clusters connected t :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud/compliance/enable-compliance.mdx b/calico-cloud/compliance/enable-compliance.mdx index 0a85f039e1..e3fe3b512c 100644 --- a/calico-cloud/compliance/enable-compliance.mdx +++ b/calico-cloud/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Activate compliance reporting components on clusters connected to C :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud/compliance/overview.mdx b/calico-cloud/compliance/overview.mdx index 31d8fcc6a6..55813ef0ee 100644 --- a/calico-cloud/compliance/overview.mdx +++ b/calico-cloud/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Cloud compliance reports against Kubernetes :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud/release-notes/index.mdx b/calico-cloud/release-notes/index.mdx index 9d302a22f3..09bfa65081 100644 --- a/calico-cloud/release-notes/index.mdx +++ b/calico-cloud/release-notes/index.mdx @@ -67,7 +67,6 @@ For more information see [Deploy a dual ToR cluster](../networking/configuring/d ### Deprecated and removed features * All compliance reporting features are deprecated and will be removed in a future release. - We're building a new compliance reporting system that will eventually replace the current one. ## November 6, 2024 (version 20.2.0) diff --git a/calico-cloud_versioned_docs/version-22-2/compliance/compliance-reports-cis.mdx b/calico-cloud_versioned_docs/version-22-2/compliance/compliance-reports-cis.mdx index ed22ba3225..0306866931 100644 --- a/calico-cloud_versioned_docs/version-22-2/compliance/compliance-reports-cis.mdx +++ b/calico-cloud_versioned_docs/version-22-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports for clusters connected t :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-22-2/compliance/enable-compliance.mdx b/calico-cloud_versioned_docs/version-22-2/compliance/enable-compliance.mdx index 0a85f039e1..e3fe3b512c 100644 --- a/calico-cloud_versioned_docs/version-22-2/compliance/enable-compliance.mdx +++ b/calico-cloud_versioned_docs/version-22-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Activate compliance reporting components on clusters connected to C :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-22-2/compliance/overview.mdx b/calico-cloud_versioned_docs/version-22-2/compliance/overview.mdx index 31d8fcc6a6..55813ef0ee 100644 --- a/calico-cloud_versioned_docs/version-22-2/compliance/overview.mdx +++ b/calico-cloud_versioned_docs/version-22-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Cloud compliance reports against Kubernetes :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-22-2/release-notes/index.mdx b/calico-cloud_versioned_docs/version-22-2/release-notes/index.mdx index 1101fef0c1..089c0638f8 100644 --- a/calico-cloud_versioned_docs/version-22-2/release-notes/index.mdx +++ b/calico-cloud_versioned_docs/version-22-2/release-notes/index.mdx @@ -504,7 +504,6 @@ For more information see [Deploy a dual ToR cluster](../networking/configuring/d ### Deprecated and removed features * All compliance reporting features are deprecated and will be removed in a future release. - We're building a new compliance reporting system that will eventually replace the current one. ### Updating diff --git a/calico-cloud_versioned_docs/version-22-2/threat/container-threat-detection.mdx b/calico-cloud_versioned_docs/version-22-2/threat/container-threat-detection.mdx index 05d0594f42..8756075317 100644 --- a/calico-cloud_versioned_docs/version-22-2/threat/container-threat-detection.mdx +++ b/calico-cloud_versioned_docs/version-22-2/threat/container-threat-detection.mdx @@ -9,7 +9,6 @@ redirect_from: :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-23-2/compliance/compliance-reports-cis.mdx b/calico-cloud_versioned_docs/version-23-2/compliance/compliance-reports-cis.mdx index ed22ba3225..0306866931 100644 --- a/calico-cloud_versioned_docs/version-23-2/compliance/compliance-reports-cis.mdx +++ b/calico-cloud_versioned_docs/version-23-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports for clusters connected t :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-23-2/compliance/enable-compliance.mdx b/calico-cloud_versioned_docs/version-23-2/compliance/enable-compliance.mdx index 0a85f039e1..e3fe3b512c 100644 --- a/calico-cloud_versioned_docs/version-23-2/compliance/enable-compliance.mdx +++ b/calico-cloud_versioned_docs/version-23-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Activate compliance reporting components on clusters connected to C :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-23-2/compliance/overview.mdx b/calico-cloud_versioned_docs/version-23-2/compliance/overview.mdx index 31d8fcc6a6..55813ef0ee 100644 --- a/calico-cloud_versioned_docs/version-23-2/compliance/overview.mdx +++ b/calico-cloud_versioned_docs/version-23-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Cloud compliance reports against Kubernetes :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-23-2/release-notes/index.mdx b/calico-cloud_versioned_docs/version-23-2/release-notes/index.mdx index 8371ff642c..a06d18f54d 100644 --- a/calico-cloud_versioned_docs/version-23-2/release-notes/index.mdx +++ b/calico-cloud_versioned_docs/version-23-2/release-notes/index.mdx @@ -556,7 +556,6 @@ For more information see [Deploy a dual ToR cluster](../networking/configuring/d ### Deprecated and removed features * All compliance reporting features are deprecated and will be removed in a future release. - We're building a new compliance reporting system that will eventually replace the current one. ### Updating diff --git a/calico-enterprise/about/calico-product-editions.mdx b/calico-enterprise/about/calico-product-editions.mdx index 4808160a01..3ec34cedf4 100644 --- a/calico-enterprise/about/calico-product-editions.mdx +++ b/calico-enterprise/about/calico-product-editions.mdx @@ -62,7 +62,6 @@ import { CalicoProducts } from '/src/___new___/components'; | Deep packet inspection | | | | | | DDoS protection | | | | | | Workload-centric WAF | | | | | -| Compliance reporting and alerts | | | | | | SIEM integrations | | | | | | **Network Security for VMs and Bare Metal** | | | | | | Restrict traffic to/from hosts and VMs using network policy | | | | | diff --git a/calico-enterprise/about/index.mdx b/calico-enterprise/about/index.mdx index 414d02dc93..dfcee21ecb 100644 --- a/calico-enterprise/about/index.mdx +++ b/calico-enterprise/about/index.mdx @@ -190,7 +190,6 @@ All of this is built on Calico Open Source, the most widely used container netwo | Deep packet inspection | | | | | | DDoS protection | | | | | | Workload-centric WAF | | | | | -| Compliance reporting and alerts | | | | | | SIEM integrations | | | | | | **Network Security for VMs and Bare Metal** | | | | | | Restrict traffic to/from hosts and VMs using network policy | | | | | diff --git a/calico-enterprise/compliance/compliance-reports-cis.mdx b/calico-enterprise/compliance/compliance-reports-cis.mdx deleted file mode 100644 index dd3258e609..0000000000 --- a/calico-enterprise/compliance/compliance-reports-cis.mdx +++ /dev/null @@ -1,199 +0,0 @@ ---- -description: Configure CIS Kubernetes benchmark reports in Calico Enterprise to assess node and cluster compliance and download results from the in-cluster reporter as CSV. ---- - -# Configure CIS benchmark reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Use the $[prodname] Kubernetes CIS benchmark report to assess compliance for all assets in a Kubernetes cluster. - -## Value - -A standard requirement for an organization’s security and compliance posture is to assess your Kubernetes clusters against CIS benchmarks. The $[prodname] Kubernetes CIS benchmark report provides this comprehensive view into your Kubernetes clusters while strengthening your threat detection capability by looking beyond networking data. - -## Concepts - -### Default settings and configuration - -During $[prodname] installation, each node starts a pod named, `compliance-benchmarker`. A preconfigured Kubernetes CIS benchmark report is generated every hour. You can view the report in **Compliance**, **Compliance Reports**, download it to .csv format. - -To schedule the CIS benchmark report or change settings, use the **global report** resource. Global reports are configured as YAML files and are applied using `kubectl`. - -### Best practices - -We recommend that you review the CIS benchmark best practices for securing cluster component configurations here: [CIS benchmarks downloads](https://learn.cisecurity.org/benchmarks). - -## Before you begin - -**Required** - -* You [Enabled compliance reports](../compliance/enable-compliance) - -**Limitations** - -CIS benchmarks runs only on nodes where $[prodname] is running. This limitation may exclude control plane nodes in some managed cloud platforms (AKS, EKS, GKE). Because the user has limited control over installation of control plane nodes in managed cloud platforms, these reports may have limited use for cloud users. - -## How to - -- [Configure and schedule CIS benchmark reports](#configure-and-schedule-cis-benchmark-reports) -- [View report generation status](#view-report-generation-status) -- [Review and address CIS benchmark results](#review-and-address-cis-benchmark-results) -- [Manually run reports](#manually-run-reports) -- [Troubleshooting](#troubleshooting) - -### Configure and schedule CIS benchmark reports - -Verify that the `compliance-benchmarker` is running and the `cis-benchmark` report type is installed. - -```bash -kubectl get -n tigera-compliance daemonset compliance-benchmarker -kubectl get globalreporttype cis-benchmark -``` - -In the following example, we use a **GlobalReport** with CIS benchmark fields to schedule and filter results. The report is scheduled to run at midnight of the next day (in UTC), and the benchmark items 1.1.4 and 1.2.5 will be omitted from the results. - -| **Fields** | **Description** | -| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| schedule | The start and end time of the report using [crontab format](https://en.wikipedia.org/wiki/Cron). To allow for archiving, reports are generated approximately 30 minutes after the end time. A single report is limited to a maximum of two per hour. | -| highThreshold | **Optional**. Integer percentage value that determines the lower limit of passing tests to consider a node as healthy. Default: 100 | -| medThreshold | **Optional**. Integer percentage value that determines the lower limit of passing tests to consider a node as unhealthy. Default: 50 | -| includeUnscoredTests | **Optional**. Boolean value that when false, applies a filter to exclude tests that are marked as “Unscored” by the CIS benchmark standard. If true, the tests will be included in the report. Default: true | -| numFailedTests | **Optional**. Integer value that sets the number of tests to display in the Top-failed Tests section of the CIS benchmark report. Default: 5 | -| resultsFilter | **Optional**. An include or exclude filter to apply on the test results that will appear on the report. | - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-results - labels: - deployment: production -spec: - reportType: cis-benchmark - schedule: 0 0 * * * - cis: - highThreshold: 100 - medThreshold: 50 - includeUnscoredTests: true - numFailedTests: 5 - resultsFilters: - - benchmarkSelection: { kubernetesVersion: '1.13' } - exclude: ['1.1.4', '1.2.5'] -``` - -### View report generation status - -To view the status of a report, you must use the `kubectl` command. For example: - -```bash -kubectl get globalreports.projectcalico.org daily-cis-results -o yaml -``` - -In a report, the job status types are: - -- **lastScheduledReportJob**: - The most recently scheduled job for generating the report. Because reports are scheduled in order, the “end time” of - this report will be the “start time” of the next scheduled report. -- **activeReportJobs**: - Default = allows up to 5 concurrent report generation jobs. -- **lastFailedReportJobs**: - Default = keeps the 3 most recent failed jobs and deletes older ones. A single report generation job will be retried - up to 6 times (by default) before it is marked as failed. -- **lastSuccessfulReportJobs**: - Default = keeps the 2 most recent successful jobs and deletes older ones. - -#### Change the default report generation time - -By default, reports are generated 30 minutes after the end of the report, to ensure all of the audit data is archived. -(However, this gap does not affect the data collected “start/end time” for a report.) - -You can adjust the time for audit data for cases like initial report testing, to demo a report, or when manually -creating a report that is not counted in global report status. - -To change the delay, go to the installation manifest, and uncomment and set the environment variable -`TIGERA_COMPLIANCE_JOB_START_DELAY`. Specify value as a [Duration string][parse-duration]. - -### Review and address CIS benchmark results - -We recommend the following approach to CIS benchmark reports results: - -1. Download the Kubernetes CIS benchmarks and export your full CIS benchmark results in .csv format. -1. In the compliance dashboard, review the "Top-Failed Tests" section to identify which tests are the most problematic. -1. Cross-reference the top-failed tests to identify which nodes are failing that test. -1. Look up those tests in the [Kubernetes benchmark document](https://downloads.cisecurity.org/#/) and follow the remediation steps to resolve the failure. -1. Discuss with your infrastructure and security team if this remediation is viable within your organization. -1. If so, update your nodes with the fix and ensure that the test passes on the next generation of the report. -1. If the fix is not viable but is an acceptable risk to take within the organization, configure the report specification to exclude that test index so that it no longer appears in the report. -1. If the fix is not viable and not an acceptable risk to take on, keep the failing test within the report so that your team is reminded to address the issue as soon as possible. - -### Manually run reports - -You can manually run reports at any time. For example, run a manual report: - -- To specify a different start/end time -- If a scheduled report fails - -$[prodname] GlobalReport schedules Kubernetes Jobs which create a single-run pod to generate a report and store it in Elasticsearch. Because you need to run manual reports as a pod, you need higher permissions: allow `create` access for pods in namespace `tigera-compliance` using the `tigera-compliance-reporter` service account. - -To manually run a report: - -1. Download the pod template corresponding to your installation method. - **Operator** - - For management and standalone clusters: - - ```bash - curl -O $[filesUrl]/manifests/compliance-reporter-pod.yaml - ``` - - For managed clusters: - - ```bash - curl $[filesUrl]/manifests/compliance-reporter-pod-managed.yaml -o compliance-reporter-pod.yaml - ``` - -1. Edit the template as follows: - - - Edit the pod name if required. - - If you are using your own docker repository, update the container image name with your repo and image tag. - - Set the following environments according to the instructions in the downloaded manifest: - - `TIGERA_COMPLIANCE_REPORT_NAME` - - `TIGERA_COMPLIANCE_REPORT_START_TIME` - - `TIGERA_COMPLIANCE_REPORT_END_TIME` - -1. Apply the updated manifest, and query the status of the pod to ensure it completes. - Upon completion, the report is available in the web console. - - ```bash - # Apply the compliance report pod - kubectl apply -f compliance-reporter-pod.yaml - # Query the status of the pod - kubectl get pod -n=tigera-compliance - ``` - -:::note - -Manually-generated reports do not appear in GlobalReport status. - -::: - -### Troubleshooting - -**Problem**: Compliance reports can fail to generate if the `compliance-benchmarker` component cannot find the required `kubelet` or `kubectl` binaries to determine the Kubernetes version running on the cluster. - -**Solution or workaround**: If a node is running within a container (not running `kubelet` as a binary), make sure the `kubectl` binary is available in the `/usr/bin` directory. - -## Additional resources - -- For details on configuring and scheduling reports, see [Global reports](../reference/resources/globalreport.mdx) -- For other predefined compliance reports, see [Compliance reports](../reference/resources/compliance-reports/index.mdx) - -[parse-duration]: https://golang.org/pkg/time/#ParseDuration diff --git a/calico-enterprise/compliance/enable-compliance.mdx b/calico-enterprise/compliance/enable-compliance.mdx deleted file mode 100644 index 8c60a2c317..0000000000 --- a/calico-enterprise/compliance/enable-compliance.mdx +++ /dev/null @@ -1,49 +0,0 @@ ---- -description: Turn on the in-cluster compliance reporter, controller, snapshotter, and server components that produce Calico Enterprise compliance reports and CIS benchmarks. ---- - -# Enable compliance reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Enabling compliance reports improves the cluster's compliance posture. It involves generating compliance reports for Kubernetes clusters based on archived flow and audit logs for Calico Enterprise and Kubernetes resources. The process includes components for snapshotting configurations, generating reports, managing jobs, providing APIs with RBAC, and benchmarking security. - -## Value - -The compliance system consists of several key components that work together to ensure comprehensive compliance monitoring and reporting: - - - `compliance-snapshotter` : Lists required configurations and pushes snapshots to Elasticsearch, providing visibility into configuration changes. - - `compliance-reporter` : Generates reports by analyzing configuration history, determining configuration evolution and identifying "worst-case outliers." - - `compliance-controller` : Manages the creation, deletion, and monitoring of report generation jobs. - - `compliance-server` : Offers API for report management and enforces RBAC. - - `compliance-benchmarker` : Runs CIS Kubernetes Benchmark checks on each node to ensure secure deployment. - -**Required** - -* For managed clusters, ensure that compliance reporting is enabled in the management cluster. - -### Enable compliance reports using kubectl - -* Create a compliance custom resource, named `tigera-secure`, in the cluster. - -```bash -kubectl apply -f - < \ No newline at end of file diff --git a/calico-enterprise/compliance/index.mdx b/calico-enterprise/compliance/index.mdx index 4cf8b13d87..d561170195 100644 --- a/calico-enterprise/compliance/index.mdx +++ b/calico-enterprise/compliance/index.mdx @@ -1,19 +1,15 @@ --- -description: Generate compliance reports and encrypt in-cluster traffic in your Calico Enterprise cluster, with archived flow logs, audit logs, CIS benchmarks, and WireGuard. +description: Encrypt in-cluster traffic with WireGuard and configure security options for your Calico Enterprise cluster. hide_table_of_contents: true --- import { DocCardLink, DocCardLinkLayout } from '/src/___new___/components'; -# Compliance and security +# Security -Get reports on Kubernetes workloads and environments for regulatory compliance. -Encrypt traffic in your cluster with WireGuard. +Encrypt traffic in your cluster with WireGuard, and configure security options for your $[prodname] cluster. - - - diff --git a/calico-enterprise/compliance/overview.mdx b/calico-enterprise/compliance/overview.mdx deleted file mode 100644 index 1e4ac16448..0000000000 --- a/calico-enterprise/compliance/overview.mdx +++ /dev/null @@ -1,382 +0,0 @@ ---- -description: Schedule and run Calico Enterprise compliance reports against Kubernetes workloads using archived flow logs and audit logs stored in Elasticsearch. ---- - -# Schedule and run compliance reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Schedule and run compliance reports to assess Kubernetes workloads and environments for regulatory compliance. - -## Value - -Compliance tools that rely on periodic snapshots, do not provide accurate assessments of Kubernetes workloads against your compliance standards. $[prodname] compliance dashboard and reports provide a complete inventory of regulated workloads, along with evidence of enforcement of network controls for these workloads. Additionally, audit reports are available to see changes to any network security controls. - -## Concepts - -### Compliance reports at a glance - -Compliance report are based on archived flow logs and audit logs for all of your $[prodname] resources, plus any audit logs you've configured for Kubernetes resources in the Kubernetes API server: - -- Pods -- Host endpoints -- Service accounts -- Namespaces -- Kubernetes service endpoints -- Global network sets -- Calico and Kubernetes network policies -- Global network policies - -Compliance reports provide the following high-level information: - -- **Protection** - - - Endpoints explicitly protected using ingress or egress policy - - Endpoints with Envoy enabled - -- **Policies and services** - - - Policies and services associated with endpoints - - Policy audit logs - -- **Traffic** - - Allowed ingress/egress traffic to/from namespaces - - Allowed ingress/egress traffic to/from the internet - -![compliance-reporting](/img/calico-enterprise/compliance-reporting.png) - -## Before you begin - -**Unsupported** - -- AKS -- GKE -- OpenShift -- TKG - -**Required** - -* You [Enabled compliance reports](../compliance/enable-compliance) - -- Ensure that all nodes in your Kubernetes clusters are time-synchronized using NTP or similar (for accurate audit log timestamps) - -- [Configure audit logs for Kubernetes resources](../observability/elastic/audit-overview.mdx) - - You must configure audit logs for Kubernetes resources through the Kubernetes API to get a complete view of all resources. - -## How to - -- [Configure report permissions](#configure-report-permissions) -- [Configure and schedule reports](#configure-and-schedule-reports) -- [View report generation status](#view-report-generation-status) -- [Run reports](#run-reports) - -### Configure report permissions - -Report permissions are granted using the standard Kubernetes RBAC based on ClusterRole and ClusterRoleBindings. The following table outlines the required RBAC verbs for each resource type for a specific user actions. - -| **Action** | **globalreporttypes** | **globalreports** | **globalreports/status** | -| ------------------------------------------------------- | ------------------------------- | --------------------------------- | ------------------------ | -| Manage reports (create/modify/delete) | | \* | get | -| View status of report generation through kubectl | | get | get | -| List the generated reports and summary status in the UI | | list + get (for required reports) | | -| Export the generated reports from the UI | get (for the particular report) | get (for required reports) | | - -The following sample manifest creates RBAC for three users: Paul, Candice and David. - -- Paul has permissions to create/modify/delete the report schedules and configuration, but does not have permission to export generated reports from the UI. -- Candice has permissions to list and export generated reports from the UI, but cannot modify the report schedule or configuration. -- David has permissions to list and export generated `dev-inventory` reports from the UI, but cannot list or download other reports, nor modify the report - schedule or configuration. - -```yaml -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-manage-report-config -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['*'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreports/status'] - verbs: ['get', 'list', 'watch'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-manage-report-config -subjects: - - kind: User - name: paul - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-manage-report-config - apiGroup: rbac.authorization.k8s.io - ---- -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-all-reports -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['get', 'list'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreporttypes'] - verbs: ['get'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-all-reports -subjects: - - kind: User - name: candice - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-list-download-all-reports - apiGroup: rbac.authorization.k8s.io - ---- -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-dev-inventory -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['list'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['get'] - resourceNames: ['dev-inventory'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreporttypes'] - verbs: ['get'] - resourceNames: ['dev-inventory'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-dev-inventory -subjects: - - kind: User - name: david - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-list-download-dev-inventory - apiGroup: rbac.authorization.k8s.io -``` - -### Configure and schedule reports - -To configure and schedule a compliance report, create a [GlobalReport](../reference/resources/globalreport.mdx) with the following information. - -| **Fields** | **Description** | -| --------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| name | Unique name for your report. | -| reportType | One of the following predefined report types: `inventory`, `network-access`, `policy-audit`. | -| schedule | The start and end time of the report using [crontab format](https://en.wikipedia.org/wiki/Cron). To allow for archiving, reports are generated approximately 30 minutes after the end time. A single report is limited to a maximum of two per hour. | -| endpoints | **Optional**. For inventory and network-access reports, specifies the endpoints to include in the report. For the policy-audit report, restricts audit logs to include only policies that apply to the selected endpoints. If not specified, the report includes all endpoints and audit logs. | -| jobNodeSelector | **Optional**. Limits report generation jobs to specific nodes. | -| suspend | **Optional**. Suspends report generation. All in-flight reports will complete, and future scheduled reports are suspended. | - -:::note - -GlobalReports can only be configured using kubectl (not calicoctl); and they cannot be edited in the Tigera -Secure EE the web console. - -::: - -The following sections provide sample schedules for the predefined reports. - -### Weekly reports, all endpoints - -The following report schedules weekly inventory reports for _all_ endpoints. The jobs that create the reports will run -on the infrastructure nodes (e.g. nodetype == 'infrastructure'). - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: weekly-full-inventory -spec: - reportType: inventory - schedule: 0 0 * * 0 - jobNodeSelector: - nodetype: infrastructure -``` - -### Daily reports, selected endpoints - -The following report schedules daily inventory reports for production endpoints (e.g. deployment == ‘production’). - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-production-inventory -spec: - reportType: inventory - endpoints: - selector: deployment == 'production' - schedule: 0 0 * * * -``` - -### Hourly reports, endpoints in named namespaces - -The following report schedules hourly network-access reports for the accounts department endpoints, that are -specified using the namespace names: **payable**, **collections** and **payroll**. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: hourly-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - names: ['payable', 'collections', 'payroll'] - schedule: 0 * * * * -``` - -### Daily reports, endpoints in selected namespaces - -The following report schedules daily network-access reports for the accounts department with endpoints specified using -a namespace selector. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - selector: department == 'accounts' - schedule: 0 0 * * * -``` - -### Monthly reports, endpoints for named service accounts in named namespaces - -The following schedules monthly audit reports. The audited policy is restricted to policy that applies to -widgets/controller endpoints specified by the namespace **widgets** and service account **controller**. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: monthly-widgets-controller-tigera-policy-audit -spec: - reportType: policy-audit - schedule: 0 0 1 * * - endpoints: - serviceAccounts: - names: ['controller'] - namespaces: - names: ['widgets'] -``` - -### View report generation status - -To view the status of a report, you must use the `kubectl` command. For example: - -```bash -kubectl get globalreports.projectcalico.org daily-inventory.p -o yaml -``` - -In a report, the job status types are: - -- **lastScheduledReportJob**: - The most recently scheduled job for generating the report. Because reports are scheduled in order, the “end time” of - this report will be the “start time” of the next scheduled report. -- **activeReportJobs**: - Default = allows up to 5 concurrent report generation jobs. -- **lastFailedReportJobs**: - Default = keeps the 3 most recent failed jobs and deletes older ones. A single report generation job will be retried - up to 6 times (by default) before it is marked as failed. -- **lastSuccessfulReportJobs**: - Default = keeps the 2 most recent successful jobs and deletes older ones. - -### Change the default report generation time - -By default, reports are generated 30 minutes after the end of the report, to ensure all of the audit data is archived. -(However, this gap does not affect the data collected “start/end time” for a report.) - -You can adjust the time for audit data for cases like initial report testing, to demo a report, or when manually -creating a report that is not counted in global report status. - -To change the delay, go to the installation manifest, and uncomment and set the environment -`TIGERA_COMPLIANCE_JOB_START_DELAY`. Specify value as a [Duration string][parse-duration]. - -### Run reports - -You can run reports at any time to specify a different start/end time, and if a scheduled report fails. - -$[prodname] GlobalReport schedules Kubernetes Jobs, which create a single-run pod to generate a report and store it -in Elasticsearch. Because you need to run reports as a pod, you need higher permissions: allow `create` access for pods in namespace `tigera-compliance` using the `tigera-compliance-reporter` service account. - -To run a report on demand: - -1. Download the pod template corresponding to your installation method. - - For management and standalone clusters: - - ```bash - curl -O $[filesUrl]/manifests/compliance-reporter-pod.yaml - ``` - - For managed clusters: - - ```bash - curl $[filesUrl]/manifests/compliance-reporter-pod-managed.yaml -o compliance-reporter-pod.yaml - ``` - -1. Edit the template as follows: - - Edit the pod name if required. - - If you are using your own docker repository, update the container image name with your repo and image tag. - - Set the following environments according to the instructions in the downloaded manifest: - - `TIGERA_COMPLIANCE_REPORT_NAME` - - `TIGERA_COMPLIANCE_REPORT_START_TIME` - - `TIGERA_COMPLIANCE_REPORT_END_TIME` -1. Apply the updated manifest, and query the status of the pod to ensure it completes. - Upon completion, the report is available in the $[prodname] web console. - - ```bash - # Apply the compliance report pod - kubectl apply -f compliance-reporter-pod.yaml - - # Query the status of the pod - kubectl get pod -n tigera-compliance - ``` - -:::note - -Manually-generated reports do not appear in GlobalReport status. - -::: - -## Additional resources - -- For details on configuring and scheduling reports, see [Global reports](../reference/resources/globalreport.mdx) -- For report field descriptions, see [Compliance reports](../reference/resources/compliance-reports/index.mdx) -- [CIS benchmarks](compliance-reports-cis.mdx) - -[parse-duration]: https://golang.org/pkg/time/#ParseDuration diff --git a/calico-enterprise/observability/get-started-cem.mdx b/calico-enterprise/observability/get-started-cem.mdx index 2910289ad2..5ca9a5357e 100644 --- a/calico-enterprise/observability/get-started-cem.mdx +++ b/calico-enterprise/observability/get-started-cem.mdx @@ -111,20 +111,6 @@ This page is where you switch views between clusters in the web console. When yo ![managed-clusters](/img/calico-enterprise/managed-clusters.png) -## Compliance Reports - -> From the left navbar, click **Compliance**. - -Compliance tools that rely on periodic snapshots, do not provide accurate assessments of Kubernetes workloads against your compliance standards. $[prodname] compliance dashboard and reports provide a complete inventory of regulated workloads, along with evidence of enforcement of network controls for these workloads. Additionally, audit reports are available to see changes to any network security controls. - -**Compliance reports** are based on archived flow logs and audit logs for all $[prodname] resources, and audit logs for Kubernetes resources in the Kubernetes API server. - -![cis-benchmark](/img/calico-enterprise/cis-benchmark.png) - -Using the filter, you can select report types. - -![compliance-filter](/img/calico-enterprise/compliance-filter.png) - ## Activity > From the left navbar, select **Activity**, **Timeline**. diff --git a/calico-enterprise/operations/cnx/roles-and-permissions.mdx b/calico-enterprise/operations/cnx/roles-and-permissions.mdx index 3e88e18a39..1c183ccad2 100644 --- a/calico-enterprise/operations/cnx/roles-and-permissions.mdx +++ b/calico-enterprise/operations/cnx/roles-and-permissions.mdx @@ -21,7 +21,6 @@ The [Calico Enterprise API server](../../reference/installation/api.mdx#apiserve | Features | RBAC controls for... | | ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Network policy | - Tiered policy, including AWS security groups and federated services.
- Kubernetes network policy (in default tier)
- $[prodname] network policies including namespaces
- Staged policy, policy recommendation, policy preview | -| Compliance | Report management, generation, export, and status. | | Visibility and troubleshooting | Elasticsearch logs: flow, audit, dns, intrusion detection, bgp | | Multi-cluster management | Management and managed clusters in single management plane. | @@ -47,5 +46,4 @@ For RBAC details on any given feature, see the feature. For example: - [Policy preview RBAC](../../network-policy/policy-impact-preview.mdx) - [Staged policy RBAC](../../network-policy/staged-network-policies.mdx) - [Elasticsearch logs RBAC](../../observability/elastic/rbac-elasticsearch.mdx) -- [Compliance reports RBAC](../../compliance/overview.mdx) - [Multi-cluster management RBAC](../../multicluster/set-up-multi-cluster-management/standard-install/create-a-management-cluster.mdx) diff --git a/calico-enterprise/operations/troubleshoot/troubleshooting.mdx b/calico-enterprise/operations/troubleshoot/troubleshooting.mdx index 31c9f17327..08bf914c5c 100644 --- a/calico-enterprise/operations/troubleshoot/troubleshooting.mdx +++ b/calico-enterprise/operations/troubleshoot/troubleshooting.mdx @@ -141,13 +141,6 @@ sysctl -w net.netfilter.nf_conntrack_max=1000000 echo "net.netfilter.nf_conntrack_max=1000000" >> /etc/sysctl.conf ``` -## Compliance report is not generating at expected time - -By design, reports are scheduled to generate 30 minutes after the specified end time. The reason for this is to allow a certain amount of -time to pass for all the relevant data within the specified start and end time to be fully processed and stored. This delay can be modified -by setting the `TIGERA_COMPLIANCE_JOB_START_DELAY` environment variable on the `compliance-controller` deployment to the -desired [Golang duration](https://godoc.org/time#Duration). - ## GlobalAlert reports error "Trying to create too many buckets" ``` diff --git a/calico-enterprise/reference/index.mdx b/calico-enterprise/reference/index.mdx index 3e2808cdc5..726992ad39 100644 --- a/calico-enterprise/reference/index.mdx +++ b/calico-enterprise/reference/index.mdx @@ -74,11 +74,6 @@ APIs, CLI, architecture and design, and FAQ. - - - - - @@ -87,7 +82,6 @@ APIs, CLI, architecture and design, and FAQ. - diff --git a/calico-enterprise/reference/installation/_api.mdx b/calico-enterprise/reference/installation/_api.mdx index 581bf232e7..943cd61444 100644 --- a/calico-enterprise/reference/installation/_api.mdx +++ b/calico-enterprise/reference/installation/_api.mdx @@ -14,7 +14,6 @@ Resource Types - [APIServer](#apiserver) - [ApplicationLayer](#applicationlayer) - [Authentication](#authentication) -- [Compliance](#compliance) - [EgressGateway](#egressgateway) - [GatewayAPI](#gatewayapi) - [Goldmane](#goldmane) @@ -1260,486 +1259,6 @@ _Appears in:_ | `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | Define resources requests and limits for single Pods. | -### Compliance - - - -Compliance installs the components required for Tigera compliance reporting. At most one instance -of this resource is supported. It must be named "tigera-secure". - -| Field | Description | -| --- | --- | -| `apiVersion` _string_ | `operator.tigera.io/v1` | -| `kind` _string_ | `Compliance` | -| `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | -| `spec` _[ComplianceSpec](#compliancespec)_ | Specification of the desired state for Tigera compliance reporting. | -| `status` _[ComplianceStatus](#compliancestatus)_ | Most recently observed state for Tigera compliance reporting. | - - -### ComplianceBenchmarkerDaemonSet - - - -ComplianceBenchmarkerDaemonSet is the configuration for the Compliance Benchmarker DaemonSet. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceBenchmarkerDaemonSetSpec](#compliancebenchmarkerdaemonsetspec)_ | (Optional) Spec is the specification of the Compliance Benchmarker DaemonSet. | - - -### ComplianceBenchmarkerDaemonSetContainer - - - -ComplianceBenchmarkerDaemonSetContainer is a Compliance Benchmarker DaemonSet container. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the Compliance Benchmarker DaemonSet container by name.
Supported values are: compliance-benchmarker | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named Compliance Benchmarker DaemonSet container's resources. If omitted, the Compliance Benchmarker DaemonSet will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceBenchmarkerDaemonSetInitContainer - - - -ComplianceBenchmarkerDaemonSetInitContainer is a Compliance Benchmarker DaemonSet init container. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the Compliance Benchmarker DaemonSet init container by name.
Supported values are: tigera-compliance-benchmarker-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named Compliance Benchmarker DaemonSet init container's resources. If omitted, the Compliance Benchmarker DaemonSet will use its default value for this init container's resources. | - - -### ComplianceBenchmarkerDaemonSetPodSpec - - - -ComplianceBenchmarkerDaemonSetPodSpec is the Compliance Benchmarker DaemonSet's PodSpec. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodTemplateSpec](#compliancebenchmarkerdaemonsetpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceBenchmarkerDaemonSetInitContainer](#compliancebenchmarkerdaemonsetinitcontainer) array_ | (Optional) InitContainers is a list of Compliance benchmark init containers. If specified, this overrides the specified Compliance Benchmarker DaemonSet init containers. If omitted, the Compliance Benchmarker DaemonSet will use its default values for its init containers. | -| `containers` _[ComplianceBenchmarkerDaemonSetContainer](#compliancebenchmarkerdaemonsetcontainer) array_ | (Optional) Containers is a list of Compliance benchmark containers. If specified, this overrides the specified Compliance Benchmarker DaemonSet containers. If omitted, the Compliance Benchmarker DaemonSet will use its default values for its containers. | - - -### ComplianceBenchmarkerDaemonSetPodTemplateSpec - - - -ComplianceBenchmarkerDaemonSetPodTemplateSpec is the Compliance Benchmarker DaemonSet's PodTemplateSpec - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetSpec](#compliancebenchmarkerdaemonsetspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec)_ | (Optional) Spec is the Compliance Benchmarker DaemonSet's PodSpec. | - - -### ComplianceBenchmarkerDaemonSetSpec - - - -ComplianceBenchmarkerDaemonSetSpec defines configuration for the Compliance Benchmarker DaemonSet. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSet](#compliancebenchmarkerdaemonset) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceBenchmarkerDaemonSetPodTemplateSpec](#compliancebenchmarkerdaemonsetpodtemplatespec)_ | (Optional) Template describes the Compliance Benchmarker DaemonSet pod that will be created. | - - -### ComplianceControllerDeployment - - - -ComplianceControllerDeployment is the configuration for the compliance controller Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceControllerDeploymentSpec](#compliancecontrollerdeploymentspec)_ | (Optional) Spec is the specification of the compliance controller Deployment. | - - -### ComplianceControllerDeploymentContainer - - - -ComplianceControllerDeploymentContainer is a compliance controller Deployment container. - -_Appears in:_ -- [ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance controller Deployment container by name.
Supported values are: compliance-controller | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance controller Deployment container's resources. If omitted, the compliance controller Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceControllerDeploymentInitContainer - - - -ComplianceControllerDeploymentInitContainer is a compliance controller Deployment init container. - -_Appears in:_ -- [ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance controller Deployment init container by name.
Supported values are: tigera-compliance-controller-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance controller Deployment init container's resources. If omitted, the compliance controller Deployment will use its default value for this init container's resources. | - - -### ComplianceControllerDeploymentPodSpec - - - -ComplianceControllerDeploymentPodSpec is the compliance controller Deployment's PodSpec. - -_Appears in:_ -- [ComplianceControllerDeploymentPodTemplateSpec](#compliancecontrollerdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceControllerDeploymentInitContainer](#compliancecontrollerdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of compliance controller init containers. If specified, this overrides the specified compliance controller Deployment init containers. If omitted, the compliance controller Deployment will use its default values for its init containers. | -| `containers` _[ComplianceControllerDeploymentContainer](#compliancecontrollerdeploymentcontainer) array_ | (Optional) Containers is a list of compliance controller containers. If specified, this overrides the specified compliance controller Deployment containers. If omitted, the compliance controller Deployment will use its default values for its containers. | - - -### ComplianceControllerDeploymentPodTemplateSpec - - - -ComplianceControllerDeploymentPodTemplateSpec is the compliance controller Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceControllerDeploymentSpec](#compliancecontrollerdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec)_ | (Optional) Spec is the compliance controller Deployment's PodSpec. | - - -### ComplianceControllerDeploymentSpec - - - -ComplianceControllerDeploymentSpec defines configuration for the compliance controller Deployment. - -_Appears in:_ -- [ComplianceControllerDeployment](#compliancecontrollerdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceControllerDeploymentPodTemplateSpec](#compliancecontrollerdeploymentpodtemplatespec)_ | (Optional) Template describes the compliance controller Deployment pod that will be created. | - - -### ComplianceReporterPodSpec - - - -ComplianceReporterPodSpec is the ComplianceReporter PodSpec. - -_Appears in:_ -- [ComplianceReporterPodTemplateSpec](#compliancereporterpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceReporterPodTemplateInitContainer](#compliancereporterpodtemplateinitcontainer) array_ | (Optional) InitContainers is a list of ComplianceReporter PodSpec init containers. If specified, this overrides the specified ComplianceReporter PodSpec init containers. If omitted, the ComplianceServer Deployment will use its default values for its init containers. | -| `containers` _[ComplianceReporterPodTemplateContainer](#compliancereporterpodtemplatecontainer) array_ | (Optional) Containers is a list of ComplianceServer containers. If specified, this overrides the specified ComplianceReporter PodSpec containers. If omitted, the ComplianceServer Deployment will use its default values for its containers. | - - -### ComplianceReporterPodTemplate - - - -ComplianceReporterPodTemplate is the configuration for the ComplianceReporter PodTemplate. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceReporterPodTemplateSpec](#compliancereporterpodtemplatespec)_ | (Optional) Spec is the specification of the ComplianceReporter PodTemplateSpec. | - - -### ComplianceReporterPodTemplateContainer - - - -ComplianceReporterPodTemplateContainer is a ComplianceServer Deployment container. - -_Appears in:_ -- [ComplianceReporterPodSpec](#compliancereporterpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment container by name.
Supported values are: reporter | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment container's resources. If omitted, the ComplianceServer Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceReporterPodTemplateInitContainer - - - -ComplianceReporterPodTemplateInitContainer is a ComplianceServer Deployment init container. - -_Appears in:_ -- [ComplianceReporterPodSpec](#compliancereporterpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceReporter PodSpec init container by name.
Supported values are: tigera-compliance-reporter-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceReporter PodSpec init container's resources. If omitted, the ComplianceServer Deployment will use its default value for this init container's resources. | - - -### ComplianceReporterPodTemplateSpec - - - -ComplianceReporterPodTemplateSpec is the ComplianceReporter PodTemplateSpec. - -_Appears in:_ -- [ComplianceReporterPodTemplate](#compliancereporterpodtemplate) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceReporterPodSpec](#compliancereporterpodspec)_ | (Optional) Spec is the ComplianceReporter PodTemplate's PodSpec. | - - -### ComplianceServerDeployment - - - -ComplianceServerDeployment is the configuration for the ComplianceServer Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceServerDeploymentSpec](#complianceserverdeploymentspec)_ | (Optional) Spec is the specification of the ComplianceServer Deployment. | - - -### ComplianceServerDeploymentContainer - - - -ComplianceServerDeploymentContainer is a ComplianceServer Deployment container. - -_Appears in:_ -- [ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment container by name.
Supported values are: compliance-server | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment container's resources. If omitted, the ComplianceServer Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceServerDeploymentInitContainer - - - -ComplianceServerDeploymentInitContainer is a ComplianceServer Deployment init container. - -_Appears in:_ -- [ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment init container by name.
Supported values are: tigera-compliance-server-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment init container's resources. If omitted, the ComplianceServer Deployment will use its default value for this init container's resources. | - - -### ComplianceServerDeploymentPodSpec - - - -ComplianceServerDeploymentPodSpec is the ComplianceServer Deployment's PodSpec. - -_Appears in:_ -- [ComplianceServerDeploymentPodTemplateSpec](#complianceserverdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceServerDeploymentInitContainer](#complianceserverdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of ComplianceServer init containers. If specified, this overrides the specified ComplianceServer Deployment init containers. If omitted, the ComplianceServer Deployment will use its default values for its init containers. | -| `containers` _[ComplianceServerDeploymentContainer](#complianceserverdeploymentcontainer) array_ | (Optional) Containers is a list of ComplianceServer containers. If specified, this overrides the specified ComplianceServer Deployment containers. If omitted, the ComplianceServer Deployment will use its default values for its containers. | - - -### ComplianceServerDeploymentPodTemplateSpec - - - -ComplianceServerDeploymentPodTemplateSpec is the ComplianceServer Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceServerDeploymentSpec](#complianceserverdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec)_ | (Optional) Spec is the ComplianceServer Deployment's PodSpec. | - - -### ComplianceServerDeploymentSpec - - - -ComplianceServerDeploymentSpec defines configuration for the ComplianceServer Deployment. - -_Appears in:_ -- [ComplianceServerDeployment](#complianceserverdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceServerDeploymentPodTemplateSpec](#complianceserverdeploymentpodtemplatespec)_ | (Optional) Template describes the ComplianceServer Deployment pod that will be created. | - - -### ComplianceSnapshotterDeployment - - - -ComplianceSnapshotterDeployment is the configuration for the compliance snapshotter Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceSnapshotterDeploymentSpec](#compliancesnapshotterdeploymentspec)_ | (Optional) Spec is the specification of the compliance snapshotter Deployment. | - - -### ComplianceSnapshotterDeploymentContainer - - - -ComplianceSnapshotterDeploymentContainer is a compliance snapshotter Deployment container. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance snapshotter Deployment container by name.
Supported values are: compliance-snapshotter | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance snapshotter Deployment container's resources. If omitted, the compliance snapshotter Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceSnapshotterDeploymentInitContainer - - - -ComplianceSnapshotterDeploymentInitContainer is a compliance snapshotter Deployment init container. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance snapshotter Deployment init container by name.
Supported values are: tigera-compliance-snapshotter-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance snapshotter Deployment init container's resources. If omitted, the compliance snapshotter Deployment will use its default value for this init container's resources. | - - -### ComplianceSnapshotterDeploymentPodSpec - - - -ComplianceSnapshotterDeploymentPodSpec is the compliance snapshotter Deployment's PodSpec. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodTemplateSpec](#compliancesnapshotterdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceSnapshotterDeploymentInitContainer](#compliancesnapshotterdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of compliance snapshotter init containers. If specified, this overrides the specified compliance snapshotter Deployment init containers. If omitted, the compliance snapshotter Deployment will use its default values for its init containers. | -| `containers` _[ComplianceSnapshotterDeploymentContainer](#compliancesnapshotterdeploymentcontainer) array_ | (Optional) Containers is a list of compliance snapshotter containers. If specified, this overrides the specified compliance snapshotter Deployment containers. If omitted, the compliance snapshotter Deployment will use its default values for its containers. | - - -### ComplianceSnapshotterDeploymentPodTemplateSpec - - - -ComplianceSnapshotterDeploymentPodTemplateSpec is the compliance snapshotter Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceSnapshotterDeploymentSpec](#compliancesnapshotterdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec)_ | (Optional) Spec is the compliance snapshotter Deployment's PodSpec. | - - -### ComplianceSnapshotterDeploymentSpec - - - -ComplianceSnapshotterDeploymentSpec defines configuration for the compliance snapshotter Deployment. - -_Appears in:_ -- [ComplianceSnapshotterDeployment](#compliancesnapshotterdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceSnapshotterDeploymentPodTemplateSpec](#compliancesnapshotterdeploymentpodtemplatespec)_ | (Optional) Template describes the compliance snapshotter Deployment pod that will be created. | - - -### ComplianceSpec - - - -ComplianceSpec defines the desired state of Tigera compliance reporting capabilities. - -_Appears in:_ -- [Compliance](#compliance) - -| Field | Description | -| --- | --- | -| `complianceControllerDeployment` _[ComplianceControllerDeployment](#compliancecontrollerdeployment)_ | (Optional) ComplianceControllerDeployment configures the Compliance Controller Deployment. | -| `complianceSnapshotterDeployment` _[ComplianceSnapshotterDeployment](#compliancesnapshotterdeployment)_ | (Optional) ComplianceSnapshotterDeployment configures the Compliance Snapshotter Deployment. | -| `complianceBenchmarkerDaemonSet` _[ComplianceBenchmarkerDaemonSet](#compliancebenchmarkerdaemonset)_ | (Optional) ComplianceBenchmarkerDaemonSet configures the Compliance Benchmarker DaemonSet. | -| `complianceServerDeployment` _[ComplianceServerDeployment](#complianceserverdeployment)_ | (Optional) ComplianceServerDeployment configures the Compliance Server Deployment. | -| `complianceReporterPodTemplate` _[ComplianceReporterPodTemplate](#compliancereporterpodtemplate)_ | (Optional) ComplianceReporterPodTemplate configures the Compliance Reporter PodTemplate. | - - -### ComplianceStatus - - - -ComplianceStatus defines the observed state of Tigera compliance reporting capabilities. - -_Appears in:_ -- [Compliance](#compliance) - -| Field | Description | -| --- | --- | -| `state` _string_ | State provides user-readable status. | -| `conditions` _[Condition](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#condition-v1-meta) array_ | (Optional) Conditions represents the latest observed set of conditions for the component. A component may be one or more of Ready, Progressing, Degraded or other customer types. | - - ### ComponentName _Underlying type:_ _string_ @@ -5644,11 +5163,6 @@ _Appears in:_ - [CalicoNodeWindowsDaemonSetContainer](#caliconodewindowsdaemonsetcontainer) - [CalicoWebhooksDeploymentContainer](#calicowebhooksdeploymentcontainer) - [CalicoWindowsUpgradeDaemonSetContainer](#calicowindowsupgradedaemonsetcontainer) -- [ComplianceBenchmarkerDaemonSetContainer](#compliancebenchmarkerdaemonsetcontainer) -- [ComplianceControllerDeploymentContainer](#compliancecontrollerdeploymentcontainer) -- [ComplianceReporterPodTemplateContainer](#compliancereporterpodtemplatecontainer) -- [ComplianceServerDeploymentContainer](#complianceserverdeploymentcontainer) -- [ComplianceSnapshotterDeploymentContainer](#compliancesnapshotterdeploymentcontainer) - [DashboardsJobContainer](#dashboardsjobcontainer) - [DexDeploymentContainer](#dexdeploymentcontainer) - [ECKOperatorStatefulSetContainer](#eckoperatorstatefulsetcontainer) diff --git a/calico-enterprise/reference/installation/_crd-ref-docs/config.yaml b/calico-enterprise/reference/installation/_crd-ref-docs/config.yaml index fd123b9c48..e7b0103bba 100644 --- a/calico-enterprise/reference/installation/_crd-ref-docs/config.yaml +++ b/calico-enterprise/reference/installation/_crd-ref-docs/config.yaml @@ -3,6 +3,7 @@ processor: ignoreTypes: - "List$" - "Tenant*" + - "^Compliance" # RE2 regular expressions describing type fields that should be excluded from the generated documentation. ignoreFields: - "TypeMeta$" diff --git a/calico-enterprise/reference/installation/helm_customization.mdx b/calico-enterprise/reference/installation/helm_customization.mdx index f9595a106e..92d4e6064f 100644 --- a/calico-enterprise/reference/installation/helm_customization.mdx +++ b/calico-enterprise/reference/installation/helm_customization.mdx @@ -8,7 +8,6 @@ You can customize the following resources and settings during $[prodname] Helm-b - [Installation](api.mdx#installationspec) - [Api server](api.mdx#apiserverspec) -- [Compliance](api.mdx#compliancespec) - [Intrusion detection](api.mdx#intrusiondetectionspec) - [Log collector](api.mdx#logcollectorspec) - [Log storage](api.mdx#logstoragespec) @@ -63,10 +62,6 @@ monitor: enabled: true -compliance: - enabled: true - - policyRecommendation: enabled: true @@ -120,8 +115,6 @@ You can define pod affinity for the following Tigera components. Update the appr - calico-apiserver: through ApiServer resource - calico-nodes: through CalicoNodeDaemonSet property in the Installation resource - calico-kube-controllers: through CalicoKubeControllersDeployment property in the Installation resource -- compliance deployment pods (compliance-snapshotter, compliance-server, compliance-controller, compliance-benchmarker, -compliance-scaleloader, compliance-reporter): through Compliance resource - elasticsearch pods: through LogStorage resource - for more info on this option please checkout [Advanced Node Scheduling](../../operations/logstorage/advanced-node-scheduling.mdx) ### Encryption using WireGuard diff --git a/calico-enterprise/reference/installation/tigerastatus.mdx b/calico-enterprise/reference/installation/tigerastatus.mdx index cf68a274d2..aaef840282 100644 --- a/calico-enterprise/reference/installation/tigerastatus.mdx +++ b/calico-enterprise/reference/installation/tigerastatus.mdx @@ -11,7 +11,6 @@ Installing $[prodname] on your Kubernetes cluster is managed by the Tigera Opera - authentication - calico - calico-windows -- compliance - egressgateway - intrusion detection - log-collector @@ -40,7 +39,7 @@ For detailed output (including messages and further details on any non-functioni ## Log storage -Log storage provides persistent storage for $[prodname] Elasticsearch logs (flow, dns, l7, bgp, audit, etc.), and compliance reports. +Log storage provides persistent storage for $[prodname] Elasticsearch logs (flow, dns, l7, bgp, audit, etc.). To check log storage status, run the following command: diff --git a/calico-enterprise/reference/resources/compliance-reports/cis-benchmark.mdx b/calico-enterprise/reference/resources/compliance-reports/cis-benchmark.mdx deleted file mode 100644 index 92184ddb25..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/cis-benchmark.mdx +++ /dev/null @@ -1,71 +0,0 @@ ---- -description: Reference for the CIS benchmark compliance report in Calico Enterprise that audits Kubernetes nodes against CIS recommendations. ---- - -# CIS benchmark report - -To create a CIS benchmark report, create a `GlobalReport` with the `reportType` set to `cis-benchmark`. - -The following sample command uses a GlobalReport to create a daily CIS benchmark report that run on all the nodes. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-benchmark-report -spec: - reportType: cis-benchmark - schedule: 0 0 * * * -EOF -``` - -## OpenShift - -While there is no extra setup configuration required by the user to generate a benchmark report for OpenShift, the result sets will be different than a report generated for regular Kubernetes clusters. Use the [OpenShift Container Platform Security Guide](https://static.open-scap.org/ssg-guides/ssg-ocp4-guide-index.html) to cross-reference the benchmark results. - -## Downloadable reports - -## total-summary.csv - -A textual representation of the dashboard. - -| Heading | Description | Format | -| ---------------------- | ----------------------------------------------------------------- | -------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval start time. | RFC3339 string | -| type | The type of benchmark report | string | -| hiPercentageThreshold | The percentage of passing tests required to rate a node as high | int | -| medPercentageThreshold | The percentage of passing tests required to rate a node as medium | int | -| hiNodeCount | The number of nodes rated as high | int | -| medNodeCount | The number of nodes rated as medium | int | -| lowNodeCount | The number of nodes rated as low | int | - -## node-summary.csv - -A .csv file of test result summaries per node. - -| Heading | Description | Format | -| ------------ | ---------------------------------------------------------------------------------- | ------ | -| node | The name of the node. | string | -| version | The version of the platform. | string | -| status | The rating of the node based on percentage of tests passing. | string | -| testsPassing | The number of tests passing. | int | -| testsFailing | The number of tests failing. | int | -| testsUnknown | The number of tests whose results are undetermined due to automation restrictions. | int | -| testsTotal | The total number of tests executed. | int | - -### failed-tests.csv - -A .csv file of tests that have failed. - -| Heading | Description | Format | -| --------- | -------------------------------------------------------------------------------------- | ------ | -| nodeName | Node where the test is executed. | string | -| testIndex | Index of the test on the Kubernetes CIS benchmark. | string | -| status | Test results: PASS, FAIL, INFO. | string | -| scored | Indicates whether the Kubernetes CIS benchmark counts this test towards their scoring. | string | - -### all-tests.csv - -A .csv file with tests that were executed on all nodes. Format remains the same as above. diff --git a/calico-enterprise/reference/resources/compliance-reports/index.mdx b/calico-enterprise/reference/resources/compliance-reports/index.mdx deleted file mode 100644 index deb390a14f..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/index.mdx +++ /dev/null @@ -1,11 +0,0 @@ ---- -description: Reference index for compliance report types available with Calico Enterprise covering inventory, network access, policy audit, and CIS benchmark. -hide_table_of_contents: true ---- - -# Compliance reports (deprecated) - -import DocCardList from '@theme/DocCardList'; -import { useCurrentSidebarCategory } from '@docusaurus/theme-common'; - - diff --git a/calico-enterprise/reference/resources/compliance-reports/inventory.mdx b/calico-enterprise/reference/resources/compliance-reports/inventory.mdx deleted file mode 100644 index 4e2585393d..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/inventory.mdx +++ /dev/null @@ -1,86 +0,0 @@ ---- -description: Reference for the inventory compliance report in Calico Enterprise that catalogs endpoints, namespaces, and policies in scope at report time. ---- - -# Inventory report - -To create an Inventory report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `inventory`. - -The following sample command creates a GlobalReport that results in a daily inventory report for -endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-inventory-report - labels: - deployment: production -spec: - reportType: inventory - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ----------------------------- | ----------------------------------------------------------------------------------------------------------- | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| endpointsNumInScope | The number of enumerated endpoints that are in-scope according to the requested endpoint selection options. | number | -| endpointsNumIngressProtected | The number of in-scope endpoints that were always ingress protected during the report interval. | number | -| endpointsNumEgressProtected | The number of in-scope endpoints that were always egress protected during the report interval. | number | -| namespacesNumInScope | The number of namespaces containing in-scope endpoints. | number | -| namespacesNumIngressProtected | The number of namespaces whose in-scope endpoints were always ingress protected during the report interval. | number | -| namespacesNumEgressProtected | The number of namespaces whose in-scope endpoints were always egress protected during the report interval. | number | -| serviceAccountsNumInScope | The number of service accounts associated with in-scope endpoints. | number | - -### endpoints.csv - -An endpoints CSV file that includes per-endpoint information. - -| Heading | Description | Format | -| ---------------- | --------------------------------------------------------------------------------------------- | ----------------------------------- | -| endpoint | The name of the endpoint. | string | -| ingressProtected | Whether the endpoint was always ingress protected during the report interval. | bool | -| egressProtected | Whether the endpoint was always egress protected during the report interval. | bool | -| envoyEnabled | Whether the endpoint was always Envoy enabled during the report interval. | bool | -| appliedPolicies | The full set of policies that applied to the endpoint at any time during the report interval. | ";" separated list of policy names | -| services | The full set of services that included this endpoint at any time during the report interval. | ";" separated list of service names | - -### namespaces.csv - -A namespaces CSV file that includes per-namespace information. - -| Heading | Description | Format | -| ---------------- | ------------------------------------------------------------------------------------------------------------- | ------ | -| namespace | The name of the namespace. | string | -| ingressProtected | Whether all in-scope endpoints within the namespace were always ingress protected during the report interval. | bool | -| egressProtected | Whether all in-scope endpoints within the namespace were always egress protected during the report interval. | bool | -| envoyEnabled | Whether all in-scope endpoints within the namespace were always Envoy enabled during the report interval. | bool | - -### services.csv - -A services CSV file that includes per-service information. - -| Heading | Description | Format | -| ---------------- | ---------------------------------------------------------------------------------------------------------------- | ------ | -| service | The name of the service. | string | -| ingressProtected | Whether all in-scope endpoints that are in the service were always ingress protected during the report interval. | bool | -| envoyEnabled | Whether all in-scope endpoints that are in the service were always Envoy enabled during the report interval. | bool | diff --git a/calico-enterprise/reference/resources/compliance-reports/network-access.mdx b/calico-enterprise/reference/resources/compliance-reports/network-access.mdx deleted file mode 100644 index e01798e591..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/network-access.mdx +++ /dev/null @@ -1,92 +0,0 @@ ---- -description: Reference for the network access compliance report in Calico Enterprise that summarizes which endpoints could communicate based on policy. ---- - -# Network Access report - -To create an Inventory report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `network-access`. - -The following sample command creates a GlobalReport that results in a daily network access report for -endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-network-access-report - labels: - deployment: production -spec: - reportType: network-access - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -:::note - -There is a known issue that audit logs do not contain deletion events for resources that were -deleted implicitly as part of a namespace deletion event. Currently, this means policies and pods that have been -deleted in this way may still appear in the reports that cover any period within the next day. - -::: - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| endpointsNumIngressProtected | The number of in-scope endpoints that were always ingress protected during the report interval. | number | -| endpointsNumEgressProtected | The number of in-scope endpoints that were always egress protected during the report interval. | number | -| endpointsNumIngressUnprotected | The number of in-scope endpoints that were ingress unprotected at any point during the report interval. | number | -| endpointsNumEgressUnprotected | The number of in-scope endpoints that were egress unprotected at any point during the report interval. | number | -| endpointsNumIngressFromInternet | The number of in-scope endpoints that allowed ingress traffic from the public internet at any point during the report interval. | number | -| endpointsNumEgressToInternet | The number of in-scope endpoints that allowed egress traffic to the public internet at any point during the report interval. | number | -| endpointsNumIngressFromOtherNamespace | The number of in-scope endpoints that allowed ingress traffic from another namespace at any point during the report interval. | number | -| endpointsNumEgressToOtherNamespace | The number of in-scope endpoints that allowed egress traffic to another namespace at any point during the report interval. | number | -| endpointsNumEnvoyEnabled | The number of in-scope endpoints that were always Envoy enabled during the report interval. | number | - -### endpoints.csv - -An endpoints CSV file that includes per-endpoint information. - -| Heading | Description | Format | -| ------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------- | -| endpoint | The name of the endpoint. | string | -| ingressProtected | Whether the endpoint was always ingress protected during the report interval. | bool | -| egressProtected | Whether the endpoint was always egress protected during the report interval. | bool | -| ingressFromInternet | Whether the endpoint allowed ingress traffic from the public internet at any point during the report interval. | number | -| egressToInternet | Whether the endpoint allowed egress traffic to the public internet at any point during the report interval. | number | -| ingressFromOtherNamespace | Whether the endpoint allowed ingress traffic from another namespace at any point during the report interval. | number | -| egressToOtherNamespace | Whether the endpoint allowed egress traffic to another namespace at any point during the report interval. | number | -| envoyEnabled | Whether the endpoint was always Envoy enabled during the report interval. | bool | -| appliedPolicies | The full set of policies that applied to the endpoint at any time during the report interval. | ";" separated list of policy names | -| services | The full set of services that included this endpoint at any time during the report interval. | ";" separated list of service names | -| trafficAggregationPrefix\* | The flow log aggregation prefix. | string | -| endpointsGeneratingTrafficToThisEndpoint\* | The set of endpoints that were generating traffic to this endpoint. | ";" separated list of service names | -| endpointsReceivingTrafficFromThisEndpoint\* | The set of endpoints that this endpoint is generating traffic to. | ";" separated list of service names | - -\* Traffic data is determined from flow logs. By default, $[prodname] aggregates flow logs so that flows to -and from pods in the same replica set are summarized if the flows are accepted. (Denied flows are not aggregated this -way by default). This means that the per-endpoint traffic details do not refer specifically to that endpoint, but -rather the set of endpoints specified by the trafficAggregationPrefix. - -If you want per-endpoint detail you should turn down the level of aggregation. To do so, -set the value of `flowLogsFileAggregationKindForAllowed` to 1 using a [FelixConfiguration][felixconfig] - -[felixconfig]: ../felixconfig.mdx diff --git a/calico-enterprise/reference/resources/compliance-reports/overview.mdx b/calico-enterprise/reference/resources/compliance-reports/overview.mdx deleted file mode 100644 index ec0cafe0e5..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/overview.mdx +++ /dev/null @@ -1,102 +0,0 @@ ---- -description: Reference overview of compliance reporting in Calico Enterprise covering schedules, report scope, and the GlobalReport resource. ---- - -# Compliance reports (deprecated) - -The $[prodname] compliance reporting feature provides the following compliance reports: - -- [Inventory](inventory.mdx) -- [Network Access](network-access.mdx) -- [Policy Audit](policy-audit.mdx) -- [CIS Benchmark](cis-benchmark.mdx) - -Create a [`GlobalReport`](../globalreport.mdx) resource to automatically schedule report generation, and specify the report scope (resources to include in the report). - -## Concepts - -### In-scope asset - -An asset (Pod or HostEndpoint) is flagged as in-scope by endpoint labels, namespace and/or namespace labels, and service -account and/or service account labels. - -_How this applies to the report_: -The report includes all resources that were in-scope at any point during the report interval. The resource is included -when it is first flagged as in-scope according to the configured label selector and name selections. The resource is -included even if the resource is deleted or goes out-of-scope before the end of the report interval. - -### Ingress protected - -An endpoint is ingress protected if it has at least one Ingress policy that is applied to it. - -A service is ingress protected if all of the in-scope endpoints within that service are ingress protected. - -A namespace is ingress protected if all of the in-scope endpoints within that namespace are ingress protected. - -_How this applies to the report_: -An endpoint is ingress protected only if it was ingress protected throughout the entire report interval. - -### Egress protected - -As per ingress, but with egress policy rules. Note that egress statistics are not obtained for services. - -### Allows ingress traffic from another namespace - -An endpoint is flagged as allowing ingress traffic from another namespace if it has one or more policies that apply to -it with an ingress allow rule that: - -- has an explicit namespace selector configured, or -- has no source selector or source CIDR configured, or -- (for GlobalNetworkPolicy) has no source CIDR. - -A service is flagged as allowing ingress traffic from another namespace if any of the in-scope endpoints within that -service are flagged. - -A namespace is flagged as allowing ingress traffic from another namespace if all of the in-scope endpoints within that -namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as allowing ingress traffic from another namespace if it was flagged at any time during the -report interval. - -### Allows egress traffic to another namespace - -As per ingress, but with egress policy rules and destination selector/CIDR. Note that egress statistics are not obtained -for services. - -### Allows ingress traffic from the internet - -An endpoint is flagged as allowing ingress traffic from the internet if it has one or more policies that apply to it -with an ingress allow rule that: - -- has no source selector or source CIDR configured, or -- has a source CIDR in the non-private IP ranges and has no source selector, or -- has a source selector that matches one or more NetworkSets that contain at least one non-private IP. - -A service is flagged as allowing ingress traffic from the internet if any of the in-scope endpoints within that service -are flagged. - -A namespace is flagged as allowing ingress traffic from the internet if all of the in-scope endpoints within that -namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as allowing ingress traffic from the internet if it was flagged as such at any time during the -report interval. - -### Allows egress traffic to the internet - -As per ingress, but with egress policy rules and destination selector/CIDR. Note that egress statistics are not obtained -for services. - -### Envoy enabled - -An endpoint is flagged as Envoy Enabled if the associated Pod Spec and Annotations indicate that an Istio init and main -container are deployed in the Pod. Provided Istio is appropriately configured on the cluster, this can be extrapolated -to be indication of whether mTLS is enabled for the endpoint. - -A service is flagged as Envoy enabled if all of the in-scope endpoints within that service are flagged. - -A namespace is flagged as Envoy enabled if all of the in-scope endpoints within that namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as Envoy enabled if it was flagged as such throughout the entire report interval. diff --git a/calico-enterprise/reference/resources/compliance-reports/policy-audit.mdx b/calico-enterprise/reference/resources/compliance-reports/policy-audit.mdx deleted file mode 100644 index 67d19a5b84..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/policy-audit.mdx +++ /dev/null @@ -1,56 +0,0 @@ ---- -description: Reference for the policy audit compliance report in Calico Enterprise that records changes to network policies during the report period. ---- - -# Policy audit report - -To create a Policy Audit report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `policy-audit`. - -The following sample command creates a GlobalReport that results in a daily policy audit report for -policies that are applied to endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-policy-audit-report - labels: - deployment: production -spec: - reportType: policy-audit - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ----------------------- | ------------------------------------------------------------------------------------------------------ | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| numCreatedPolicies | The number of policies that apply to in-scope endpoints that were created during the report interval. | number | -| numModifiedPolicies | The number of policies that apply to in-scope endpoints that were modified during the report interval. | number | -| numDeletedPolicies | The number of policies that apply to in-scope endpoints that were deleted during the report interval. | number | - -### events.json - -Events formatted in JSON. - -### events.yaml - -Events formatted in YAML. diff --git a/calico-enterprise/reference/resources/globalreport.mdx b/calico-enterprise/reference/resources/globalreport.mdx deleted file mode 100644 index 16e2c70171..0000000000 --- a/calico-enterprise/reference/resources/globalreport.mdx +++ /dev/null @@ -1,149 +0,0 @@ ---- -description: Reference for the GlobalReport resource in Calico Enterprise that schedules compliance reports against cluster network and policy state. ---- - -# Global report - -A global report resource is a configuration for generating compliance reports. A global report configuration in $[prodname] lets you: - -- Specify report contents, frequency, and data filtering -- Specify the node(s) on which to run the report generation jobs -- Enable/disable creation of new jobs for generating the report - -For `kubectl` [commands](https://kubernetes.io/docs/reference/kubectl/overview/), the following case-insensitive aliases -may be used to specify the resource type on the CLI: -`globalreport.projectcalico.org`, `globalreports.projectcalico.org` and abbreviations such as -`globalreport.p` and `globalreports.p`. - -## Sample YAML - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: weekly-full-inventory -spec: - reportType: inventory - schedule: 0 0 * * 0 - jobNodeSelector: - nodetype: infrastructure - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: hourly-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - names: ['payable', 'collections', 'payroll'] - schedule: 0 * * * * - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: monthly-widgets-controller-tigera-policy-audit -spec: - reportType: policy-audit - schedule: 0 0 1 * * - endpoints: - serviceAccounts: - names: ['controller'] - namespaces: - names: ['widgets'] - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-benchmark -spec: - reportType: cis-benchmark - schedule: 0 0 * * * - cis: - resultsFilters: - - benchmarkSelection: { kubernetesVersion: '1.13' } - exclude: ['1.1.4', '1.2.5'] -``` - -## GlobalReport Definition - -### Metadata - -| Field | Description | Accepted Values | Schema | -| ------ | ---------------------------------------- | ------------------------------------------------ | ------ | -| name | The name of this report. | Lower-case alphanumeric with optional `-` or `.` | string | -| labels | A set of labels to apply to this report. | | map | - -### Spec - -| Field | Description | Required | Accepted Values | Schema | -| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------- | -| reportType | The type of report to produce. This field controls the content of the report - see the links for each type for more details. | Yes | [cis‑benchmark](compliance-reports/cis-benchmark.mdx), [inventory](compliance-reports/inventory.mdx), [network‑access](compliance-reports/network-access.mdx), [policy‑audit](compliance-reports/policy-audit.mdx) | string | -| endpoints | Specify which endpoints are in scope. If omitted, selects everything. | | | [EndpointsSelection](#endpointsselection) | -| schedule | Configure report frequency by specifying start and end time in [cron-format][cron-format]. Reports are started 30 minutes (configurable) after the scheduled value to allow enough time for data archival. A maximum limit of 12 schedules per hour is enforced (an average of one report every 5 minutes). | Yes | | string | -| jobNodeSelector | Specify the node(s) for scheduling the report jobs using selectors. | | | map | -| suspend | Disable future scheduled report jobs. In-flight reports are not affected. | | | bool | -| cis | Parameters related to generating a CIS benchmark report. | | | [CISBenchmarkParams](#cisbenchmarkparams) | - -### EndpointsSelection - -| Field | Description | Schema | -| --------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------- | -| selector | Endpoint label selector to restrict endpoint selection. | string | -| namespaces | Namespace name and label selector to restrict endpoints by selected namespaces. | [NamesAndLabelsMatch](#namesandlabelsmatch) | -| serviceAccounts | Service account name and label selector to restrict endpoints by selected service accounts. | [NamesAndLabelsMatch](#namesandlabelsmatch) | - -### CISBenchmarkParams - -| Fields | Description | Required | Schema | -| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----------------------------------------- | -| highThreshold | Integer percentage value that determines the lower limit of passing tests to consider a node as healthy. Default: 100 | No | int | -| medThreshold | Integer percentage value that determines the lower limit of passing tests to consider a node as unhealthy. Default: 50 | No | int | -| includeUnscoredTests | Boolean value that when false, applies a filter to exclude tests that are marked as “Unscored” by the CIS benchmark standard. If true, the tests will be included in the report. Default: false | No | bool | -| numFailedTests | Integer value that sets the number of tests to display in the Top-failed Tests section of the CIS benchmark report. Default: 5 | No | int | -| resultsFilters | Specifies an include or exclude filter to apply on the test results that will appear on the report. | No | [CISBenchmarkFilter](#cisbenchmarkfilter) | - -### CISBenchmarkFilter - -| Fields | Description | Required | Schema | -| ------------------ | ---------------------------------------------------------------------------------------------- | -------- | ----------------------------------------------- | -| benchmarkSelection | Specify which set of benchmarks that this filter should apply to. Selects all benchmark types. | No | [CISBenchmarkSelection](#cisbenchmarkselection) | -| exclude | Specify which benchmark tests to exclude | No | array of strings | -| include | Specify which benchmark tests to include only (higher precedence than exclude) | No | array of strings | - -### CISBenchmarkSelection - -| Fields | Description | Required | Schema | -| ----------------- | -------------------------------------- | -------- | ------ | -| kubernetesVersion | Specifies a version of the benchmarks. | Yes | string | - -### NamesAndLabelsMatch - -| Field | Description | Schema | -| -------- | ------------------------------------ | ------ | -| names | Set of resource names. | list | -| selector | Selects a set of resources by label. | string | - -Use the `NamesAndLabelsMatch`to limit the scope of endpoints. If both `names` -and `selector` are specified, the resource is identified using label _AND_ name -match. - -:::note - -To use the $[prodname] compliance reporting feature, you must ensure all required resource types -are being audited and the logs archived in Elasticsearch. You must explicitly configure the [Kubernetes API Server](../../observability/kube-audit.mdx) - to send audit logs for Kubernetes-owned resources -to Elasticsearch. - -::: - -## Supported operations - -| Datastore type | Create/Delete | Update | Get/List | Notes | -| --------------------- | ------------- | ------ | -------- | ----- | -| Kubernetes API server | Yes | Yes | Yes | | - -[cron-format]: https://en.wikipedia.org/wiki/Cron diff --git a/calico-enterprise/reference/resources/overview.mdx b/calico-enterprise/reference/resources/overview.mdx index a70cdfda35..69e8943535 100644 --- a/calico-enterprise/reference/resources/overview.mdx +++ b/calico-enterprise/reference/resources/overview.mdx @@ -54,7 +54,6 @@ The following resources are supported: - [GlobalAlert](globalalert.mdx) - [GlobalNetworkPolicy](globalnetworkpolicy.mdx) - [GlobalNetworkSet](globalnetworkset.mdx) -- [GlobalReport](globalreport.mdx) - [GlobalThreatFeed](globalthreatfeed.mdx) - [HostEndpoint](hostendpoint.mdx) - [IPPool](ippool.mdx) diff --git a/calico-enterprise/release-notes/index.mdx b/calico-enterprise/release-notes/index.mdx index a4501972fc..cb984e245a 100644 --- a/calico-enterprise/release-notes/index.mdx +++ b/calico-enterprise/release-notes/index.mdx @@ -28,6 +28,7 @@ This version of Calico Enterprise is based on [Calico Open Source $[openSourceVe ### Deprecated and removed features +- The compliance reporting feature has been removed from the $[prodname] web console. - $[prodname] is moving the `projectcalico.org/v3` API from the aggregated API server to native Kubernetes CRDs. Both mechanisms will be supported until native v3 CRDs are compatible with all supported platforms, after which the aggregated API server will be removed. ## Technology Preview features @@ -46,7 +47,7 @@ Merged gateways (`mergeGateways: true`) are no longer supported, so each gateway Migrate in this order: -1. **Before you upgrade**, if you run a global default deny policy, create a network policy in each Gateway's namespace that allows the proxy pods, so they can start as soon as they move. For the policy, see [Create an ingress gateway](../networking/ingress-gateway/create-ingress-gateway.mdx). +1. Before you upgrade, if you run a global default deny policy, create a network policy in each Gateway's namespace that allows the proxy pods, so they can start as soon as they move. For the policy, see [Create an ingress gateway](../networking/ingress-gateway/create-ingress-gateway.mdx). 2. Upgrade $[prodname]. 3. After the upgrade, re-point monitoring, RBAC, and external DNS from `tigera-gateway` to each Gateway's namespace. If you used merged gateways, plan for one load balancer, DNS record, and certificate per gateway. diff --git a/calico-enterprise_versioned_docs/version-3.20-2/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.20-2/compliance/compliance-reports-cis.mdx index afb915b1c0..dc965fbe54 100644 --- a/calico-enterprise_versioned_docs/version-3.20-2/compliance/compliance-reports-cis.mdx +++ b/calico-enterprise_versioned_docs/version-3.20-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure reports to assess compliance for all assets in a Kubernet :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.20-2/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.20-2/compliance/enable-compliance.mdx index 462ccdcad2..be8f5f9850 100644 --- a/calico-enterprise_versioned_docs/version-3.20-2/compliance/enable-compliance.mdx +++ b/calico-enterprise_versioned_docs/version-3.20-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Enable compliance reports to configure reports to assess compliance :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.20-2/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.20-2/compliance/overview.mdx index 51a89b42d1..a3c3cdc389 100644 --- a/calico-enterprise_versioned_docs/version-3.20-2/compliance/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.20-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Get the reports for regulatory compliance on Kubernetes workloads a :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.20-2/release-notes/index.mdx b/calico-enterprise_versioned_docs/version-3.20-2/release-notes/index.mdx index 1a153ea0a4..da21b944be 100644 --- a/calico-enterprise_versioned_docs/version-3.20-2/release-notes/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.20-2/release-notes/index.mdx @@ -78,7 +78,6 @@ For more information, see [Packet capture](../observability/packetcapture.mdx), ## Deprecated and removed features * All compliance reporting features are deprecated and will be removed in a future release. - We're building a new compliance reporting system that will eventually replace the current one. * The honeypods feature has been removed from this release. ## Bug fixes diff --git a/calico-enterprise_versioned_docs/version-3.21-2/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.21-2/compliance/compliance-reports-cis.mdx index afb915b1c0..dc965fbe54 100644 --- a/calico-enterprise_versioned_docs/version-3.21-2/compliance/compliance-reports-cis.mdx +++ b/calico-enterprise_versioned_docs/version-3.21-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure reports to assess compliance for all assets in a Kubernet :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.21-2/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.21-2/compliance/enable-compliance.mdx index 462ccdcad2..be8f5f9850 100644 --- a/calico-enterprise_versioned_docs/version-3.21-2/compliance/enable-compliance.mdx +++ b/calico-enterprise_versioned_docs/version-3.21-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Enable compliance reports to configure reports to assess compliance :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.21-2/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.21-2/compliance/overview.mdx index 51a89b42d1..a3c3cdc389 100644 --- a/calico-enterprise_versioned_docs/version-3.21-2/compliance/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.21-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Get the reports for regulatory compliance on Kubernetes workloads a :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.22-2/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.22-2/compliance/compliance-reports-cis.mdx index dd3258e609..b7f30715ce 100644 --- a/calico-enterprise_versioned_docs/version-3.22-2/compliance/compliance-reports-cis.mdx +++ b/calico-enterprise_versioned_docs/version-3.22-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports in Calico Enterprise to :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.22-2/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.22-2/compliance/enable-compliance.mdx index 8c60a2c317..8033d59188 100644 --- a/calico-enterprise_versioned_docs/version-3.22-2/compliance/enable-compliance.mdx +++ b/calico-enterprise_versioned_docs/version-3.22-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Turn on the in-cluster compliance reporter, controller, snapshotter :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.22-2/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.22-2/compliance/overview.mdx index 1e4ac16448..76f4abdc46 100644 --- a/calico-enterprise_versioned_docs/version-3.22-2/compliance/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.22-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Enterprise compliance reports against Kuber :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.23-2/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.23-2/compliance/compliance-reports-cis.mdx index dd3258e609..b7f30715ce 100644 --- a/calico-enterprise_versioned_docs/version-3.23-2/compliance/compliance-reports-cis.mdx +++ b/calico-enterprise_versioned_docs/version-3.23-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports in Calico Enterprise to :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.23-2/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.23-2/compliance/enable-compliance.mdx index 8c60a2c317..8033d59188 100644 --- a/calico-enterprise_versioned_docs/version-3.23-2/compliance/enable-compliance.mdx +++ b/calico-enterprise_versioned_docs/version-3.23-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Turn on the in-cluster compliance reporter, controller, snapshotter :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.23-2/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.23-2/compliance/overview.mdx index 1e4ac16448..76f4abdc46 100644 --- a/calico-enterprise_versioned_docs/version-3.23-2/compliance/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.23-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Enterprise compliance reports against Kuber :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.24-1/about/calico-product-editions.mdx b/calico-enterprise_versioned_docs/version-3.24-1/about/calico-product-editions.mdx index 4808160a01..3ec34cedf4 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/about/calico-product-editions.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/about/calico-product-editions.mdx @@ -62,7 +62,6 @@ import { CalicoProducts } from '/src/___new___/components'; | Deep packet inspection | | | | | | DDoS protection | | | | | | Workload-centric WAF | | | | | -| Compliance reporting and alerts | | | | | | SIEM integrations | | | | | | **Network Security for VMs and Bare Metal** | | | | | | Restrict traffic to/from hosts and VMs using network policy | | | | | diff --git a/calico-enterprise_versioned_docs/version-3.24-1/about/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/about/index.mdx index 414d02dc93..dfcee21ecb 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/about/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/about/index.mdx @@ -190,7 +190,6 @@ All of this is built on Calico Open Source, the most widely used container netwo | Deep packet inspection | | | | | | DDoS protection | | | | | | Workload-centric WAF | | | | | -| Compliance reporting and alerts | | | | | | SIEM integrations | | | | | | **Network Security for VMs and Bare Metal** | | | | | | Restrict traffic to/from hosts and VMs using network policy | | | | | diff --git a/calico-enterprise_versioned_docs/version-3.24-1/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.24-1/compliance/compliance-reports-cis.mdx deleted file mode 100644 index dd3258e609..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/compliance/compliance-reports-cis.mdx +++ /dev/null @@ -1,199 +0,0 @@ ---- -description: Configure CIS Kubernetes benchmark reports in Calico Enterprise to assess node and cluster compliance and download results from the in-cluster reporter as CSV. ---- - -# Configure CIS benchmark reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Use the $[prodname] Kubernetes CIS benchmark report to assess compliance for all assets in a Kubernetes cluster. - -## Value - -A standard requirement for an organization’s security and compliance posture is to assess your Kubernetes clusters against CIS benchmarks. The $[prodname] Kubernetes CIS benchmark report provides this comprehensive view into your Kubernetes clusters while strengthening your threat detection capability by looking beyond networking data. - -## Concepts - -### Default settings and configuration - -During $[prodname] installation, each node starts a pod named, `compliance-benchmarker`. A preconfigured Kubernetes CIS benchmark report is generated every hour. You can view the report in **Compliance**, **Compliance Reports**, download it to .csv format. - -To schedule the CIS benchmark report or change settings, use the **global report** resource. Global reports are configured as YAML files and are applied using `kubectl`. - -### Best practices - -We recommend that you review the CIS benchmark best practices for securing cluster component configurations here: [CIS benchmarks downloads](https://learn.cisecurity.org/benchmarks). - -## Before you begin - -**Required** - -* You [Enabled compliance reports](../compliance/enable-compliance) - -**Limitations** - -CIS benchmarks runs only on nodes where $[prodname] is running. This limitation may exclude control plane nodes in some managed cloud platforms (AKS, EKS, GKE). Because the user has limited control over installation of control plane nodes in managed cloud platforms, these reports may have limited use for cloud users. - -## How to - -- [Configure and schedule CIS benchmark reports](#configure-and-schedule-cis-benchmark-reports) -- [View report generation status](#view-report-generation-status) -- [Review and address CIS benchmark results](#review-and-address-cis-benchmark-results) -- [Manually run reports](#manually-run-reports) -- [Troubleshooting](#troubleshooting) - -### Configure and schedule CIS benchmark reports - -Verify that the `compliance-benchmarker` is running and the `cis-benchmark` report type is installed. - -```bash -kubectl get -n tigera-compliance daemonset compliance-benchmarker -kubectl get globalreporttype cis-benchmark -``` - -In the following example, we use a **GlobalReport** with CIS benchmark fields to schedule and filter results. The report is scheduled to run at midnight of the next day (in UTC), and the benchmark items 1.1.4 and 1.2.5 will be omitted from the results. - -| **Fields** | **Description** | -| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| schedule | The start and end time of the report using [crontab format](https://en.wikipedia.org/wiki/Cron). To allow for archiving, reports are generated approximately 30 minutes after the end time. A single report is limited to a maximum of two per hour. | -| highThreshold | **Optional**. Integer percentage value that determines the lower limit of passing tests to consider a node as healthy. Default: 100 | -| medThreshold | **Optional**. Integer percentage value that determines the lower limit of passing tests to consider a node as unhealthy. Default: 50 | -| includeUnscoredTests | **Optional**. Boolean value that when false, applies a filter to exclude tests that are marked as “Unscored” by the CIS benchmark standard. If true, the tests will be included in the report. Default: true | -| numFailedTests | **Optional**. Integer value that sets the number of tests to display in the Top-failed Tests section of the CIS benchmark report. Default: 5 | -| resultsFilter | **Optional**. An include or exclude filter to apply on the test results that will appear on the report. | - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-results - labels: - deployment: production -spec: - reportType: cis-benchmark - schedule: 0 0 * * * - cis: - highThreshold: 100 - medThreshold: 50 - includeUnscoredTests: true - numFailedTests: 5 - resultsFilters: - - benchmarkSelection: { kubernetesVersion: '1.13' } - exclude: ['1.1.4', '1.2.5'] -``` - -### View report generation status - -To view the status of a report, you must use the `kubectl` command. For example: - -```bash -kubectl get globalreports.projectcalico.org daily-cis-results -o yaml -``` - -In a report, the job status types are: - -- **lastScheduledReportJob**: - The most recently scheduled job for generating the report. Because reports are scheduled in order, the “end time” of - this report will be the “start time” of the next scheduled report. -- **activeReportJobs**: - Default = allows up to 5 concurrent report generation jobs. -- **lastFailedReportJobs**: - Default = keeps the 3 most recent failed jobs and deletes older ones. A single report generation job will be retried - up to 6 times (by default) before it is marked as failed. -- **lastSuccessfulReportJobs**: - Default = keeps the 2 most recent successful jobs and deletes older ones. - -#### Change the default report generation time - -By default, reports are generated 30 minutes after the end of the report, to ensure all of the audit data is archived. -(However, this gap does not affect the data collected “start/end time” for a report.) - -You can adjust the time for audit data for cases like initial report testing, to demo a report, or when manually -creating a report that is not counted in global report status. - -To change the delay, go to the installation manifest, and uncomment and set the environment variable -`TIGERA_COMPLIANCE_JOB_START_DELAY`. Specify value as a [Duration string][parse-duration]. - -### Review and address CIS benchmark results - -We recommend the following approach to CIS benchmark reports results: - -1. Download the Kubernetes CIS benchmarks and export your full CIS benchmark results in .csv format. -1. In the compliance dashboard, review the "Top-Failed Tests" section to identify which tests are the most problematic. -1. Cross-reference the top-failed tests to identify which nodes are failing that test. -1. Look up those tests in the [Kubernetes benchmark document](https://downloads.cisecurity.org/#/) and follow the remediation steps to resolve the failure. -1. Discuss with your infrastructure and security team if this remediation is viable within your organization. -1. If so, update your nodes with the fix and ensure that the test passes on the next generation of the report. -1. If the fix is not viable but is an acceptable risk to take within the organization, configure the report specification to exclude that test index so that it no longer appears in the report. -1. If the fix is not viable and not an acceptable risk to take on, keep the failing test within the report so that your team is reminded to address the issue as soon as possible. - -### Manually run reports - -You can manually run reports at any time. For example, run a manual report: - -- To specify a different start/end time -- If a scheduled report fails - -$[prodname] GlobalReport schedules Kubernetes Jobs which create a single-run pod to generate a report and store it in Elasticsearch. Because you need to run manual reports as a pod, you need higher permissions: allow `create` access for pods in namespace `tigera-compliance` using the `tigera-compliance-reporter` service account. - -To manually run a report: - -1. Download the pod template corresponding to your installation method. - **Operator** - - For management and standalone clusters: - - ```bash - curl -O $[filesUrl]/manifests/compliance-reporter-pod.yaml - ``` - - For managed clusters: - - ```bash - curl $[filesUrl]/manifests/compliance-reporter-pod-managed.yaml -o compliance-reporter-pod.yaml - ``` - -1. Edit the template as follows: - - - Edit the pod name if required. - - If you are using your own docker repository, update the container image name with your repo and image tag. - - Set the following environments according to the instructions in the downloaded manifest: - - `TIGERA_COMPLIANCE_REPORT_NAME` - - `TIGERA_COMPLIANCE_REPORT_START_TIME` - - `TIGERA_COMPLIANCE_REPORT_END_TIME` - -1. Apply the updated manifest, and query the status of the pod to ensure it completes. - Upon completion, the report is available in the web console. - - ```bash - # Apply the compliance report pod - kubectl apply -f compliance-reporter-pod.yaml - # Query the status of the pod - kubectl get pod -n=tigera-compliance - ``` - -:::note - -Manually-generated reports do not appear in GlobalReport status. - -::: - -### Troubleshooting - -**Problem**: Compliance reports can fail to generate if the `compliance-benchmarker` component cannot find the required `kubelet` or `kubectl` binaries to determine the Kubernetes version running on the cluster. - -**Solution or workaround**: If a node is running within a container (not running `kubelet` as a binary), make sure the `kubectl` binary is available in the `/usr/bin` directory. - -## Additional resources - -- For details on configuring and scheduling reports, see [Global reports](../reference/resources/globalreport.mdx) -- For other predefined compliance reports, see [Compliance reports](../reference/resources/compliance-reports/index.mdx) - -[parse-duration]: https://golang.org/pkg/time/#ParseDuration diff --git a/calico-enterprise_versioned_docs/version-3.24-1/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.24-1/compliance/enable-compliance.mdx deleted file mode 100644 index 8c60a2c317..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/compliance/enable-compliance.mdx +++ /dev/null @@ -1,49 +0,0 @@ ---- -description: Turn on the in-cluster compliance reporter, controller, snapshotter, and server components that produce Calico Enterprise compliance reports and CIS benchmarks. ---- - -# Enable compliance reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Enabling compliance reports improves the cluster's compliance posture. It involves generating compliance reports for Kubernetes clusters based on archived flow and audit logs for Calico Enterprise and Kubernetes resources. The process includes components for snapshotting configurations, generating reports, managing jobs, providing APIs with RBAC, and benchmarking security. - -## Value - -The compliance system consists of several key components that work together to ensure comprehensive compliance monitoring and reporting: - - - `compliance-snapshotter` : Lists required configurations and pushes snapshots to Elasticsearch, providing visibility into configuration changes. - - `compliance-reporter` : Generates reports by analyzing configuration history, determining configuration evolution and identifying "worst-case outliers." - - `compliance-controller` : Manages the creation, deletion, and monitoring of report generation jobs. - - `compliance-server` : Offers API for report management and enforces RBAC. - - `compliance-benchmarker` : Runs CIS Kubernetes Benchmark checks on each node to ensure secure deployment. - -**Required** - -* For managed clusters, ensure that compliance reporting is enabled in the management cluster. - -### Enable compliance reports using kubectl - -* Create a compliance custom resource, named `tigera-secure`, in the cluster. - -```bash -kubectl apply -f - < \ No newline at end of file diff --git a/calico-enterprise_versioned_docs/version-3.24-1/compliance/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/compliance/index.mdx index 4cf8b13d87..d561170195 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/compliance/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/compliance/index.mdx @@ -1,19 +1,15 @@ --- -description: Generate compliance reports and encrypt in-cluster traffic in your Calico Enterprise cluster, with archived flow logs, audit logs, CIS benchmarks, and WireGuard. +description: Encrypt in-cluster traffic with WireGuard and configure security options for your Calico Enterprise cluster. hide_table_of_contents: true --- import { DocCardLink, DocCardLinkLayout } from '/src/___new___/components'; -# Compliance and security +# Security -Get reports on Kubernetes workloads and environments for regulatory compliance. -Encrypt traffic in your cluster with WireGuard. +Encrypt traffic in your cluster with WireGuard, and configure security options for your $[prodname] cluster. - - - diff --git a/calico-enterprise_versioned_docs/version-3.24-1/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.24-1/compliance/overview.mdx deleted file mode 100644 index 1e4ac16448..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/compliance/overview.mdx +++ /dev/null @@ -1,382 +0,0 @@ ---- -description: Schedule and run Calico Enterprise compliance reports against Kubernetes workloads using archived flow logs and audit logs stored in Elasticsearch. ---- - -# Schedule and run compliance reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Schedule and run compliance reports to assess Kubernetes workloads and environments for regulatory compliance. - -## Value - -Compliance tools that rely on periodic snapshots, do not provide accurate assessments of Kubernetes workloads against your compliance standards. $[prodname] compliance dashboard and reports provide a complete inventory of regulated workloads, along with evidence of enforcement of network controls for these workloads. Additionally, audit reports are available to see changes to any network security controls. - -## Concepts - -### Compliance reports at a glance - -Compliance report are based on archived flow logs and audit logs for all of your $[prodname] resources, plus any audit logs you've configured for Kubernetes resources in the Kubernetes API server: - -- Pods -- Host endpoints -- Service accounts -- Namespaces -- Kubernetes service endpoints -- Global network sets -- Calico and Kubernetes network policies -- Global network policies - -Compliance reports provide the following high-level information: - -- **Protection** - - - Endpoints explicitly protected using ingress or egress policy - - Endpoints with Envoy enabled - -- **Policies and services** - - - Policies and services associated with endpoints - - Policy audit logs - -- **Traffic** - - Allowed ingress/egress traffic to/from namespaces - - Allowed ingress/egress traffic to/from the internet - -![compliance-reporting](/img/calico-enterprise/compliance-reporting.png) - -## Before you begin - -**Unsupported** - -- AKS -- GKE -- OpenShift -- TKG - -**Required** - -* You [Enabled compliance reports](../compliance/enable-compliance) - -- Ensure that all nodes in your Kubernetes clusters are time-synchronized using NTP or similar (for accurate audit log timestamps) - -- [Configure audit logs for Kubernetes resources](../observability/elastic/audit-overview.mdx) - - You must configure audit logs for Kubernetes resources through the Kubernetes API to get a complete view of all resources. - -## How to - -- [Configure report permissions](#configure-report-permissions) -- [Configure and schedule reports](#configure-and-schedule-reports) -- [View report generation status](#view-report-generation-status) -- [Run reports](#run-reports) - -### Configure report permissions - -Report permissions are granted using the standard Kubernetes RBAC based on ClusterRole and ClusterRoleBindings. The following table outlines the required RBAC verbs for each resource type for a specific user actions. - -| **Action** | **globalreporttypes** | **globalreports** | **globalreports/status** | -| ------------------------------------------------------- | ------------------------------- | --------------------------------- | ------------------------ | -| Manage reports (create/modify/delete) | | \* | get | -| View status of report generation through kubectl | | get | get | -| List the generated reports and summary status in the UI | | list + get (for required reports) | | -| Export the generated reports from the UI | get (for the particular report) | get (for required reports) | | - -The following sample manifest creates RBAC for three users: Paul, Candice and David. - -- Paul has permissions to create/modify/delete the report schedules and configuration, but does not have permission to export generated reports from the UI. -- Candice has permissions to list and export generated reports from the UI, but cannot modify the report schedule or configuration. -- David has permissions to list and export generated `dev-inventory` reports from the UI, but cannot list or download other reports, nor modify the report - schedule or configuration. - -```yaml -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-manage-report-config -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['*'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreports/status'] - verbs: ['get', 'list', 'watch'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-manage-report-config -subjects: - - kind: User - name: paul - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-manage-report-config - apiGroup: rbac.authorization.k8s.io - ---- -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-all-reports -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['get', 'list'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreporttypes'] - verbs: ['get'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-all-reports -subjects: - - kind: User - name: candice - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-list-download-all-reports - apiGroup: rbac.authorization.k8s.io - ---- -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-dev-inventory -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['list'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['get'] - resourceNames: ['dev-inventory'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreporttypes'] - verbs: ['get'] - resourceNames: ['dev-inventory'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-dev-inventory -subjects: - - kind: User - name: david - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-list-download-dev-inventory - apiGroup: rbac.authorization.k8s.io -``` - -### Configure and schedule reports - -To configure and schedule a compliance report, create a [GlobalReport](../reference/resources/globalreport.mdx) with the following information. - -| **Fields** | **Description** | -| --------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| name | Unique name for your report. | -| reportType | One of the following predefined report types: `inventory`, `network-access`, `policy-audit`. | -| schedule | The start and end time of the report using [crontab format](https://en.wikipedia.org/wiki/Cron). To allow for archiving, reports are generated approximately 30 minutes after the end time. A single report is limited to a maximum of two per hour. | -| endpoints | **Optional**. For inventory and network-access reports, specifies the endpoints to include in the report. For the policy-audit report, restricts audit logs to include only policies that apply to the selected endpoints. If not specified, the report includes all endpoints and audit logs. | -| jobNodeSelector | **Optional**. Limits report generation jobs to specific nodes. | -| suspend | **Optional**. Suspends report generation. All in-flight reports will complete, and future scheduled reports are suspended. | - -:::note - -GlobalReports can only be configured using kubectl (not calicoctl); and they cannot be edited in the Tigera -Secure EE the web console. - -::: - -The following sections provide sample schedules for the predefined reports. - -### Weekly reports, all endpoints - -The following report schedules weekly inventory reports for _all_ endpoints. The jobs that create the reports will run -on the infrastructure nodes (e.g. nodetype == 'infrastructure'). - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: weekly-full-inventory -spec: - reportType: inventory - schedule: 0 0 * * 0 - jobNodeSelector: - nodetype: infrastructure -``` - -### Daily reports, selected endpoints - -The following report schedules daily inventory reports for production endpoints (e.g. deployment == ‘production’). - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-production-inventory -spec: - reportType: inventory - endpoints: - selector: deployment == 'production' - schedule: 0 0 * * * -``` - -### Hourly reports, endpoints in named namespaces - -The following report schedules hourly network-access reports for the accounts department endpoints, that are -specified using the namespace names: **payable**, **collections** and **payroll**. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: hourly-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - names: ['payable', 'collections', 'payroll'] - schedule: 0 * * * * -``` - -### Daily reports, endpoints in selected namespaces - -The following report schedules daily network-access reports for the accounts department with endpoints specified using -a namespace selector. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - selector: department == 'accounts' - schedule: 0 0 * * * -``` - -### Monthly reports, endpoints for named service accounts in named namespaces - -The following schedules monthly audit reports. The audited policy is restricted to policy that applies to -widgets/controller endpoints specified by the namespace **widgets** and service account **controller**. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: monthly-widgets-controller-tigera-policy-audit -spec: - reportType: policy-audit - schedule: 0 0 1 * * - endpoints: - serviceAccounts: - names: ['controller'] - namespaces: - names: ['widgets'] -``` - -### View report generation status - -To view the status of a report, you must use the `kubectl` command. For example: - -```bash -kubectl get globalreports.projectcalico.org daily-inventory.p -o yaml -``` - -In a report, the job status types are: - -- **lastScheduledReportJob**: - The most recently scheduled job for generating the report. Because reports are scheduled in order, the “end time” of - this report will be the “start time” of the next scheduled report. -- **activeReportJobs**: - Default = allows up to 5 concurrent report generation jobs. -- **lastFailedReportJobs**: - Default = keeps the 3 most recent failed jobs and deletes older ones. A single report generation job will be retried - up to 6 times (by default) before it is marked as failed. -- **lastSuccessfulReportJobs**: - Default = keeps the 2 most recent successful jobs and deletes older ones. - -### Change the default report generation time - -By default, reports are generated 30 minutes after the end of the report, to ensure all of the audit data is archived. -(However, this gap does not affect the data collected “start/end time” for a report.) - -You can adjust the time for audit data for cases like initial report testing, to demo a report, or when manually -creating a report that is not counted in global report status. - -To change the delay, go to the installation manifest, and uncomment and set the environment -`TIGERA_COMPLIANCE_JOB_START_DELAY`. Specify value as a [Duration string][parse-duration]. - -### Run reports - -You can run reports at any time to specify a different start/end time, and if a scheduled report fails. - -$[prodname] GlobalReport schedules Kubernetes Jobs, which create a single-run pod to generate a report and store it -in Elasticsearch. Because you need to run reports as a pod, you need higher permissions: allow `create` access for pods in namespace `tigera-compliance` using the `tigera-compliance-reporter` service account. - -To run a report on demand: - -1. Download the pod template corresponding to your installation method. - - For management and standalone clusters: - - ```bash - curl -O $[filesUrl]/manifests/compliance-reporter-pod.yaml - ``` - - For managed clusters: - - ```bash - curl $[filesUrl]/manifests/compliance-reporter-pod-managed.yaml -o compliance-reporter-pod.yaml - ``` - -1. Edit the template as follows: - - Edit the pod name if required. - - If you are using your own docker repository, update the container image name with your repo and image tag. - - Set the following environments according to the instructions in the downloaded manifest: - - `TIGERA_COMPLIANCE_REPORT_NAME` - - `TIGERA_COMPLIANCE_REPORT_START_TIME` - - `TIGERA_COMPLIANCE_REPORT_END_TIME` -1. Apply the updated manifest, and query the status of the pod to ensure it completes. - Upon completion, the report is available in the $[prodname] web console. - - ```bash - # Apply the compliance report pod - kubectl apply -f compliance-reporter-pod.yaml - - # Query the status of the pod - kubectl get pod -n tigera-compliance - ``` - -:::note - -Manually-generated reports do not appear in GlobalReport status. - -::: - -## Additional resources - -- For details on configuring and scheduling reports, see [Global reports](../reference/resources/globalreport.mdx) -- For report field descriptions, see [Compliance reports](../reference/resources/compliance-reports/index.mdx) -- [CIS benchmarks](compliance-reports-cis.mdx) - -[parse-duration]: https://golang.org/pkg/time/#ParseDuration diff --git a/calico-enterprise_versioned_docs/version-3.24-1/observability/get-started-cem.mdx b/calico-enterprise_versioned_docs/version-3.24-1/observability/get-started-cem.mdx index 2910289ad2..5ca9a5357e 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/observability/get-started-cem.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/observability/get-started-cem.mdx @@ -111,20 +111,6 @@ This page is where you switch views between clusters in the web console. When yo ![managed-clusters](/img/calico-enterprise/managed-clusters.png) -## Compliance Reports - -> From the left navbar, click **Compliance**. - -Compliance tools that rely on periodic snapshots, do not provide accurate assessments of Kubernetes workloads against your compliance standards. $[prodname] compliance dashboard and reports provide a complete inventory of regulated workloads, along with evidence of enforcement of network controls for these workloads. Additionally, audit reports are available to see changes to any network security controls. - -**Compliance reports** are based on archived flow logs and audit logs for all $[prodname] resources, and audit logs for Kubernetes resources in the Kubernetes API server. - -![cis-benchmark](/img/calico-enterprise/cis-benchmark.png) - -Using the filter, you can select report types. - -![compliance-filter](/img/calico-enterprise/compliance-filter.png) - ## Activity > From the left navbar, select **Activity**, **Timeline**. diff --git a/calico-enterprise_versioned_docs/version-3.24-1/operations/cnx/roles-and-permissions.mdx b/calico-enterprise_versioned_docs/version-3.24-1/operations/cnx/roles-and-permissions.mdx index 3e88e18a39..1c183ccad2 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/operations/cnx/roles-and-permissions.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/operations/cnx/roles-and-permissions.mdx @@ -21,7 +21,6 @@ The [Calico Enterprise API server](../../reference/installation/api.mdx#apiserve | Features | RBAC controls for... | | ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Network policy | - Tiered policy, including AWS security groups and federated services.
- Kubernetes network policy (in default tier)
- $[prodname] network policies including namespaces
- Staged policy, policy recommendation, policy preview | -| Compliance | Report management, generation, export, and status. | | Visibility and troubleshooting | Elasticsearch logs: flow, audit, dns, intrusion detection, bgp | | Multi-cluster management | Management and managed clusters in single management plane. | @@ -47,5 +46,4 @@ For RBAC details on any given feature, see the feature. For example: - [Policy preview RBAC](../../network-policy/policy-impact-preview.mdx) - [Staged policy RBAC](../../network-policy/staged-network-policies.mdx) - [Elasticsearch logs RBAC](../../observability/elastic/rbac-elasticsearch.mdx) -- [Compliance reports RBAC](../../compliance/overview.mdx) - [Multi-cluster management RBAC](../../multicluster/set-up-multi-cluster-management/standard-install/create-a-management-cluster.mdx) diff --git a/calico-enterprise_versioned_docs/version-3.24-1/operations/troubleshoot/troubleshooting.mdx b/calico-enterprise_versioned_docs/version-3.24-1/operations/troubleshoot/troubleshooting.mdx index 31c9f17327..08bf914c5c 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/operations/troubleshoot/troubleshooting.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/operations/troubleshoot/troubleshooting.mdx @@ -141,13 +141,6 @@ sysctl -w net.netfilter.nf_conntrack_max=1000000 echo "net.netfilter.nf_conntrack_max=1000000" >> /etc/sysctl.conf ``` -## Compliance report is not generating at expected time - -By design, reports are scheduled to generate 30 minutes after the specified end time. The reason for this is to allow a certain amount of -time to pass for all the relevant data within the specified start and end time to be fully processed and stored. This delay can be modified -by setting the `TIGERA_COMPLIANCE_JOB_START_DELAY` environment variable on the `compliance-controller` deployment to the -desired [Golang duration](https://godoc.org/time#Duration). - ## GlobalAlert reports error "Trying to create too many buckets" ``` diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/index.mdx index 3e2808cdc5..726992ad39 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/index.mdx @@ -74,11 +74,6 @@ APIs, CLI, architecture and design, and FAQ. - - - - - @@ -87,7 +82,6 @@ APIs, CLI, architecture and design, and FAQ. - diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_api.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_api.mdx index 581bf232e7..cd280156b9 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_api.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_api.mdx @@ -14,7 +14,6 @@ Resource Types - [APIServer](#apiserver) - [ApplicationLayer](#applicationlayer) - [Authentication](#authentication) -- [Compliance](#compliance) - [EgressGateway](#egressgateway) - [GatewayAPI](#gatewayapi) - [Goldmane](#goldmane) @@ -565,6 +564,21 @@ _Appears in:_ | `Public` | | +### CNIInstallMode + +_Underlying type:_ _string_ + +CNIInstallMode controls which CNI plugin binaries the operator installs onto the host. + +_Appears in:_ +- [CNISpec](#cnispec) + +| Value | Description | +| --- | --- | +| `All` | CNIInstallModeAll installs Calico's own CNI binaries plus the upstream plugin set (host-local, portmap, loopback, tuning, flannel) via a dedicated init container. | +| `CalicoOnly` | CNIInstallModeCalicoOnly installs only Calico's own CNI binaries; the host is expected to provide any required upstream plugins. | + + ### CNILogging @@ -616,6 +630,7 @@ _Appears in:_ | `ipam` _[IPAMSpec](#ipamspec)_ | (Optional) IPAM specifies the pod IP address management that will be used in the Calico or Calico Enterprise installation. | | `binDir` _string_ | (Optional) BinDir is the path to the CNI binaries directory. If you have changed the installation directory for CNI binaries in the container runtime configuration, please ensure that this field points to the same directory as specified in the container runtime settings. Default directory depends on the KubernetesProvider. * For KubernetesProvider GKE, this field defaults to "/home/kubernetes/bin". * For KubernetesProvider OpenShift, this field defaults to "/var/lib/cni/bin". * Otherwise, this field defaults to "/opt/cni/bin". | | `confDir` _string_ | (Optional) ConfDir is the path to the CNI config directory. If you have changed the installation directory for CNI configuration in the container runtime configuration, please ensure that this field points to the same directory as specified in the container runtime settings. Default directory depends on the KubernetesProvider. * For KubernetesProvider GKE, this field defaults to "/etc/cni/net.d". * For KubernetesProvider OpenShift, this field defaults to "/var/run/multus/cni/net.d". * Otherwise, this field defaults to "/etc/cni/net.d". | +| `installMode` _[CNIInstallMode](#cniinstallmode)_ | (Optional) InstallMode controls which CNI plugin binaries the operator installs onto each node when CNI.Type is Calico. * All (default): the operator runs a cni-plugins init container that stages upstream CNI plugin binaries (host-local, portmap, loopback, tuning, flannel) into a shared volume, and the install-cni init container copies them onto the host alongside Calico's own binaries. * CalicoOnly: skip the cni-plugins init container. Only Calico's own binaries are installed. Use this when the host already provides the upstream plugins (e.g. kind, certain managed node images).
Default: All | ### CRDManagement @@ -867,7 +882,7 @@ _Appears in:_ | Field | Description | | --- | --- | -| `name` _string_ | Name is an enum which identifies the calico-node DaemonSet init container by name.
Supported values are: install-cni, hostpath-init, flexvol-driver, ebpf-bootstrap, node-certs-key-cert-provisioner, calico-node-prometheus-server-tls-key-cert-provisioner, mount-bpffs (deprecated, replaced by ebpf-bootstrap) | +| `name` _string_ | Name is an enum which identifies the calico-node DaemonSet init container by name.
Supported values are: install-cni, cni-plugins, hostpath-init, flexvol-driver, ebpf-bootstrap, node-certs-key-cert-provisioner, calico-node-prometheus-server-tls-key-cert-provisioner, mount-bpffs (deprecated, replaced by ebpf-bootstrap) | | `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named calico-node DaemonSet init container's resources. If omitted, the calico-node DaemonSet will use its default value for this container's resources. If used in conjunction with the deprecated ComponentResources, then this value takes precedence. | @@ -1260,486 +1275,6 @@ _Appears in:_ | `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | Define resources requests and limits for single Pods. | -### Compliance - - - -Compliance installs the components required for Tigera compliance reporting. At most one instance -of this resource is supported. It must be named "tigera-secure". - -| Field | Description | -| --- | --- | -| `apiVersion` _string_ | `operator.tigera.io/v1` | -| `kind` _string_ | `Compliance` | -| `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | -| `spec` _[ComplianceSpec](#compliancespec)_ | Specification of the desired state for Tigera compliance reporting. | -| `status` _[ComplianceStatus](#compliancestatus)_ | Most recently observed state for Tigera compliance reporting. | - - -### ComplianceBenchmarkerDaemonSet - - - -ComplianceBenchmarkerDaemonSet is the configuration for the Compliance Benchmarker DaemonSet. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceBenchmarkerDaemonSetSpec](#compliancebenchmarkerdaemonsetspec)_ | (Optional) Spec is the specification of the Compliance Benchmarker DaemonSet. | - - -### ComplianceBenchmarkerDaemonSetContainer - - - -ComplianceBenchmarkerDaemonSetContainer is a Compliance Benchmarker DaemonSet container. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the Compliance Benchmarker DaemonSet container by name.
Supported values are: compliance-benchmarker | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named Compliance Benchmarker DaemonSet container's resources. If omitted, the Compliance Benchmarker DaemonSet will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceBenchmarkerDaemonSetInitContainer - - - -ComplianceBenchmarkerDaemonSetInitContainer is a Compliance Benchmarker DaemonSet init container. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the Compliance Benchmarker DaemonSet init container by name.
Supported values are: tigera-compliance-benchmarker-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named Compliance Benchmarker DaemonSet init container's resources. If omitted, the Compliance Benchmarker DaemonSet will use its default value for this init container's resources. | - - -### ComplianceBenchmarkerDaemonSetPodSpec - - - -ComplianceBenchmarkerDaemonSetPodSpec is the Compliance Benchmarker DaemonSet's PodSpec. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodTemplateSpec](#compliancebenchmarkerdaemonsetpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceBenchmarkerDaemonSetInitContainer](#compliancebenchmarkerdaemonsetinitcontainer) array_ | (Optional) InitContainers is a list of Compliance benchmark init containers. If specified, this overrides the specified Compliance Benchmarker DaemonSet init containers. If omitted, the Compliance Benchmarker DaemonSet will use its default values for its init containers. | -| `containers` _[ComplianceBenchmarkerDaemonSetContainer](#compliancebenchmarkerdaemonsetcontainer) array_ | (Optional) Containers is a list of Compliance benchmark containers. If specified, this overrides the specified Compliance Benchmarker DaemonSet containers. If omitted, the Compliance Benchmarker DaemonSet will use its default values for its containers. | - - -### ComplianceBenchmarkerDaemonSetPodTemplateSpec - - - -ComplianceBenchmarkerDaemonSetPodTemplateSpec is the Compliance Benchmarker DaemonSet's PodTemplateSpec - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetSpec](#compliancebenchmarkerdaemonsetspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec)_ | (Optional) Spec is the Compliance Benchmarker DaemonSet's PodSpec. | - - -### ComplianceBenchmarkerDaemonSetSpec - - - -ComplianceBenchmarkerDaemonSetSpec defines configuration for the Compliance Benchmarker DaemonSet. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSet](#compliancebenchmarkerdaemonset) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceBenchmarkerDaemonSetPodTemplateSpec](#compliancebenchmarkerdaemonsetpodtemplatespec)_ | (Optional) Template describes the Compliance Benchmarker DaemonSet pod that will be created. | - - -### ComplianceControllerDeployment - - - -ComplianceControllerDeployment is the configuration for the compliance controller Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceControllerDeploymentSpec](#compliancecontrollerdeploymentspec)_ | (Optional) Spec is the specification of the compliance controller Deployment. | - - -### ComplianceControllerDeploymentContainer - - - -ComplianceControllerDeploymentContainer is a compliance controller Deployment container. - -_Appears in:_ -- [ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance controller Deployment container by name.
Supported values are: compliance-controller | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance controller Deployment container's resources. If omitted, the compliance controller Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceControllerDeploymentInitContainer - - - -ComplianceControllerDeploymentInitContainer is a compliance controller Deployment init container. - -_Appears in:_ -- [ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance controller Deployment init container by name.
Supported values are: tigera-compliance-controller-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance controller Deployment init container's resources. If omitted, the compliance controller Deployment will use its default value for this init container's resources. | - - -### ComplianceControllerDeploymentPodSpec - - - -ComplianceControllerDeploymentPodSpec is the compliance controller Deployment's PodSpec. - -_Appears in:_ -- [ComplianceControllerDeploymentPodTemplateSpec](#compliancecontrollerdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceControllerDeploymentInitContainer](#compliancecontrollerdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of compliance controller init containers. If specified, this overrides the specified compliance controller Deployment init containers. If omitted, the compliance controller Deployment will use its default values for its init containers. | -| `containers` _[ComplianceControllerDeploymentContainer](#compliancecontrollerdeploymentcontainer) array_ | (Optional) Containers is a list of compliance controller containers. If specified, this overrides the specified compliance controller Deployment containers. If omitted, the compliance controller Deployment will use its default values for its containers. | - - -### ComplianceControllerDeploymentPodTemplateSpec - - - -ComplianceControllerDeploymentPodTemplateSpec is the compliance controller Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceControllerDeploymentSpec](#compliancecontrollerdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec)_ | (Optional) Spec is the compliance controller Deployment's PodSpec. | - - -### ComplianceControllerDeploymentSpec - - - -ComplianceControllerDeploymentSpec defines configuration for the compliance controller Deployment. - -_Appears in:_ -- [ComplianceControllerDeployment](#compliancecontrollerdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceControllerDeploymentPodTemplateSpec](#compliancecontrollerdeploymentpodtemplatespec)_ | (Optional) Template describes the compliance controller Deployment pod that will be created. | - - -### ComplianceReporterPodSpec - - - -ComplianceReporterPodSpec is the ComplianceReporter PodSpec. - -_Appears in:_ -- [ComplianceReporterPodTemplateSpec](#compliancereporterpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceReporterPodTemplateInitContainer](#compliancereporterpodtemplateinitcontainer) array_ | (Optional) InitContainers is a list of ComplianceReporter PodSpec init containers. If specified, this overrides the specified ComplianceReporter PodSpec init containers. If omitted, the ComplianceServer Deployment will use its default values for its init containers. | -| `containers` _[ComplianceReporterPodTemplateContainer](#compliancereporterpodtemplatecontainer) array_ | (Optional) Containers is a list of ComplianceServer containers. If specified, this overrides the specified ComplianceReporter PodSpec containers. If omitted, the ComplianceServer Deployment will use its default values for its containers. | - - -### ComplianceReporterPodTemplate - - - -ComplianceReporterPodTemplate is the configuration for the ComplianceReporter PodTemplate. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceReporterPodTemplateSpec](#compliancereporterpodtemplatespec)_ | (Optional) Spec is the specification of the ComplianceReporter PodTemplateSpec. | - - -### ComplianceReporterPodTemplateContainer - - - -ComplianceReporterPodTemplateContainer is a ComplianceServer Deployment container. - -_Appears in:_ -- [ComplianceReporterPodSpec](#compliancereporterpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment container by name.
Supported values are: reporter | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment container's resources. If omitted, the ComplianceServer Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceReporterPodTemplateInitContainer - - - -ComplianceReporterPodTemplateInitContainer is a ComplianceServer Deployment init container. - -_Appears in:_ -- [ComplianceReporterPodSpec](#compliancereporterpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceReporter PodSpec init container by name.
Supported values are: tigera-compliance-reporter-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceReporter PodSpec init container's resources. If omitted, the ComplianceServer Deployment will use its default value for this init container's resources. | - - -### ComplianceReporterPodTemplateSpec - - - -ComplianceReporterPodTemplateSpec is the ComplianceReporter PodTemplateSpec. - -_Appears in:_ -- [ComplianceReporterPodTemplate](#compliancereporterpodtemplate) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceReporterPodSpec](#compliancereporterpodspec)_ | (Optional) Spec is the ComplianceReporter PodTemplate's PodSpec. | - - -### ComplianceServerDeployment - - - -ComplianceServerDeployment is the configuration for the ComplianceServer Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceServerDeploymentSpec](#complianceserverdeploymentspec)_ | (Optional) Spec is the specification of the ComplianceServer Deployment. | - - -### ComplianceServerDeploymentContainer - - - -ComplianceServerDeploymentContainer is a ComplianceServer Deployment container. - -_Appears in:_ -- [ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment container by name.
Supported values are: compliance-server | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment container's resources. If omitted, the ComplianceServer Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceServerDeploymentInitContainer - - - -ComplianceServerDeploymentInitContainer is a ComplianceServer Deployment init container. - -_Appears in:_ -- [ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment init container by name.
Supported values are: tigera-compliance-server-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment init container's resources. If omitted, the ComplianceServer Deployment will use its default value for this init container's resources. | - - -### ComplianceServerDeploymentPodSpec - - - -ComplianceServerDeploymentPodSpec is the ComplianceServer Deployment's PodSpec. - -_Appears in:_ -- [ComplianceServerDeploymentPodTemplateSpec](#complianceserverdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceServerDeploymentInitContainer](#complianceserverdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of ComplianceServer init containers. If specified, this overrides the specified ComplianceServer Deployment init containers. If omitted, the ComplianceServer Deployment will use its default values for its init containers. | -| `containers` _[ComplianceServerDeploymentContainer](#complianceserverdeploymentcontainer) array_ | (Optional) Containers is a list of ComplianceServer containers. If specified, this overrides the specified ComplianceServer Deployment containers. If omitted, the ComplianceServer Deployment will use its default values for its containers. | - - -### ComplianceServerDeploymentPodTemplateSpec - - - -ComplianceServerDeploymentPodTemplateSpec is the ComplianceServer Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceServerDeploymentSpec](#complianceserverdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec)_ | (Optional) Spec is the ComplianceServer Deployment's PodSpec. | - - -### ComplianceServerDeploymentSpec - - - -ComplianceServerDeploymentSpec defines configuration for the ComplianceServer Deployment. - -_Appears in:_ -- [ComplianceServerDeployment](#complianceserverdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceServerDeploymentPodTemplateSpec](#complianceserverdeploymentpodtemplatespec)_ | (Optional) Template describes the ComplianceServer Deployment pod that will be created. | - - -### ComplianceSnapshotterDeployment - - - -ComplianceSnapshotterDeployment is the configuration for the compliance snapshotter Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceSnapshotterDeploymentSpec](#compliancesnapshotterdeploymentspec)_ | (Optional) Spec is the specification of the compliance snapshotter Deployment. | - - -### ComplianceSnapshotterDeploymentContainer - - - -ComplianceSnapshotterDeploymentContainer is a compliance snapshotter Deployment container. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance snapshotter Deployment container by name.
Supported values are: compliance-snapshotter | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance snapshotter Deployment container's resources. If omitted, the compliance snapshotter Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceSnapshotterDeploymentInitContainer - - - -ComplianceSnapshotterDeploymentInitContainer is a compliance snapshotter Deployment init container. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance snapshotter Deployment init container by name.
Supported values are: tigera-compliance-snapshotter-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance snapshotter Deployment init container's resources. If omitted, the compliance snapshotter Deployment will use its default value for this init container's resources. | - - -### ComplianceSnapshotterDeploymentPodSpec - - - -ComplianceSnapshotterDeploymentPodSpec is the compliance snapshotter Deployment's PodSpec. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodTemplateSpec](#compliancesnapshotterdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceSnapshotterDeploymentInitContainer](#compliancesnapshotterdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of compliance snapshotter init containers. If specified, this overrides the specified compliance snapshotter Deployment init containers. If omitted, the compliance snapshotter Deployment will use its default values for its init containers. | -| `containers` _[ComplianceSnapshotterDeploymentContainer](#compliancesnapshotterdeploymentcontainer) array_ | (Optional) Containers is a list of compliance snapshotter containers. If specified, this overrides the specified compliance snapshotter Deployment containers. If omitted, the compliance snapshotter Deployment will use its default values for its containers. | - - -### ComplianceSnapshotterDeploymentPodTemplateSpec - - - -ComplianceSnapshotterDeploymentPodTemplateSpec is the compliance snapshotter Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceSnapshotterDeploymentSpec](#compliancesnapshotterdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec)_ | (Optional) Spec is the compliance snapshotter Deployment's PodSpec. | - - -### ComplianceSnapshotterDeploymentSpec - - - -ComplianceSnapshotterDeploymentSpec defines configuration for the compliance snapshotter Deployment. - -_Appears in:_ -- [ComplianceSnapshotterDeployment](#compliancesnapshotterdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceSnapshotterDeploymentPodTemplateSpec](#compliancesnapshotterdeploymentpodtemplatespec)_ | (Optional) Template describes the compliance snapshotter Deployment pod that will be created. | - - -### ComplianceSpec - - - -ComplianceSpec defines the desired state of Tigera compliance reporting capabilities. - -_Appears in:_ -- [Compliance](#compliance) - -| Field | Description | -| --- | --- | -| `complianceControllerDeployment` _[ComplianceControllerDeployment](#compliancecontrollerdeployment)_ | (Optional) ComplianceControllerDeployment configures the Compliance Controller Deployment. | -| `complianceSnapshotterDeployment` _[ComplianceSnapshotterDeployment](#compliancesnapshotterdeployment)_ | (Optional) ComplianceSnapshotterDeployment configures the Compliance Snapshotter Deployment. | -| `complianceBenchmarkerDaemonSet` _[ComplianceBenchmarkerDaemonSet](#compliancebenchmarkerdaemonset)_ | (Optional) ComplianceBenchmarkerDaemonSet configures the Compliance Benchmarker DaemonSet. | -| `complianceServerDeployment` _[ComplianceServerDeployment](#complianceserverdeployment)_ | (Optional) ComplianceServerDeployment configures the Compliance Server Deployment. | -| `complianceReporterPodTemplate` _[ComplianceReporterPodTemplate](#compliancereporterpodtemplate)_ | (Optional) ComplianceReporterPodTemplate configures the Compliance Reporter PodTemplate. | - - -### ComplianceStatus - - - -ComplianceStatus defines the observed state of Tigera compliance reporting capabilities. - -_Appears in:_ -- [Compliance](#compliance) - -| Field | Description | -| --- | --- | -| `state` _string_ | State provides user-readable status. | -| `conditions` _[Condition](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#condition-v1-meta) array_ | (Optional) Conditions represents the latest observed set of conditions for the component. A component may be one or more of Ready, Progressing, Degraded or other customer types. | - - ### ComponentName _Underlying type:_ _string_ @@ -1920,7 +1455,7 @@ _Appears in:_ DashboardsJobSpec defines configuration for the Dashboards job. _Appears in:_ -- DashboardsJob +- [DashboardsJob](#dashboardsjob) | Field | Description | | --- | --- | @@ -1938,7 +1473,7 @@ _Validation:_ _Appears in:_ -- Index +- [Index](#index) | Value | Description | | --- | --- | @@ -2664,8 +2199,8 @@ _Appears in:_ | --- | --- | | `params` _object (keys:string, values:string array)_ | Optional HTTP URL parameters
Default: scrape all metrics. | | `bearerTokenSecret` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#secretkeyselector-v1-core)_ | Secret to mount to read bearer token for scraping targets. Recommended: when unset, the operator will create a Secret, a ClusterRole and a ClusterRoleBinding. | -| `interval` _Duration_ | Interval at which metrics should be scraped. If not specified Prometheus' global scrape interval is used. | -| `scrapeTimeout` _Duration_ | Timeout after which the scrape is ended. If not specified, the Prometheus global scrape timeout is used unless it is less than `Interval` in which the latter is used. | +| `interval` _[Duration](#duration)_ | Interval at which metrics should be scraped. If not specified Prometheus' global scrape interval is used. | +| `scrapeTimeout` _[Duration](#duration)_ | Timeout after which the scrape is ended. If not specified, the Prometheus global scrape timeout is used unless it is less than `Interval` in which the latter is used. | | `honorLabels` _boolean_ | HonorLabels chooses the metric's labels on collisions with target labels. | | `honorTimestamps` _boolean_ | HonorTimestamps controls whether Prometheus respects the timestamps present in scraped data. | | `metricRelabelings` _RelabelConfig array_ | MetricRelabelConfigs to apply to samples before ingestion. | @@ -2820,6 +2355,20 @@ _Appears in:_ | `spec` _[GatewayAPISpec](#gatewayapispec)_ | | +### GatewayAPIExtensions + + + +GatewayAPIExtensions enables and configures Tigera-built Gateway API add-ons. + +_Appears in:_ +- [GatewayAPISpec](#gatewayapispec) + +| Field | Description | +| --- | --- | +| `waf` _[WAFExtensionSpec](#wafextensionspec)_ | (Optional) WAF enables and configures the Tigera Web Application Firewall (Coraza WASM when WAF.State is nil, and when WAF.State is "Disabled", the operator does not render the WAF env vars or RBAC on calico-kube-controllers. Set WAF.State = "Enabled" to turn the feature on. See design `tigera/designs#25` (PMREQ-384) for the full surface. | + + ### GatewayAPISpec @@ -2836,6 +2385,7 @@ _Appears in:_ | `gatewayControllerDeployment` _[GatewayControllerDeployment](#gatewaycontrollerdeployment)_ | (Optional) Allows customization of the gateway controller deployment. | | `gatewayCertgenJob` _[GatewayCertgenJob](#gatewaycertgenjob)_ | (Optional) Allows customization of the gateway certgen job. | | `crdManagement` _[CRDManagement](#crdmanagement)_ | (Optional) Configures how to manage and update Gateway API CRDs. The default behaviour - which is used when this field is not set, or is set to "PreferExisting" - is that the Tigera operator will create the Gateway API CRDs if they do not already exist, but will not overwrite any existing Gateway API CRDs. This setting may be preferable if the customer is using other implementations of the Gateway API concurrently with the Gateway API support in Calico Enterprise. It is then the customer's responsibility to ensure that CRDs are installed that meet the needs of all the Gateway API implementations in their cluster. Alternatively, if this field is set to "Reconcile", the Tigera operator will keep the cluster's Gateway API CRDs aligned with those that it would install on a cluster that does not yet have any version of those CRDs. | +| `extensions` _[GatewayAPIExtensions](#gatewayapiextensions)_ | (Optional) Extensions enables and configures Tigera-built add-ons that sit on top of the Gateway API data plane. Each add-on is opt-in: an unset Extensions, an unset add-on field, and an empty add-on object all leave the add-on disabled. | ### GatewayCertgenJob @@ -3625,7 +3175,7 @@ _Appears in:_ | `disableBGPExport` _boolean_ | (Optional) DisableBGPExport specifies whether routes from this IP pool's CIDR are exported over BGP.
Default: false | | `disableNewAllocations` _boolean_ | DisableNewAllocations specifies whether or not new IP allocations are allowed from this pool. This is useful when you want to prevent new pods from receiving IP addresses from this pool, without impacting any existing pods that have already been assigned addresses from this pool. | | `allowedUses` _[IPPoolAllowedUse](#ippoolalloweduse) array_ | AllowedUse controls what the IP pool will be used for. If not specified or empty, defaults to ["Tunnel", "Workload"] for back-compatibility | -| `assignmentMode` _AssignmentMode_ | AssignmentMode determines if IP addresses from this pool should be assigned automatically or on request only | +| `assignmentMode` _[AssignmentMode](#assignmentmode)_ | AssignmentMode determines if IP addresses from this pool should be assigned automatically or on request only | ### IPPoolAllowedUse @@ -4064,7 +3614,8 @@ _Appears in:_ | `istiod` _[IstiodDeployment](#istioddeployment)_ | (Optional) IstiodDeployment defines the resource requirements and node selector for the Istio deployment. | | `istioCNI` _[IstioCNIDaemonset](#istiocnidaemonset)_ | (Optional) IstioCNIDaemonset defines the resource requirements for the Istio CNI plugin. | | `ztunnel` _[ZTunnelDaemonset](#ztunneldaemonset)_ | (Optional) ZTunnelDaemonset defines the resource requirements for the ZTunnelDaemonset component. | -| `dscpMark` _DSCP_ | (Optional) DSCPMark define the value of the DSCP mark done by Felix and recognised by Istio CNI for Transparent NetworkPolicies. | +| `waypointLogging` _[LogCollectionStatusType](#logcollectionstatustype)_ | (Optional) WaypointLogging controls whether L7 logging is enabled on every Gateway using the istio-waypoint GatewayClass. When Enabled (the default), the operator injects an l7-collector sidecar into each waypoint pod via class-level defaults. When Disabled, no sidecar is injected and the associated EnvoyFilters are not created. Allowed values are Enabled or Disabled. | +| `dscpMark` _[DSCP](#dscp)_ | (Optional) DSCPMark define the value of the DSCP mark done by Felix and recognised by Istio CNI for Transparent NetworkPolicies. | ### IstioStatus @@ -4511,6 +4062,7 @@ _Validation:_ _Appears in:_ +- [IstioSpec](#istiospec) - [LogCollectionSpec](#logcollectionspec) | Value | Description | @@ -5013,7 +4565,7 @@ _Appears in:_ | --- | --- | | `externalPrometheus` _[ExternalPrometheus](#externalprometheus)_ | ExternalPrometheus optionally configures integration with an external Prometheus for scraping Calico metrics. When specified, the operator will render resources in the defined namespace. This option can be useful for configuring scraping from git-ops tools without the need of post-installation steps. | | `prometheus` _[Prometheus](#prometheus)_ | (Optional) Prometheus is the configuration for the Prometheus. | -| `alertmanager` _[Alertmanager](#alertmanager)_ | (Optional) Alertmanager is the configuration for the Alertmanager. | +| `alertManager` _[Alertmanager](#alertmanager)_ | (Optional) Alertmanager is the configuration for the Alertmanager. | ### MonitorStatus @@ -5644,11 +5196,6 @@ _Appears in:_ - [CalicoNodeWindowsDaemonSetContainer](#caliconodewindowsdaemonsetcontainer) - [CalicoWebhooksDeploymentContainer](#calicowebhooksdeploymentcontainer) - [CalicoWindowsUpgradeDaemonSetContainer](#calicowindowsupgradedaemonsetcontainer) -- [ComplianceBenchmarkerDaemonSetContainer](#compliancebenchmarkerdaemonsetcontainer) -- [ComplianceControllerDeploymentContainer](#compliancecontrollerdeploymentcontainer) -- [ComplianceReporterPodTemplateContainer](#compliancereporterpodtemplatecontainer) -- [ComplianceServerDeploymentContainer](#complianceserverdeploymentcontainer) -- [ComplianceSnapshotterDeploymentContainer](#compliancesnapshotterdeploymentcontainer) - [DashboardsJobContainer](#dashboardsjobcontainer) - [DexDeploymentContainer](#dexdeploymentcontainer) - [ECKOperatorStatefulSetContainer](#eckoperatorstatefulsetcontainer) @@ -6084,7 +5631,7 @@ _Appears in:_ _Appears in:_ -- TLSPassThroughRoute +- [TLSPassThroughRoute](#tlspassthroughroute) | Field | Description | | --- | --- | @@ -6102,7 +5649,7 @@ _Appears in:_ _Appears in:_ -- TLSTerminatedRoute +- [TLSTerminatedRoute](#tlsterminatedroute) | Field | Description | | --- | --- | @@ -6351,6 +5898,39 @@ _Appears in:_ | `nameAttribute` _string_ | (Optional) A mapping of the attribute that is used as the username. This attribute can be used to apply RBAC to a user.
Default: uid | +### WAFExtensionSpec + + + +WAFExtensionSpec configures the WAF Gateway API add-on. + +_Appears in:_ +- [GatewayAPIExtensions](#gatewayapiextensions) + +| Field | Description | +| --- | --- | +| `state` _[WAFExtensionState](#wafextensionstate)_ | (Optional) State turns the WAF Gateway API add-on on or off. Default (nil or "Disabled") means the operator does not render the WAF surface on calico-kube-controllers. Set to "Enabled" to opt in. | + + +### WAFExtensionState + +_Underlying type:_ _string_ + +WAFExtensionState is the on/off enum for the WAF Gateway API add-on. + +_Validation:_ +- Enum: [Enabled Disabled] + + +_Appears in:_ +- [WAFExtensionSpec](#wafextensionspec) + +| Value | Description | +| --- | --- | +| `Enabled` | | +| `Disabled` | | + + ### WAFStatusType _Underlying type:_ _string_ diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_crd-ref-docs/config.yaml b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_crd-ref-docs/config.yaml index fd123b9c48..e7b0103bba 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_crd-ref-docs/config.yaml +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_crd-ref-docs/config.yaml @@ -3,6 +3,7 @@ processor: ignoreTypes: - "List$" - "Tenant*" + - "^Compliance" # RE2 regular expressions describing type fields that should be excluded from the generated documentation. ignoreFields: - "TypeMeta$" diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/helm_customization.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/helm_customization.mdx index f9595a106e..92d4e6064f 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/helm_customization.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/helm_customization.mdx @@ -8,7 +8,6 @@ You can customize the following resources and settings during $[prodname] Helm-b - [Installation](api.mdx#installationspec) - [Api server](api.mdx#apiserverspec) -- [Compliance](api.mdx#compliancespec) - [Intrusion detection](api.mdx#intrusiondetectionspec) - [Log collector](api.mdx#logcollectorspec) - [Log storage](api.mdx#logstoragespec) @@ -63,10 +62,6 @@ monitor: enabled: true -compliance: - enabled: true - - policyRecommendation: enabled: true @@ -120,8 +115,6 @@ You can define pod affinity for the following Tigera components. Update the appr - calico-apiserver: through ApiServer resource - calico-nodes: through CalicoNodeDaemonSet property in the Installation resource - calico-kube-controllers: through CalicoKubeControllersDeployment property in the Installation resource -- compliance deployment pods (compliance-snapshotter, compliance-server, compliance-controller, compliance-benchmarker, -compliance-scaleloader, compliance-reporter): through Compliance resource - elasticsearch pods: through LogStorage resource - for more info on this option please checkout [Advanced Node Scheduling](../../operations/logstorage/advanced-node-scheduling.mdx) ### Encryption using WireGuard diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/tigerastatus.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/tigerastatus.mdx index cf68a274d2..aaef840282 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/tigerastatus.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/tigerastatus.mdx @@ -11,7 +11,6 @@ Installing $[prodname] on your Kubernetes cluster is managed by the Tigera Opera - authentication - calico - calico-windows -- compliance - egressgateway - intrusion detection - log-collector @@ -40,7 +39,7 @@ For detailed output (including messages and further details on any non-functioni ## Log storage -Log storage provides persistent storage for $[prodname] Elasticsearch logs (flow, dns, l7, bgp, audit, etc.), and compliance reports. +Log storage provides persistent storage for $[prodname] Elasticsearch logs (flow, dns, l7, bgp, audit, etc.). To check log storage status, run the following command: diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/cis-benchmark.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/cis-benchmark.mdx deleted file mode 100644 index 92184ddb25..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/cis-benchmark.mdx +++ /dev/null @@ -1,71 +0,0 @@ ---- -description: Reference for the CIS benchmark compliance report in Calico Enterprise that audits Kubernetes nodes against CIS recommendations. ---- - -# CIS benchmark report - -To create a CIS benchmark report, create a `GlobalReport` with the `reportType` set to `cis-benchmark`. - -The following sample command uses a GlobalReport to create a daily CIS benchmark report that run on all the nodes. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-benchmark-report -spec: - reportType: cis-benchmark - schedule: 0 0 * * * -EOF -``` - -## OpenShift - -While there is no extra setup configuration required by the user to generate a benchmark report for OpenShift, the result sets will be different than a report generated for regular Kubernetes clusters. Use the [OpenShift Container Platform Security Guide](https://static.open-scap.org/ssg-guides/ssg-ocp4-guide-index.html) to cross-reference the benchmark results. - -## Downloadable reports - -## total-summary.csv - -A textual representation of the dashboard. - -| Heading | Description | Format | -| ---------------------- | ----------------------------------------------------------------- | -------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval start time. | RFC3339 string | -| type | The type of benchmark report | string | -| hiPercentageThreshold | The percentage of passing tests required to rate a node as high | int | -| medPercentageThreshold | The percentage of passing tests required to rate a node as medium | int | -| hiNodeCount | The number of nodes rated as high | int | -| medNodeCount | The number of nodes rated as medium | int | -| lowNodeCount | The number of nodes rated as low | int | - -## node-summary.csv - -A .csv file of test result summaries per node. - -| Heading | Description | Format | -| ------------ | ---------------------------------------------------------------------------------- | ------ | -| node | The name of the node. | string | -| version | The version of the platform. | string | -| status | The rating of the node based on percentage of tests passing. | string | -| testsPassing | The number of tests passing. | int | -| testsFailing | The number of tests failing. | int | -| testsUnknown | The number of tests whose results are undetermined due to automation restrictions. | int | -| testsTotal | The total number of tests executed. | int | - -### failed-tests.csv - -A .csv file of tests that have failed. - -| Heading | Description | Format | -| --------- | -------------------------------------------------------------------------------------- | ------ | -| nodeName | Node where the test is executed. | string | -| testIndex | Index of the test on the Kubernetes CIS benchmark. | string | -| status | Test results: PASS, FAIL, INFO. | string | -| scored | Indicates whether the Kubernetes CIS benchmark counts this test towards their scoring. | string | - -### all-tests.csv - -A .csv file with tests that were executed on all nodes. Format remains the same as above. diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/index.mdx deleted file mode 100644 index deb390a14f..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/index.mdx +++ /dev/null @@ -1,11 +0,0 @@ ---- -description: Reference index for compliance report types available with Calico Enterprise covering inventory, network access, policy audit, and CIS benchmark. -hide_table_of_contents: true ---- - -# Compliance reports (deprecated) - -import DocCardList from '@theme/DocCardList'; -import { useCurrentSidebarCategory } from '@docusaurus/theme-common'; - - diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/inventory.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/inventory.mdx deleted file mode 100644 index 4e2585393d..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/inventory.mdx +++ /dev/null @@ -1,86 +0,0 @@ ---- -description: Reference for the inventory compliance report in Calico Enterprise that catalogs endpoints, namespaces, and policies in scope at report time. ---- - -# Inventory report - -To create an Inventory report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `inventory`. - -The following sample command creates a GlobalReport that results in a daily inventory report for -endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-inventory-report - labels: - deployment: production -spec: - reportType: inventory - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ----------------------------- | ----------------------------------------------------------------------------------------------------------- | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| endpointsNumInScope | The number of enumerated endpoints that are in-scope according to the requested endpoint selection options. | number | -| endpointsNumIngressProtected | The number of in-scope endpoints that were always ingress protected during the report interval. | number | -| endpointsNumEgressProtected | The number of in-scope endpoints that were always egress protected during the report interval. | number | -| namespacesNumInScope | The number of namespaces containing in-scope endpoints. | number | -| namespacesNumIngressProtected | The number of namespaces whose in-scope endpoints were always ingress protected during the report interval. | number | -| namespacesNumEgressProtected | The number of namespaces whose in-scope endpoints were always egress protected during the report interval. | number | -| serviceAccountsNumInScope | The number of service accounts associated with in-scope endpoints. | number | - -### endpoints.csv - -An endpoints CSV file that includes per-endpoint information. - -| Heading | Description | Format | -| ---------------- | --------------------------------------------------------------------------------------------- | ----------------------------------- | -| endpoint | The name of the endpoint. | string | -| ingressProtected | Whether the endpoint was always ingress protected during the report interval. | bool | -| egressProtected | Whether the endpoint was always egress protected during the report interval. | bool | -| envoyEnabled | Whether the endpoint was always Envoy enabled during the report interval. | bool | -| appliedPolicies | The full set of policies that applied to the endpoint at any time during the report interval. | ";" separated list of policy names | -| services | The full set of services that included this endpoint at any time during the report interval. | ";" separated list of service names | - -### namespaces.csv - -A namespaces CSV file that includes per-namespace information. - -| Heading | Description | Format | -| ---------------- | ------------------------------------------------------------------------------------------------------------- | ------ | -| namespace | The name of the namespace. | string | -| ingressProtected | Whether all in-scope endpoints within the namespace were always ingress protected during the report interval. | bool | -| egressProtected | Whether all in-scope endpoints within the namespace were always egress protected during the report interval. | bool | -| envoyEnabled | Whether all in-scope endpoints within the namespace were always Envoy enabled during the report interval. | bool | - -### services.csv - -A services CSV file that includes per-service information. - -| Heading | Description | Format | -| ---------------- | ---------------------------------------------------------------------------------------------------------------- | ------ | -| service | The name of the service. | string | -| ingressProtected | Whether all in-scope endpoints that are in the service were always ingress protected during the report interval. | bool | -| envoyEnabled | Whether all in-scope endpoints that are in the service were always Envoy enabled during the report interval. | bool | diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/network-access.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/network-access.mdx deleted file mode 100644 index e01798e591..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/network-access.mdx +++ /dev/null @@ -1,92 +0,0 @@ ---- -description: Reference for the network access compliance report in Calico Enterprise that summarizes which endpoints could communicate based on policy. ---- - -# Network Access report - -To create an Inventory report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `network-access`. - -The following sample command creates a GlobalReport that results in a daily network access report for -endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-network-access-report - labels: - deployment: production -spec: - reportType: network-access - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -:::note - -There is a known issue that audit logs do not contain deletion events for resources that were -deleted implicitly as part of a namespace deletion event. Currently, this means policies and pods that have been -deleted in this way may still appear in the reports that cover any period within the next day. - -::: - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| endpointsNumIngressProtected | The number of in-scope endpoints that were always ingress protected during the report interval. | number | -| endpointsNumEgressProtected | The number of in-scope endpoints that were always egress protected during the report interval. | number | -| endpointsNumIngressUnprotected | The number of in-scope endpoints that were ingress unprotected at any point during the report interval. | number | -| endpointsNumEgressUnprotected | The number of in-scope endpoints that were egress unprotected at any point during the report interval. | number | -| endpointsNumIngressFromInternet | The number of in-scope endpoints that allowed ingress traffic from the public internet at any point during the report interval. | number | -| endpointsNumEgressToInternet | The number of in-scope endpoints that allowed egress traffic to the public internet at any point during the report interval. | number | -| endpointsNumIngressFromOtherNamespace | The number of in-scope endpoints that allowed ingress traffic from another namespace at any point during the report interval. | number | -| endpointsNumEgressToOtherNamespace | The number of in-scope endpoints that allowed egress traffic to another namespace at any point during the report interval. | number | -| endpointsNumEnvoyEnabled | The number of in-scope endpoints that were always Envoy enabled during the report interval. | number | - -### endpoints.csv - -An endpoints CSV file that includes per-endpoint information. - -| Heading | Description | Format | -| ------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------- | -| endpoint | The name of the endpoint. | string | -| ingressProtected | Whether the endpoint was always ingress protected during the report interval. | bool | -| egressProtected | Whether the endpoint was always egress protected during the report interval. | bool | -| ingressFromInternet | Whether the endpoint allowed ingress traffic from the public internet at any point during the report interval. | number | -| egressToInternet | Whether the endpoint allowed egress traffic to the public internet at any point during the report interval. | number | -| ingressFromOtherNamespace | Whether the endpoint allowed ingress traffic from another namespace at any point during the report interval. | number | -| egressToOtherNamespace | Whether the endpoint allowed egress traffic to another namespace at any point during the report interval. | number | -| envoyEnabled | Whether the endpoint was always Envoy enabled during the report interval. | bool | -| appliedPolicies | The full set of policies that applied to the endpoint at any time during the report interval. | ";" separated list of policy names | -| services | The full set of services that included this endpoint at any time during the report interval. | ";" separated list of service names | -| trafficAggregationPrefix\* | The flow log aggregation prefix. | string | -| endpointsGeneratingTrafficToThisEndpoint\* | The set of endpoints that were generating traffic to this endpoint. | ";" separated list of service names | -| endpointsReceivingTrafficFromThisEndpoint\* | The set of endpoints that this endpoint is generating traffic to. | ";" separated list of service names | - -\* Traffic data is determined from flow logs. By default, $[prodname] aggregates flow logs so that flows to -and from pods in the same replica set are summarized if the flows are accepted. (Denied flows are not aggregated this -way by default). This means that the per-endpoint traffic details do not refer specifically to that endpoint, but -rather the set of endpoints specified by the trafficAggregationPrefix. - -If you want per-endpoint detail you should turn down the level of aggregation. To do so, -set the value of `flowLogsFileAggregationKindForAllowed` to 1 using a [FelixConfiguration][felixconfig] - -[felixconfig]: ../felixconfig.mdx diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/overview.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/overview.mdx deleted file mode 100644 index ec0cafe0e5..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/overview.mdx +++ /dev/null @@ -1,102 +0,0 @@ ---- -description: Reference overview of compliance reporting in Calico Enterprise covering schedules, report scope, and the GlobalReport resource. ---- - -# Compliance reports (deprecated) - -The $[prodname] compliance reporting feature provides the following compliance reports: - -- [Inventory](inventory.mdx) -- [Network Access](network-access.mdx) -- [Policy Audit](policy-audit.mdx) -- [CIS Benchmark](cis-benchmark.mdx) - -Create a [`GlobalReport`](../globalreport.mdx) resource to automatically schedule report generation, and specify the report scope (resources to include in the report). - -## Concepts - -### In-scope asset - -An asset (Pod or HostEndpoint) is flagged as in-scope by endpoint labels, namespace and/or namespace labels, and service -account and/or service account labels. - -_How this applies to the report_: -The report includes all resources that were in-scope at any point during the report interval. The resource is included -when it is first flagged as in-scope according to the configured label selector and name selections. The resource is -included even if the resource is deleted or goes out-of-scope before the end of the report interval. - -### Ingress protected - -An endpoint is ingress protected if it has at least one Ingress policy that is applied to it. - -A service is ingress protected if all of the in-scope endpoints within that service are ingress protected. - -A namespace is ingress protected if all of the in-scope endpoints within that namespace are ingress protected. - -_How this applies to the report_: -An endpoint is ingress protected only if it was ingress protected throughout the entire report interval. - -### Egress protected - -As per ingress, but with egress policy rules. Note that egress statistics are not obtained for services. - -### Allows ingress traffic from another namespace - -An endpoint is flagged as allowing ingress traffic from another namespace if it has one or more policies that apply to -it with an ingress allow rule that: - -- has an explicit namespace selector configured, or -- has no source selector or source CIDR configured, or -- (for GlobalNetworkPolicy) has no source CIDR. - -A service is flagged as allowing ingress traffic from another namespace if any of the in-scope endpoints within that -service are flagged. - -A namespace is flagged as allowing ingress traffic from another namespace if all of the in-scope endpoints within that -namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as allowing ingress traffic from another namespace if it was flagged at any time during the -report interval. - -### Allows egress traffic to another namespace - -As per ingress, but with egress policy rules and destination selector/CIDR. Note that egress statistics are not obtained -for services. - -### Allows ingress traffic from the internet - -An endpoint is flagged as allowing ingress traffic from the internet if it has one or more policies that apply to it -with an ingress allow rule that: - -- has no source selector or source CIDR configured, or -- has a source CIDR in the non-private IP ranges and has no source selector, or -- has a source selector that matches one or more NetworkSets that contain at least one non-private IP. - -A service is flagged as allowing ingress traffic from the internet if any of the in-scope endpoints within that service -are flagged. - -A namespace is flagged as allowing ingress traffic from the internet if all of the in-scope endpoints within that -namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as allowing ingress traffic from the internet if it was flagged as such at any time during the -report interval. - -### Allows egress traffic to the internet - -As per ingress, but with egress policy rules and destination selector/CIDR. Note that egress statistics are not obtained -for services. - -### Envoy enabled - -An endpoint is flagged as Envoy Enabled if the associated Pod Spec and Annotations indicate that an Istio init and main -container are deployed in the Pod. Provided Istio is appropriately configured on the cluster, this can be extrapolated -to be indication of whether mTLS is enabled for the endpoint. - -A service is flagged as Envoy enabled if all of the in-scope endpoints within that service are flagged. - -A namespace is flagged as Envoy enabled if all of the in-scope endpoints within that namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as Envoy enabled if it was flagged as such throughout the entire report interval. diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/policy-audit.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/policy-audit.mdx deleted file mode 100644 index 67d19a5b84..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/policy-audit.mdx +++ /dev/null @@ -1,56 +0,0 @@ ---- -description: Reference for the policy audit compliance report in Calico Enterprise that records changes to network policies during the report period. ---- - -# Policy audit report - -To create a Policy Audit report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `policy-audit`. - -The following sample command creates a GlobalReport that results in a daily policy audit report for -policies that are applied to endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-policy-audit-report - labels: - deployment: production -spec: - reportType: policy-audit - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ----------------------- | ------------------------------------------------------------------------------------------------------ | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| numCreatedPolicies | The number of policies that apply to in-scope endpoints that were created during the report interval. | number | -| numModifiedPolicies | The number of policies that apply to in-scope endpoints that were modified during the report interval. | number | -| numDeletedPolicies | The number of policies that apply to in-scope endpoints that were deleted during the report interval. | number | - -### events.json - -Events formatted in JSON. - -### events.yaml - -Events formatted in YAML. diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/globalreport.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/globalreport.mdx deleted file mode 100644 index 16e2c70171..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/globalreport.mdx +++ /dev/null @@ -1,149 +0,0 @@ ---- -description: Reference for the GlobalReport resource in Calico Enterprise that schedules compliance reports against cluster network and policy state. ---- - -# Global report - -A global report resource is a configuration for generating compliance reports. A global report configuration in $[prodname] lets you: - -- Specify report contents, frequency, and data filtering -- Specify the node(s) on which to run the report generation jobs -- Enable/disable creation of new jobs for generating the report - -For `kubectl` [commands](https://kubernetes.io/docs/reference/kubectl/overview/), the following case-insensitive aliases -may be used to specify the resource type on the CLI: -`globalreport.projectcalico.org`, `globalreports.projectcalico.org` and abbreviations such as -`globalreport.p` and `globalreports.p`. - -## Sample YAML - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: weekly-full-inventory -spec: - reportType: inventory - schedule: 0 0 * * 0 - jobNodeSelector: - nodetype: infrastructure - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: hourly-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - names: ['payable', 'collections', 'payroll'] - schedule: 0 * * * * - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: monthly-widgets-controller-tigera-policy-audit -spec: - reportType: policy-audit - schedule: 0 0 1 * * - endpoints: - serviceAccounts: - names: ['controller'] - namespaces: - names: ['widgets'] - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-benchmark -spec: - reportType: cis-benchmark - schedule: 0 0 * * * - cis: - resultsFilters: - - benchmarkSelection: { kubernetesVersion: '1.13' } - exclude: ['1.1.4', '1.2.5'] -``` - -## GlobalReport Definition - -### Metadata - -| Field | Description | Accepted Values | Schema | -| ------ | ---------------------------------------- | ------------------------------------------------ | ------ | -| name | The name of this report. | Lower-case alphanumeric with optional `-` or `.` | string | -| labels | A set of labels to apply to this report. | | map | - -### Spec - -| Field | Description | Required | Accepted Values | Schema | -| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------- | -| reportType | The type of report to produce. This field controls the content of the report - see the links for each type for more details. | Yes | [cis‑benchmark](compliance-reports/cis-benchmark.mdx), [inventory](compliance-reports/inventory.mdx), [network‑access](compliance-reports/network-access.mdx), [policy‑audit](compliance-reports/policy-audit.mdx) | string | -| endpoints | Specify which endpoints are in scope. If omitted, selects everything. | | | [EndpointsSelection](#endpointsselection) | -| schedule | Configure report frequency by specifying start and end time in [cron-format][cron-format]. Reports are started 30 minutes (configurable) after the scheduled value to allow enough time for data archival. A maximum limit of 12 schedules per hour is enforced (an average of one report every 5 minutes). | Yes | | string | -| jobNodeSelector | Specify the node(s) for scheduling the report jobs using selectors. | | | map | -| suspend | Disable future scheduled report jobs. In-flight reports are not affected. | | | bool | -| cis | Parameters related to generating a CIS benchmark report. | | | [CISBenchmarkParams](#cisbenchmarkparams) | - -### EndpointsSelection - -| Field | Description | Schema | -| --------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------- | -| selector | Endpoint label selector to restrict endpoint selection. | string | -| namespaces | Namespace name and label selector to restrict endpoints by selected namespaces. | [NamesAndLabelsMatch](#namesandlabelsmatch) | -| serviceAccounts | Service account name and label selector to restrict endpoints by selected service accounts. | [NamesAndLabelsMatch](#namesandlabelsmatch) | - -### CISBenchmarkParams - -| Fields | Description | Required | Schema | -| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----------------------------------------- | -| highThreshold | Integer percentage value that determines the lower limit of passing tests to consider a node as healthy. Default: 100 | No | int | -| medThreshold | Integer percentage value that determines the lower limit of passing tests to consider a node as unhealthy. Default: 50 | No | int | -| includeUnscoredTests | Boolean value that when false, applies a filter to exclude tests that are marked as “Unscored” by the CIS benchmark standard. If true, the tests will be included in the report. Default: false | No | bool | -| numFailedTests | Integer value that sets the number of tests to display in the Top-failed Tests section of the CIS benchmark report. Default: 5 | No | int | -| resultsFilters | Specifies an include or exclude filter to apply on the test results that will appear on the report. | No | [CISBenchmarkFilter](#cisbenchmarkfilter) | - -### CISBenchmarkFilter - -| Fields | Description | Required | Schema | -| ------------------ | ---------------------------------------------------------------------------------------------- | -------- | ----------------------------------------------- | -| benchmarkSelection | Specify which set of benchmarks that this filter should apply to. Selects all benchmark types. | No | [CISBenchmarkSelection](#cisbenchmarkselection) | -| exclude | Specify which benchmark tests to exclude | No | array of strings | -| include | Specify which benchmark tests to include only (higher precedence than exclude) | No | array of strings | - -### CISBenchmarkSelection - -| Fields | Description | Required | Schema | -| ----------------- | -------------------------------------- | -------- | ------ | -| kubernetesVersion | Specifies a version of the benchmarks. | Yes | string | - -### NamesAndLabelsMatch - -| Field | Description | Schema | -| -------- | ------------------------------------ | ------ | -| names | Set of resource names. | list | -| selector | Selects a set of resources by label. | string | - -Use the `NamesAndLabelsMatch`to limit the scope of endpoints. If both `names` -and `selector` are specified, the resource is identified using label _AND_ name -match. - -:::note - -To use the $[prodname] compliance reporting feature, you must ensure all required resource types -are being audited and the logs archived in Elasticsearch. You must explicitly configure the [Kubernetes API Server](../../observability/kube-audit.mdx) - to send audit logs for Kubernetes-owned resources -to Elasticsearch. - -::: - -## Supported operations - -| Datastore type | Create/Delete | Update | Get/List | Notes | -| --------------------- | ------------- | ------ | -------- | ----- | -| Kubernetes API server | Yes | Yes | Yes | | - -[cron-format]: https://en.wikipedia.org/wiki/Cron diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/overview.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/overview.mdx index a70cdfda35..69e8943535 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/overview.mdx @@ -54,7 +54,6 @@ The following resources are supported: - [GlobalAlert](globalalert.mdx) - [GlobalNetworkPolicy](globalnetworkpolicy.mdx) - [GlobalNetworkSet](globalnetworkset.mdx) -- [GlobalReport](globalreport.mdx) - [GlobalThreatFeed](globalthreatfeed.mdx) - [HostEndpoint](hostendpoint.mdx) - [IPPool](ippool.mdx) diff --git a/calico-enterprise_versioned_docs/version-3.24-1/release-notes/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/release-notes/index.mdx index cdf3ca79ea..7cfc972a23 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/release-notes/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/release-notes/index.mdx @@ -56,24 +56,35 @@ For more information, see [L2 reachability for pods and services without BGP](.. ### Enhancements -* **Enable Calico Ingress Gateway during Helm installation:** - You can now enable Calico Ingress Gateway when you install $[prodname] with Helm, by setting `gatewayAPI.enabled: true` in your `values.yaml`. +* You can now enable Calico Ingress Gateway when you install $[prodname] with Helm, by setting `gatewayAPI.enabled: true` in your `values.yaml`. For more information, see the [Helm installation reference](../reference/installation/helm_customization.mdx). -- New installs default to v3 CRD mode: `projectcalico.org/v3` resources are served directly by CRDs, with no aggregation API server. Existing and upgraded clusters are unaffected. To install with the aggregation API server instead, apply the v1 CRDs before installing the operator. v3 CRD mode requires Kubernetes 1.32 or later. See [Native v3 CRDs](../operations/native-v3-crds.mdx). ### Deprecated and removed features -- $[prodname] is moving the `projectcalico.org/v3` API from the aggregated API server to native Kubernetes CRDs. Both mechanisms will be supported until native v3 CRDs are compatible with all supported platforms, after which the aggregated API server will be removed. +* The compliance reporting feature has been removed from the $[prodname] web console. +* $[prodname] is moving the `projectcalico.org/v3` API from the aggregated API server to native Kubernetes CRDs. + Both mechanisms will be supported until native v3 CRDs are compatible with all supported platforms, after which the aggregated API server will be removed. -## Technology Preview features +{/* ## Technology Preview features */} -## Upgrade notes +{/* ### Known issues */} -{/* Add breaking changes and required upgrade steps here, one subsection per feature. */} +## Upgrading + +Before upgrading to Calico Enterprise 3.24, review [Upgrade notes](#upgrade-notes), [Deprecated and removed features](#deprecated-and-removed-features), and Known issues. + +### Upgrade from a previous minor -### Calico Ingress Gateway +Calico Enterprise 3.24 supports a direct upgrade from versions 3.23 and 3.22. +To upgrade from an earlier version, plan an intermediate upgrade. -:::warning[Breaking change] +For upgrade instructions, see [Upgrade Calico Enterprise](../getting-started/upgrading/upgrading-enterprise/index.mdx). + +### Upgrade notes + +{/* Add breaking changes and required upgrade steps here, one subsection per feature. */} + +#### Breaking changes for Calico Ingress Gateway Calico Ingress Gateway now runs each gateway's proxy in the same namespace as its `Gateway`, and the controller moves to `calico-system`. On upgrade, existing proxies move out of the `tigera-gateway` namespace into each Gateway's namespace, so anything pinned to `tigera-gateway` — network policy, monitoring, RBAC, and external DNS — must move with them. @@ -81,17 +92,15 @@ Merged gateways (`mergeGateways: true`) are no longer supported, so each gateway Migrate in this order: -1. **Before you upgrade**, if you run a global default deny policy, create a network policy in each Gateway's namespace that allows the proxy pods, so they can start as soon as they move. For the policy, see [Create an ingress gateway](../networking/ingress-gateway/create-ingress-gateway.mdx). +1. Before you upgrade, if you run a global default deny policy, create a network policy in each Gateway's namespace that allows the proxy pods, so they can start as soon as they move. For the policy, see [Create an ingress gateway](../networking/ingress-gateway/create-ingress-gateway.mdx). 2. Upgrade $[prodname]. 3. After the upgrade, re-point monitoring, RBAC, and external DNS from `tigera-gateway` to each Gateway's namespace. If you used merged gateways, plan for one load balancer, DNS record, and certificate per gateway. -::: - ## Release details ### Calico Enterprise 3.24.0-1.0 (early preview) -January xx, 2024 +July 31, 2026 Calico Enterprise 3.24.0-1.0 is now available as an early preview release. This release is for previewing and testing purposes only. diff --git a/calico-enterprise_versioned_docs/version-3.24-1/releases.json b/calico-enterprise_versioned_docs/version-3.24-1/releases.json index 0037f01fc4..da3b696d58 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/releases.json +++ b/calico-enterprise_versioned_docs/version-3.24-1/releases.json @@ -2,12 +2,12 @@ { "title": "v3.24.0-1.0", "tigera-operator": { - "version": "v3.24.0-1.0", + "version": "v1.43.0", "image": "tigera/operator", "registry": "quay.io" }, "calico": { - "minor_version": "v3.33", + "minor_version": "v3.32", "archive_path": "archive" }, "components": { @@ -28,19 +28,22 @@ "image": "tigera/compliance-benchmarker" }, "coreos-alertmanager": { - "version": "v0.33.1" + "version": "v0.33.0" }, "coreos-config-reloader": { - "version": "v0.92.1" + "version": "v0.91.0" }, "coreos-dex": { "version": "v2.45.1" }, + "coreos-fluentd": { + "version": "1.19.3" + }, "coreos-prometheus": { "version": "v3.12.0" }, "coreos-prometheus-operator": { - "version": "v0.92.1" + "version": "v0.91.0" }, "deep-packet-inspection": { "version": "v3.24.0-1.0", @@ -69,7 +72,7 @@ }, "elastic-tsee-installer": { "version": "v3.24.0-1.0", - "image": "tigera/intrusion-detection-job-installer" + "image": "intrusion-detection-job-installer" }, "elasticsearch": { "version": "v3.24.0-1.0", @@ -77,7 +80,7 @@ }, "elasticsearch-operator": { "version": "v3.24.0-1.0", - "image": "tigera/eck-operator" + "image": "eck-operator" }, "envoy": { "version": "v3.24.0-1.0", @@ -87,25 +90,25 @@ "version": "v3.24.0-1.0", "image": "tigera/firewall-integration" }, - "fluent-bit": { + "fluentd": { "version": "v3.24.0-1.0", - "image": "tigera/fluent-bit" + "image": "tigera/fluentd" }, - "fluent-bit-windows": { + "fluentd-windows": { "version": "v3.24.0-1.0", - "image": "tigera/fluent-bit-windows" + "image": "tigera/fluentd-windows" }, "gateway-api-envoy-gateway": { "version": "v3.24.0-1.0", - "image": "tigera/envoy-gateway" + "image": "envoy-gateway" }, "gateway-api-envoy-proxy": { "version": "v3.24.0-1.0", - "image": "tigera/envoy-proxy" + "image": "envoy-proxy" }, "gateway-api-envoy-ratelimit": { "version": "v3.24.0-1.0", - "image": "tigera/envoy-ratelimit" + "image": "envoy-ratelimit" }, "gateway-l7-collector": { "version": "v3.24.0-1.0", @@ -165,14 +168,14 @@ }, "tigera-cni-windows": { "version": "v3.24.0-1.0", - "image": "tigera/cni-windows" + "image": "cni-windows" }, "tigera-third-party-cni-plugins": { "version": "v3.24.0-1.0", - "image": "tigera/third-party-cni-plugins" + "image": "third-party-cni-plugins" }, "upstream-istio": { - "version": "1.29.5" + "version": "1.29.2" } } } diff --git a/calico-enterprise_versioned_docs/version-3.24-1/variables.js b/calico-enterprise_versioned_docs/version-3.24-1/variables.js index e865354268..916921f426 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/variables.js +++ b/calico-enterprise_versioned_docs/version-3.24-1/variables.js @@ -21,7 +21,7 @@ const variables = { noderunning: 'calico-node', rootDirWindows: 'C:\\TigeraCalico', registry: 'quay.io/', - envoyVersion: '1.8.0', + envoyVersion: '1.8.2', chart_version_name: 'v3.24.0-1.0', tigeraOperator: releases[0]['tigera-operator'], dikastesVersion: releases[0].components.dikastes.version, diff --git a/calico-enterprise_versioned_sidebars/version-3.24-1-sidebars.json b/calico-enterprise_versioned_sidebars/version-3.24-1-sidebars.json index bf09a1148b..5ac9289392 100644 --- a/calico-enterprise_versioned_sidebars/version-3.24-1-sidebars.json +++ b/calico-enterprise_versioned_sidebars/version-3.24-1-sidebars.json @@ -646,7 +646,7 @@ }, { "type": "category", - "label": "Compliance and security", + "label": "Security", "link": { "type": "doc", "id": "compliance/index" @@ -661,9 +661,6 @@ "compliance/istio/deploy-istio-ambient" ] }, - "compliance/enable-compliance", - "compliance/overview", - "compliance/compliance-reports-cis", "compliance/encrypt-cluster-pod-traffic", "compliance/configure-http-proxy" ] @@ -1000,21 +997,6 @@ "reference/resources/bgpfilter", "reference/resources/blockaffinity", "reference/resources/caliconodestatus", - { - "type": "category", - "label": "Compliance reports", - "link": { - "type": "doc", - "id": "reference/resources/compliance-reports/index" - }, - "items": [ - "reference/resources/compliance-reports/overview", - "reference/resources/compliance-reports/inventory", - "reference/resources/compliance-reports/network-access", - "reference/resources/compliance-reports/policy-audit", - "reference/resources/compliance-reports/cis-benchmark" - ] - }, "reference/resources/deeppacketinspection", "reference/resources/earlynetworkconfiguration", "reference/resources/egressgatewaypolicy", @@ -1023,7 +1005,6 @@ "reference/resources/globalalert", "reference/resources/globalnetworkpolicy", "reference/resources/globalnetworkset", - "reference/resources/globalreport", "reference/resources/globalthreatfeed", "reference/resources/hostendpoint", "reference/resources/ippool", diff --git a/docusaurus.config.js b/docusaurus.config.js index af82a25e09..ec4dc5bfe4 100644 --- a/docusaurus.config.js +++ b/docusaurus.config.js @@ -462,7 +462,7 @@ export default async function createAsyncConfig() { path: 'calico-enterprise', routeBasePath: 'calico-enterprise', editCurrentVersion: true, - onlyIncludeVersions: [...nextVersion, '3.23-2', '3.22-2', '3.21-2'], + onlyIncludeVersions: [...nextVersion, '3.24-1', '3.23-2', '3.22-2', '3.21-2'], lastVersion: '3.23-2', versions: { current: { @@ -470,6 +470,11 @@ export default async function createAsyncConfig() { path: 'next', banner: 'unreleased', }, + '3.24-1': { + label: '3.24 (early preview)', + path: '3.24', + banner: 'unreleased', + }, '3.23-2': { label: '3.23 (latest)', path: 'latest', diff --git a/sidebars-calico-enterprise.js b/sidebars-calico-enterprise.js index 8dd7e80742..06d2a9331b 100644 --- a/sidebars-calico-enterprise.js +++ b/sidebars-calico-enterprise.js @@ -503,7 +503,7 @@ module.exports = { }, { type: 'category', - label: 'Compliance and security', + label: 'Security', link: { type: 'doc', id: 'compliance/index' }, items: [ { @@ -515,9 +515,6 @@ module.exports = { 'compliance/istio/deploy-istio-ambient', ], }, - 'compliance/enable-compliance', - 'compliance/overview', - 'compliance/compliance-reports-cis', 'compliance/encrypt-cluster-pod-traffic', 'compliance/configure-http-proxy', ], @@ -768,18 +765,6 @@ module.exports = { 'reference/resources/bgpfilter', 'reference/resources/blockaffinity', 'reference/resources/caliconodestatus', - { - type: 'category', - label: 'Compliance reports', - link: { type: 'doc', id: 'reference/resources/compliance-reports/index' }, - items: [ - 'reference/resources/compliance-reports/overview', - 'reference/resources/compliance-reports/inventory', - 'reference/resources/compliance-reports/network-access', - 'reference/resources/compliance-reports/policy-audit', - 'reference/resources/compliance-reports/cis-benchmark', - ], - }, 'reference/resources/deeppacketinspection', 'reference/resources/earlynetworkconfiguration', 'reference/resources/egressgatewaypolicy', @@ -788,7 +773,6 @@ module.exports = { 'reference/resources/globalalert', 'reference/resources/globalnetworkpolicy', 'reference/resources/globalnetworkset', - 'reference/resources/globalreport', 'reference/resources/globalthreatfeed', 'reference/resources/hostendpoint', 'reference/resources/ippool',