Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
126 commits
Select commit Hold shift + click to select a range
aa43057
update integration to 1.1.1
ofiriro3 Feb 7, 2023
8163f42
Adding only elastic stack
ofiriro3 Feb 7, 2023
212965d
update working directory
ofiriro3 Feb 7, 2023
061b309
update working directory
ofiriro3 Feb 7, 2023
4bb7688
adding the ec provider
ofiriro3 Feb 7, 2023
050aeb7
Fixing gitignore files + adding github actions that uses the new bash…
ofiriro3 Feb 12, 2023
d6b9978
Moving scripts to the weekly directory
ofiriro3 Feb 12, 2023
b06001e
Updating executing permissions
ofiriro3 Feb 12, 2023
e615ee6
Update local variable to lower_case
ofiriro3 Feb 12, 2023
cf80da8
updating path
ofiriro3 Feb 12, 2023
bfc4c0a
Updating path
ofiriro3 Feb 12, 2023
4c18e6d
Fixing path
ofiriro3 Feb 12, 2023
5a78456
Updating to full path
ofiriro3 Feb 12, 2023
e3ad992
Updating to full path
ofiriro3 Feb 12, 2023
fc81e64
Updating CI to full path
ofiriro3 Feb 12, 2023
18fd270
using variable
ofiriro3 Feb 12, 2023
7c324e6
using variable
ofiriro3 Feb 12, 2023
bfe4eb3
flow without agent deployment
ofiriro3 Feb 12, 2023
f781ffb
Fixing integration
ofiriro3 Feb 12, 2023
2b6346a
Update CI to full E2E
ofiriro3 Feb 12, 2023
6c18d50
Fixing show manifest file step
ofiriro3 Feb 12, 2023
48050c6
update ci
ofiriro3 Feb 12, 2023
2e63a33
Deploy yaml file
ofiriro3 Feb 12, 2023
ae06992
Another try
ofiriro3 Feb 12, 2023
52b55ac
updating deployment file
ofiriro3 Feb 12, 2023
9adc67c
Remove image replacement
ofiriro3 Feb 12, 2023
a14ad1d
Remove secret echo to file
ofiriro3 Feb 13, 2023
1006b22
Trying to solve ssh issue
ofiriro3 Feb 13, 2023
d0b9bc7
Trying to solve ssh issue
ofiriro3 Feb 13, 2023
d71688f
Adding the entire flow
ofiriro3 Feb 13, 2023
4ab1da7
Comment out terraform
ofiriro3 Feb 13, 2023
e821839
Remove echo
ofiriro3 Feb 13, 2023
93ef663
Strict host checking false
ofiriro3 Feb 13, 2023
1c0e323
Trying to use package for copy the file
ofiriro3 Feb 13, 2023
b4ebb27
Remove working directory
ofiriro3 Feb 13, 2023
7c85402
Remove working directory
ofiriro3 Feb 13, 2023
8f99aee
Update scp use
ofiriro3 Feb 13, 2023
7987fcc
Update scp use
ofiriro3 Feb 13, 2023
fa40cdf
Fixing Ci
ofiriro3 Feb 13, 2023
8e5e4ae
Fixing Ci
ofiriro3 Feb 13, 2023
af3a2a5
Remove package
ofiriro3 Feb 13, 2023
39e9f59
Updating ssh command
ofiriro3 Feb 13, 2023
394bb47
Only echo the ssh key
ofiriro3 Feb 13, 2023
0ce7e07
Print only head
ofiriro3 Feb 13, 2023
6674a35
Comment out slack
ofiriro3 Feb 13, 2023
c94464f
adding ll
ofiriro3 Feb 13, 2023
3d784c1
adding ls
ofiriro3 Feb 13, 2023
52e28a1
adding ssh command
ofiriro3 Feb 13, 2023
cef93c4
Fixing script
ofiriro3 Feb 13, 2023
9b0896e
Changing permissions
ofiriro3 Feb 13, 2023
fcf35f2
change file to pem suffix
ofiriro3 Feb 13, 2023
15ef7ad
Fixing script
ofiriro3 Feb 13, 2023
bdf3bdc
Remove strict host
ofiriro3 Feb 13, 2023
f70e055
Adding StrictHost
ofiriro3 Feb 13, 2023
5ae401a
Adding public Ip
ofiriro3 Feb 13, 2023
c35f22e
Adding public Ip
ofiriro3 Feb 13, 2023
18d7eb3
trying to use scp-action
ofiriro3 Feb 13, 2023
b940661
Copy single file to remote
ofiriro3 Feb 13, 2023
f1ec376
Copy single file to remote
ofiriro3 Feb 13, 2023
5181f79
Change to key
ofiriro3 Feb 13, 2023
65e6f67
update flow
ofiriro3 Feb 13, 2023
9127534
adding command
ofiriro3 Feb 13, 2023
72f8423
print pwd
ofiriro3 Feb 13, 2023
8aef1c1
print pwd
ofiriro3 Feb 13, 2023
b8c2ef2
Remove spaces
ofiriro3 Feb 13, 2023
6de42c4
updating flow to ll the file
ofiriro3 Feb 13, 2023
ebfc4d8
updating flow to ll the file
ofiriro3 Feb 13, 2023
0d09ab8
updating flow to ll the file
ofiriro3 Feb 13, 2023
5335de3
only pwd
ofiriro3 Feb 13, 2023
b31d585
adding ll
ofiriro3 Feb 13, 2023
4067dcd
adding ls
ofiriro3 Feb 13, 2023
2a846af
adding cat
ofiriro3 Feb 13, 2023
ea9e924
fixing the secret to be evaluated
ofiriro3 Feb 13, 2023
441c80d
new example
ofiriro3 Feb 13, 2023
e93adcd
remote authenticatioin
ofiriro3 Feb 13, 2023
02019bb
Trying to add echo -e
ofiriro3 Feb 13, 2023
090edfa
SCP help
ofiriro3 Feb 13, 2023
727477b
SCP help
ofiriro3 Feb 13, 2023
3bfe72c
updating command to verbose
ofiriro3 Feb 13, 2023
3ba1564
updating command to verbose
ofiriro3 Feb 13, 2023
427bea3
removing host verification
ofiriro3 Feb 13, 2023
e93b6a5
Adding base 64 decoding
ofiriro3 Feb 13, 2023
e3f5ec6
mm
ofiriro3 Feb 13, 2023
590c2c5
update flow to use public ip variable
ofiriro3 Feb 13, 2023
b55ce48
update flow to use public ip variable
ofiriro3 Feb 13, 2023
850dee5
updating id of flow
ofiriro3 Feb 13, 2023
0008f61
first end to end flow
ofiriro3 Feb 13, 2023
2f09957
Fixing CI scp command
ofiriro3 Feb 13, 2023
3e5a3da
Fixing deployment
ofiriro3 Feb 13, 2023
a4170e8
Working version with no snapshot
ofiriro3 Feb 13, 2023
fe66278
Adding input validation and using 8.6.1 version
ofiriro3 Feb 13, 2023
a2efb02
Adding all old files
ofiriro3 Feb 13, 2023
dfe71ea
Merge branch 'main' into vanilla_poc
ofiriro3 Feb 13, 2023
ed4ea56
Update the git ignore
ofiriro3 Feb 13, 2023
008f3e3
Refined version
ofiriro3 Feb 13, 2023
74c9a40
Edit environment variables
ofiriro3 Feb 14, 2023
592bfd1
removing flow
ofiriro3 Feb 14, 2023
819615d
reverting changes
ofiriro3 Feb 14, 2023
f71e894
Adding the new workflow
ofiriro3 Feb 14, 2023
cf30520
Add image replacement step
ofiriro3 Feb 14, 2023
fb4c41a
Update actions checkout
ofiriro3 Feb 14, 2023
9908a76
Different format
ofiriro3 Feb 14, 2023
fd344eb
adding cat before
ofiriro3 Feb 14, 2023
abac56c
Moving the image to manifest.yaml
ofiriro3 Feb 14, 2023
124178b
trying to edit the command
ofiriro3 Feb 14, 2023
85b00c5
Trying to use environment variable for it
ofiriro3 Feb 14, 2023
cd1ccd9
Trying to use environment variable for it
ofiriro3 Feb 14, 2023
b727e5d
Update weekly-enviroment.yml EC parameter name
ofiriro3 Feb 15, 2023
d02a1ba
Merge branch 'main' into vanilla_poc
ofiriro3 Feb 15, 2023
65a8a33
Update weekly-enviroment.yml EC2 Private key parameter name
ofiriro3 Feb 15, 2023
0426cd7
Merge remote-tracking branch 'origin/vanilla_poc' into vanilla_poc
ofiriro3 Feb 15, 2023
0303ede
merge vanilla to mine
ofiriro3 Feb 15, 2023
ea5285a
merge vanilla to mine
ofiriro3 Feb 15, 2023
5067c19
adding the image replace flow
ofiriro3 Feb 15, 2023
c649c6f
Revert weekly environment to use same image
ofiriro3 Feb 15, 2023
6c9a3a6
Trying to upgrade the flow to SNAPSHOT 8.7
ofiriro3 Feb 15, 2023
b797ae8
removing manifest file
ofiriro3 Feb 15, 2023
42e160c
fixing spaces
ofiriro3 Feb 15, 2023
acc2af3
Trying to upgrade the flow to SNAPSHOT 8.7.0
ofiriro3 Feb 15, 2023
3ad78c5
Updating flow to use stagging environment
ofiriro3 Feb 22, 2023
067beea
Merge main to mine
ofiriro3 Feb 23, 2023
d997ee9
Trying to install vanilla integration using only the vanilla input
ofiriro3 Feb 23, 2023
7f0ddd4
Merge branch 'main' into weekly-enviroment-vanilla-work-with-SNAPSHOT
ofiriro3 Feb 23, 2023
61d49b0
Terraform formatting
ofiriro3 Feb 23, 2023
170ca5c
Merge remote-tracking branch 'origin/weekly-enviroment-vanilla-work-w…
ofiriro3 Feb 23, 2023
b6e0ae0
Merge branch 'main' into weekly-enviroment-vanilla-work-with-SNAPSHOT
ofiriro3 Feb 26, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/weekly-enviroment.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ env:
TF_VAR_ec_api_key: ${{ secrets.WEEKLY_ENVIRONMENT_EC_API_KEY }}
TF_VAR_environment: ${{ github.event.inputs.logLevel }}
TF_LOG: ${{ github.event.inputs.logLevel }}
TF_VAR_stack_version: 8.6.1
TF_VAR_stack_version: 8.7.0-SNAPSHOT

jobs:
terraform:
Expand Down
3 changes: 2 additions & 1 deletion deploy/weekly-environment/main.tf
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
provider "ec" {
apikey = var.ec_api_key
apikey = var.ec_api_key
endpoint = var.endpoint
}

module "ec_deployment" {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,50 +15,24 @@
"data_stream": {
"type": "logs",
"dataset": "cloud_security_posture.findings"
},
"release": "ga"
}
]
},
{
"type": "cloudbeat/cis_eks",
"policy_template": "kspm",
"enabled": false,
"streams": [
{
"enabled": false,
"data_stream": {
"type": "logs",
"dataset": "cloud_security_posture.findings"
},
"release": "ga",
"vars": {
"access_key_id": {
"type": "text"
},
"secret_access_key": {
"type": "text"
},
"session_token": {
"type": "text"
},
"shared_credential_file": {
"type": "text"
},
"credential_profile_name": {
"type": "text"
},
"role_arn": {
"type": "text"
}
}
}
]
}
],
"package": {
"name": "cloud_security_posture",
"title": "Kubernetes Security Posture Management (KSPM)",
"version": "1.1.1"
"title": "Security Posture Management (CSPM/KSPM)",
"version": "1.2.10"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this version is not stable, no?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As far as I know the broken integration is 1.2.11, but the integration will auto-upgrade to 1.2.11 after the deployment.
As far as I saw I got findings as usual, although the agent wasn't healthy (on 1.2.11).

Do you think it would be better to deploy @jeniawhite version? 1.2.12-next

},
"vars": {
"posture": {
"value": "kspm",
"type": "text"
},
"deployment": {
"value": "cloudbeat/cis_k8s",
"type": "text"
}
}
}
7 changes: 6 additions & 1 deletion deploy/weekly-environment/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ variable "ec_api_key" {

variable "ess_region" {
default = "gcp-us-central1"
description = "Optional ESS region where the deployment will be created. Defaults to gcp-us-west2"
description = "Optional ESS region where the deployment will be created. Defaults to gcp-us-central1"
Comment thread
oren-zohar marked this conversation as resolved.
type = string
}

Expand Down Expand Up @@ -58,3 +58,8 @@ variable "deployment_name_prefix" {
default = "weekly-environment"
description = "Optional set a prefix of the deployment. Defaults to weekly-environment"
}

variable "endpoint" {
default = "https://staging.found.no/"
description = "Optional endpoint for the Elastic Cloud API"
}