Skip to content

Commit 6e846c6

Browse files
author
Nissim Bitan
committed
Update Aqua Deployments
1 parent 0cd4f9e commit 6e846c6

40 files changed

+250
-54
lines changed

automation/aquactl/aquasec.cfg

Lines changed: 188 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,188 @@
1+
{{- if .Values.Infra }}
2+
# Aqua infrastructure information about the installation platform and destination
3+
infra:
4+
# Platform namespace
5+
# - Kubernetes and Pivotal PKS example
6+
# kubectl create namespace aqua
7+
# - Openshift example
8+
# oc new-project aqua
9+
namespace: {{ .Values.Infra.Namespace }}
10+
# Kubectl Context from ~/.kube/config choose your context
11+
context: {{ .Values.Infra.Context }}
12+
# Platform to use: Kubernetes, Openshift, Pivotal
13+
platform: {{ .Values.Infra.Platform }}
14+
{{- else }}
15+
# Aqua infrastructure information about the installation platform and destination
16+
# infra:
17+
# Platform namespace
18+
# - Kubernetes and Pivotal PKS example
19+
# kubectl create namespace aqua
20+
# - Openshift example
21+
# oc new-project aqua
22+
# namespace: {{ .Values.Infra.Namespace }}
23+
# Kubectl Context from ~/.kube/config choose your context
24+
# context: {{ .Values.Infra.Context }}
25+
# Platform to use: Kubernetes, Openshift, Pivotal
26+
# platform: {{ .Values.Infra.Platform }}
27+
{{- end }}
28+
{{- if .Values.Common }}
29+
# Aqua Common variables for all installation process
30+
common:
31+
# Installation version for aqua unless overide version in each service as server, gateway or database
32+
version: "{{ .Values.Common.Version }}"
33+
registry: {{ .Values.Common.Registry }}
34+
PullPolicy: {{ .Values.Common.PullPolicy }}
35+
# If to enable dockerless scaning configuration
36+
dockerless: {{ .Values.Common.Dockerless }}
37+
# Docker socker path for example if using pivotal pks docker socket should be /var/vcap/data/sys/run/docker/docker.sock
38+
dockerSocketPath: "{{ .Values.Common.DockerSocketPath }}"
39+
# Pull docker image secret name
40+
pullImageSecret: {{ .Values.Common.PullImageSecret }}
41+
serviceAccount: {{ .Values.Common.ServiceAccount }}
42+
# Aqua admin password secret name
43+
adminPasswordSecretName: {{ .Values.Common.AdminPasswordSecretName }}
44+
# Aqua admin password secret key
45+
adminPasswordSecretKey: {{ .Values.Common.AdminPasswordSecretKey }}
46+
# Aqua License token secret name
47+
aquaLicenseSecretName: {{ .Values.Common.AquaLicenseSecretName }}
48+
# Aqua License token secret key
49+
aquaLicenseSecretKey: {{ .Values.Common.AquaLicenseSecretKey }}
50+
aquaInternalDbSecretName: {{ .Values.Common.AquaInternalDbSecretName }}
51+
aquaInternalDbSecretKey: {{ .Values.Common.AquaInternalDbSecretKey }}
52+
{{- else }}
53+
# Aqua Common variables for all installation process
54+
# common:
55+
# Installation version for aqua unless overide version in each service as server, gateway or database
56+
# version: "4.2"
57+
# If to enable dockerless scaning configuration
58+
# dockerless: false
59+
# Docker socker path for example if using pivotal pks docker socket should be /var/vcap/data/sys/run/docker/docker.sock
60+
# dockerSocketPath: "/var/run/docker.sock"
61+
# Pull docker image secret name
62+
# pullImageSecret:
63+
# Aqua admin password secret name
64+
# adminPasswordSecretName:
65+
# Aqua admin password secret key
66+
# adminPasswordSecretKey:
67+
# Aqua License token secret name
68+
# aquaLicenseSecretName:
69+
# Aqua License token secret key
70+
# adminPasswordSecretKey:
71+
{{- end }}
72+
{{- if .Values.Security }}
73+
# Aqua Security Properties
74+
security:
75+
rbac: {{ .Values.Security.Rbac }}
76+
privileged: {{ .Values.Security.Privileged }}
77+
roleRef: {{ .Values.Security.RoleRef }}
78+
{{- else }}
79+
# Aqua Security Properties
80+
# security:
81+
# rbac: true
82+
# privileged: true
83+
# roleRef:
84+
{{- end }}
85+
{{- if .Values.Server }}
86+
# Aqua Server Service
87+
server:
88+
replicas: {{ .Values.Server.Replicas }}
89+
service: "{{ .Values.Server.Service }}"
90+
{{- if .Values.Server.Image }}
91+
image:
92+
repository: {{ .Values.Server.Image.Repository }}
93+
registry: {{ .Values.Server.Image.Registry }}
94+
tag: "{{ .Values.Server.Image.Tag }}"
95+
pullPolicy: {{ .Values.Server.Image.PullPolicy }}
96+
{{- end }}
97+
{{- else }}
98+
# Aqua Server Service
99+
# server:
100+
# replicas: 1
101+
# service: "LoadBalancer"
102+
# image:
103+
# repository: server
104+
# registry: registry.aquasec.com
105+
# tag: "4.2"
106+
# pullPolicy: Always
107+
{{- end }}
108+
{{- if .Values.Gateway }}
109+
# Aqua Gateway Service
110+
gateway:
111+
replicas: {{ .Values.Gateway.Replicas }}
112+
service: "{{ .Values.Gateway.Service }}"
113+
{{- if .Values.Gateway.Image }}
114+
image:
115+
repository: {{ .Values.Gateway.Image.Repository }}
116+
registry: {{ .Values.Gateway.Image.Registry }}
117+
tag: "{{ .Values.Gateway.Image.Tag }}"
118+
pullPolicy: {{ .Values.Gateway.Image.PullPolicy }}
119+
{{- end }}
120+
{{- else }}
121+
# Aqua Gateway Service
122+
# gateway:
123+
# replicas: 1
124+
# service: "ClusterIP"
125+
# image:
126+
# repository: gateway
127+
# registry: registry.aquasec.com
128+
# tag: "4.2"
129+
# pullPolicy: Always
130+
{{- end }}
131+
{{- if .Values.Database }}
132+
# Aqua Database Service
133+
database:
134+
replicas: {{ .Values.Database.Replicas }}
135+
service: "{{ .Values.Database.Service }}"
136+
{{- if .Values.Database.Image }}
137+
image:
138+
repository: {{ .Values.Database.Image.Repository }}
139+
registry: {{ .Values.Database.Image.Registry }}
140+
tag: "{{ .Values.Database.Image.Tag }}"
141+
pullPolicy: {{ .Values.Database.Image.PullPolicy }}
142+
{{- end }}
143+
{{- else }}
144+
# Aqua Database Service
145+
# database:
146+
# replicas: 1
147+
# service: "ClusterIP"
148+
# image:
149+
# repository: database
150+
# registry: registry.aquasec.com
151+
# tag: "4.2"
152+
# pullPolicy: Always
153+
{{- end }}
154+
{{- if .Values.ExternalDb }}
155+
# Aqua External Database
156+
externalDb:
157+
scalock:
158+
name: {{ .Values.ExternalDb.Scalock.Name }}
159+
host: {{ .Values.ExternalDb.Scalock.Host }}
160+
port: {{ .Values.ExternalDb.Scalock.Port }}
161+
username: {{ .Values.ExternalDb.Scalock.Username }}
162+
passwordSecretName: {{ .Values.ExternalDb.Scalock.PasswordSecretName }}
163+
passwordSecretKey: {{ .Values.ExternalDb.Scalock.PasswordSecretKey }}
164+
audit:
165+
name: {{ .Values.ExternalDb.Audit.Name }}
166+
host: {{ .Values.ExternalDb.Audit.Host }}
167+
port: {{ .Values.ExternalDb.Audit.Port }}
168+
username: {{ .Values.ExternalDb.Audit.Username }}
169+
passwordSecretName: {{ .Values.ExternalDb.Audit.PasswordSecretName }}
170+
passwordSecretKey: {{ .Values.ExternalDb.Audit.PasswordSecretKey }}
171+
{{- else }}
172+
# Aqua External Database
173+
# externalDb:
174+
# scalock:
175+
# name:
176+
# host:
177+
# port:
178+
# username:
179+
# passwordSecretName:
180+
# passwordSecretKey:
181+
# audit:
182+
# name:
183+
# host:
184+
# port:
185+
# username:
186+
# passwordSecretName:
187+
# passwordSecretKey:
188+
{{- end }}

automation/shell/Kubernetes/AKS/aqua-aks-local-non-csp.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -468,7 +468,7 @@ EOF
468468
# serviceAccount: aqua-sa
469469
# containers:
470470
# - name: aqua-cc
471-
# image: docker.io/aquasec/cybercenter-standard:latest
471+
# image: registry.aquasec.com/cybercenter-standard:latest
472472
# imagePullPolicy: Always
473473
# command: []
474474
# args:

automation/shell/Kubernetes/AKS/aqua-aks-remote-non-csp.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -407,7 +407,7 @@ EOF
407407
# serviceAccount: aqua-sa
408408
# containers:
409409
# - name: aqua-cc
410-
# image: docker.io/aquasec/cybercenter-standard:latest
410+
# image: registry.aquasec.com/cybercenter-standard:latest
411411
# imagePullPolicy: Always
412412
# command: []
413413
# args:

automation/shell/Kubernetes/AKS/aqua-enforcer-aks-non-csp.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ spec:
4848
aqua-enforcer: "yes"
4949
containers:
5050
- name: aqua-agent
51-
image: docker.io/aquasec/agent:${aquaenforcertag}
51+
image: registry.aquasec.com/enforcer:${aquaenforcertag}
5252
securityContext:
5353
privileged: true
5454
env:

automation/shell/Kubernetes/AKS/aqua-enforcer-saas.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@ spec:
7373
aqua-enforcer: "yes"
7474
containers:
7575
- name: aqua-agent
76-
image: docker.io/aquasec/agent:${aquaenforcertag}
76+
image: registry.aquasec.com/enforcer:${aquaenforcertag}
7777
securityContext:
7878
privileged: true
7979
env:

automation/shell/Kubernetes/EKS/aqua-eks-docker-non-csp.sh

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -160,7 +160,7 @@ spec:
160160
- name: aqua-database
161161
securityContext:
162162
privileged: true
163-
image: docker.io/aquasec/database:${aquatag}
163+
image: registry.aquasec.com/database:${aquatag}
164164
env:
165165
- name: "POSTGRES_PASSWORD"
166166
valueFrom:
@@ -278,7 +278,7 @@ spec:
278278
serviceAccount: aqua-sa
279279
containers:
280280
- name: aqua-web
281-
image: docker.io/aquasec/server:${aquatag}
281+
image: registry.aquasec.com/server:${aquatag}
282282
securityContext:
283283
privileged: true
284284
env:
@@ -354,7 +354,7 @@ spec:
354354
serviceAccount: aqua-sa
355355
containers:
356356
- name: aqua-gateway
357-
image: docker.io/aquasec/gateway:${aquatag}
357+
image: registry.aquasec.com/gateway:${aquatag}
358358
env:
359359
- name: "SCALOCK_AUDIT_DBPASSWORD"
360360
valueFrom:
@@ -404,7 +404,7 @@ spec:
404404
serviceAccount: aqua-sa
405405
containers:
406406
- name: aqua-cc
407-
image: docker.io/aquasec/cybercenter-standard:latest
407+
image: registry.aquasec.com/cybercenter-standard:latest
408408
imagePullPolicy: Always
409409
command: []
410410
args:

automation/shell/Kubernetes/EKS/aqua-eks-local-non-csp.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -468,7 +468,7 @@ EOF
468468
# serviceAccount: aqua-sa
469469
# containers:
470470
# - name: aqua-cc
471-
# image: docker.io/aquasec/cybercenter-standard:latest
471+
# image: registry.aquasec.com/cybercenter-standard:latest
472472
# imagePullPolicy: Always
473473
# command: []
474474
# args:

automation/shell/Kubernetes/EKS/aqua-eks-remote-non-csp.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -655,7 +655,7 @@ EOF
655655
## serviceAccount: aqua-sa
656656
## containers:
657657
## - name: aqua-cc
658-
## image: docker.io/aquasec/cybercenter-standard:latest
658+
## image: registry.aquasec.com/cybercenter-standard:latest
659659
## imagePullPolicy: Always
660660
## command: []
661661
## args:

automation/shell/Kubernetes/EKS/aqua-enforcer-eks-non-csp.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ spec:
4848
aqua-enforcer: "yes"
4949
containers:
5050
- name: aqua-agent
51-
image: docker.io/aquasec/agent:${aquaenforcertag}
51+
image: registry.aquasec.com/enforcer:${aquaenforcertag}
5252
securityContext:
5353
privileged: true
5454
env:

automation/shell/Kubernetes/EKS/aqua-enforcer-saas.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,7 @@ spec:
7474
aqua-enforcer: "yes"
7575
containers:
7676
- name: aqua-agent
77-
image: docker.io/aquasec/agent:${aquaenforcertag}
77+
image: registry.aquasec.com/enforcer:${aquaenforcertag}
7878
securityContext:
7979
privileged: true
8080
env:

0 commit comments

Comments
 (0)