chore: remove unused workflow files.
The chart has been moved to another repo.
This commit is contained in:
parent
9ab70156e7
commit
860541cc22
6 changed files with 0 additions and 265 deletions
5
.github/ct.yaml
vendored
5
.github/ct.yaml
vendored
|
@ -1,5 +0,0 @@
|
||||||
chart-dirs:
|
|
||||||
- charts
|
|
||||||
remote: origin
|
|
||||||
target-branch: main
|
|
||||||
check-version-increment: false
|
|
122
.github/kubescape-controls-inputs.json
vendored
122
.github/kubescape-controls-inputs.json
vendored
|
@ -1,122 +0,0 @@
|
||||||
{
|
|
||||||
"cpu_limit_max": [],
|
|
||||||
"cpu_limit_min": [],
|
|
||||||
"cpu_request_max": [],
|
|
||||||
"cpu_request_min": [],
|
|
||||||
"imageRepositoryAllowList": [
|
|
||||||
"ghcr.io"
|
|
||||||
],
|
|
||||||
"insecureCapabilities": [
|
|
||||||
"SETPCAP",
|
|
||||||
"NET_ADMIN",
|
|
||||||
"NET_RAW",
|
|
||||||
"SYS_MODULE",
|
|
||||||
"SYS_RAWIO",
|
|
||||||
"SYS_PTRACE",
|
|
||||||
"SYS_ADMIN",
|
|
||||||
"SYS_BOOT",
|
|
||||||
"MAC_OVERRIDE",
|
|
||||||
"MAC_ADMIN",
|
|
||||||
"PERFMON",
|
|
||||||
"ALL",
|
|
||||||
"BPF"
|
|
||||||
],
|
|
||||||
"k8sRecommendedLabels": [
|
|
||||||
"app.kubernetes.io/name",
|
|
||||||
"app.kubernetes.io/instance",
|
|
||||||
"app.kubernetes.io/version",
|
|
||||||
"app.kubernetes.io/component",
|
|
||||||
"app.kubernetes.io/part-of",
|
|
||||||
"app.kubernetes.io/managed-by",
|
|
||||||
"app.kubernetes.io/created-by"
|
|
||||||
],
|
|
||||||
"listOfDangerousArtifcats": [
|
|
||||||
"bin/bash",
|
|
||||||
"sbin/sh",
|
|
||||||
"bin/ksh",
|
|
||||||
"bin/tcsh",
|
|
||||||
"bin/zsh",
|
|
||||||
"usr/bin/scsh",
|
|
||||||
"bin/csh",
|
|
||||||
"bin/busybox",
|
|
||||||
"usr/bin/busybox"
|
|
||||||
],
|
|
||||||
"max_critical_vulnerabilities": [
|
|
||||||
"5"
|
|
||||||
],
|
|
||||||
"max_high_vulnerabilities": [
|
|
||||||
"10"
|
|
||||||
],
|
|
||||||
"memory_limit_max": [],
|
|
||||||
"memory_limit_min": [],
|
|
||||||
"memory_request_max": [],
|
|
||||||
"memory_request_min": [],
|
|
||||||
"publicRegistries": [
|
|
||||||
"quay.io",
|
|
||||||
"registry.hub.docker.com"
|
|
||||||
],
|
|
||||||
"recommendedLabels": [
|
|
||||||
"app.kubernetes.io/name",
|
|
||||||
"app.kubernetes.io/instance"
|
|
||||||
],
|
|
||||||
"sensitiveInterfaces": [
|
|
||||||
"nifi",
|
|
||||||
"argo-server",
|
|
||||||
"weave-scope-app",
|
|
||||||
"kubeflow",
|
|
||||||
"kubernetes-dashboard"
|
|
||||||
],
|
|
||||||
"sensitiveKeyNames": [
|
|
||||||
"aws_access_key_id",
|
|
||||||
"aws_secret_access_key",
|
|
||||||
"azure_batchai_storage_account",
|
|
||||||
"azure_batchai_storage_key",
|
|
||||||
"azure_batch_account",
|
|
||||||
"azure_batch_key",
|
|
||||||
"secret",
|
|
||||||
"key",
|
|
||||||
"password",
|
|
||||||
"pwd",
|
|
||||||
"token",
|
|
||||||
"jwt",
|
|
||||||
"bearer",
|
|
||||||
"credential"
|
|
||||||
],
|
|
||||||
"sensitiveValues": [
|
|
||||||
"BEGIN \\w+ PRIVATE KEY",
|
|
||||||
"PRIVATE KEY",
|
|
||||||
"eyJhbGciO",
|
|
||||||
"JWT",
|
|
||||||
"Bearer"
|
|
||||||
],
|
|
||||||
"sensitiveValuesAllowed": [],
|
|
||||||
"servicesNames": [
|
|
||||||
"nifi-service",
|
|
||||||
"argo-server",
|
|
||||||
"minio",
|
|
||||||
"postgres",
|
|
||||||
"workflow-controller-metrics",
|
|
||||||
"weave-scope-app",
|
|
||||||
"kubernetes-dashboard"
|
|
||||||
],
|
|
||||||
"untrustedRegistries": [],
|
|
||||||
"wlKnownNames": [
|
|
||||||
"coredns",
|
|
||||||
"kube-proxy",
|
|
||||||
"event-exporter-gke",
|
|
||||||
"kube-dns",
|
|
||||||
"17-default-backend",
|
|
||||||
"metrics-server",
|
|
||||||
"ca-audit",
|
|
||||||
"ca-dashboard-aggregator",
|
|
||||||
"ca-notification-server",
|
|
||||||
"ca-ocimage",
|
|
||||||
"ca-oracle",
|
|
||||||
"ca-posture",
|
|
||||||
"ca-rbac",
|
|
||||||
"ca-vuln-scan",
|
|
||||||
"ca-webhook",
|
|
||||||
"ca-websocket",
|
|
||||||
"clair-clair"
|
|
||||||
]
|
|
||||||
}
|
|
17
.github/stale.yml
vendored
17
.github/stale.yml
vendored
|
@ -1,17 +0,0 @@
|
||||||
daysUntilStale: 30
|
|
||||||
daysUntilClose: 14
|
|
||||||
onlyLabels: []
|
|
||||||
exemptLabels:
|
|
||||||
- pinned
|
|
||||||
- security
|
|
||||||
|
|
||||||
exemptProjects: false
|
|
||||||
exemptMilestones: true
|
|
||||||
exemptAssignees: false
|
|
||||||
staleLabel: stale
|
|
||||||
|
|
||||||
markComment: >
|
|
||||||
This issue has been automatically marked as stale because it has not had
|
|
||||||
recent activity. It will be closed if no further activity occurs. Thank you
|
|
||||||
for your contributions.
|
|
||||||
limitPerRun: 30
|
|
82
.github/workflows/chart.yaml
vendored
82
.github/workflows/chart.yaml
vendored
|
@ -1,82 +0,0 @@
|
||||||
name: Chart
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
branches:
|
|
||||||
- 'main'
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- 'main'
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
chart-testing:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v3
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
|
|
||||||
- name: Set up Helm
|
|
||||||
uses: azure/setup-helm@v3
|
|
||||||
with:
|
|
||||||
version: v3.7.1
|
|
||||||
|
|
||||||
- uses: actions/setup-python@v4
|
|
||||||
with:
|
|
||||||
python-version: 3.7
|
|
||||||
|
|
||||||
- name: Set up chart-testing
|
|
||||||
uses: helm/chart-testing-action@v2.3.1
|
|
||||||
|
|
||||||
- name: Run chart-testing (list-changed)
|
|
||||||
id: list-changed
|
|
||||||
run: |
|
|
||||||
changed=$(ct --config .github/ct.yaml list-changed)
|
|
||||||
if [[ -n "$changed" ]]; then
|
|
||||||
echo "::set-output name=changed::true"
|
|
||||||
fi
|
|
||||||
|
|
||||||
- name: Run chart-testing (lint)
|
|
||||||
run: ct --config .github/ct.yaml lint
|
|
||||||
|
|
||||||
polaris-audit:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v3
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
|
|
||||||
- name: Set up Helm
|
|
||||||
uses: azure/setup-helm@v3
|
|
||||||
with:
|
|
||||||
version: v3.7.1
|
|
||||||
|
|
||||||
- name: Setup polaris
|
|
||||||
uses: fairwindsops/polaris/.github/actions/setup-polaris@master
|
|
||||||
with:
|
|
||||||
version: 6.0.0
|
|
||||||
|
|
||||||
- name: Run audit
|
|
||||||
run: |
|
|
||||||
polaris audit --helm-chart ./charts/well-known --helm-values ./charts/well-known/values.yaml --format pretty --set-exit-code-on-danger --set-exit-code-below-score 90
|
|
||||||
|
|
||||||
pluto-scan:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v2
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
|
|
||||||
- name: Set up Helm
|
|
||||||
uses: azure/setup-helm@v3
|
|
||||||
with:
|
|
||||||
version: v3.7.1
|
|
||||||
|
|
||||||
- name: Download Pluto
|
|
||||||
uses: FairwindsOps/pluto/github-action@master
|
|
||||||
|
|
||||||
- name: Use pluto
|
|
||||||
run: |
|
|
||||||
helm template ./charts/well-known -f ./charts/well-known/ci/pluto-values.yaml | pluto detect - --ignore-deprecations
|
|
15
.github/workflows/release.yaml
vendored
15
.github/workflows/release.yaml
vendored
|
@ -1,15 +0,0 @@
|
||||||
name: Release
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- 'main'
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
release:
|
|
||||||
name: Release
|
|
||||||
uses: stenic/github-workflows/.github/workflows/release-docker-helm.yaml@main
|
|
||||||
with:
|
|
||||||
docker_image: "ghcr.io/${{ github.repository }}"
|
|
||||||
chart_path: './charts/well-known'
|
|
||||||
secrets:
|
|
||||||
token: ${{ secrets.PERSONAL_ACCESS_TOKEN }}
|
|
24
.github/workflows/test.yaml
vendored
24
.github/workflows/test.yaml
vendored
|
@ -1,24 +0,0 @@
|
||||||
name: Build
|
|
||||||
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
branches:
|
|
||||||
- 'main'
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- 'main'
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
docker:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Set up QEMU
|
|
||||||
uses: docker/setup-qemu-action@v2
|
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
|
||||||
uses: docker/setup-buildx-action@v2
|
|
||||||
|
|
||||||
- name: Build
|
|
||||||
uses: docker/build-push-action@v3
|
|
||||||
with:
|
|
||||||
push: false
|
|
Loading…
Reference in a new issue