diff --git a/calico-cloud/compliance/compliance-reports-cis.mdx b/calico-cloud/compliance/compliance-reports-cis.mdx index ed22ba3225..0306866931 100644 --- a/calico-cloud/compliance/compliance-reports-cis.mdx +++ b/calico-cloud/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports for clusters connected t :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud/compliance/enable-compliance.mdx b/calico-cloud/compliance/enable-compliance.mdx index 0a85f039e1..e3fe3b512c 100644 --- a/calico-cloud/compliance/enable-compliance.mdx +++ b/calico-cloud/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Activate compliance reporting components on clusters connected to C :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud/compliance/overview.mdx b/calico-cloud/compliance/overview.mdx index 31d8fcc6a6..55813ef0ee 100644 --- a/calico-cloud/compliance/overview.mdx +++ b/calico-cloud/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Cloud compliance reports against Kubernetes :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud/release-notes/index.mdx b/calico-cloud/release-notes/index.mdx index 9d302a22f3..09bfa65081 100644 --- a/calico-cloud/release-notes/index.mdx +++ b/calico-cloud/release-notes/index.mdx @@ -67,7 +67,6 @@ For more information see [Deploy a dual ToR cluster](../networking/configuring/d ### Deprecated and removed features * All compliance reporting features are deprecated and will be removed in a future release. - We're building a new compliance reporting system that will eventually replace the current one. ## November 6, 2024 (version 20.2.0) diff --git a/calico-cloud_versioned_docs/version-22-2/compliance/compliance-reports-cis.mdx b/calico-cloud_versioned_docs/version-22-2/compliance/compliance-reports-cis.mdx index ed22ba3225..0306866931 100644 --- a/calico-cloud_versioned_docs/version-22-2/compliance/compliance-reports-cis.mdx +++ b/calico-cloud_versioned_docs/version-22-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports for clusters connected t :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-22-2/compliance/enable-compliance.mdx b/calico-cloud_versioned_docs/version-22-2/compliance/enable-compliance.mdx index 0a85f039e1..e3fe3b512c 100644 --- a/calico-cloud_versioned_docs/version-22-2/compliance/enable-compliance.mdx +++ b/calico-cloud_versioned_docs/version-22-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Activate compliance reporting components on clusters connected to C :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-22-2/compliance/overview.mdx b/calico-cloud_versioned_docs/version-22-2/compliance/overview.mdx index 31d8fcc6a6..55813ef0ee 100644 --- a/calico-cloud_versioned_docs/version-22-2/compliance/overview.mdx +++ b/calico-cloud_versioned_docs/version-22-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Cloud compliance reports against Kubernetes :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-22-2/release-notes/index.mdx b/calico-cloud_versioned_docs/version-22-2/release-notes/index.mdx index 1101fef0c1..089c0638f8 100644 --- a/calico-cloud_versioned_docs/version-22-2/release-notes/index.mdx +++ b/calico-cloud_versioned_docs/version-22-2/release-notes/index.mdx @@ -504,7 +504,6 @@ For more information see [Deploy a dual ToR cluster](../networking/configuring/d ### Deprecated and removed features * All compliance reporting features are deprecated and will be removed in a future release. - We're building a new compliance reporting system that will eventually replace the current one. ### Updating diff --git a/calico-cloud_versioned_docs/version-22-2/threat/container-threat-detection.mdx b/calico-cloud_versioned_docs/version-22-2/threat/container-threat-detection.mdx index 05d0594f42..8756075317 100644 --- a/calico-cloud_versioned_docs/version-22-2/threat/container-threat-detection.mdx +++ b/calico-cloud_versioned_docs/version-22-2/threat/container-threat-detection.mdx @@ -9,7 +9,6 @@ redirect_from: :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-23-2/compliance/compliance-reports-cis.mdx b/calico-cloud_versioned_docs/version-23-2/compliance/compliance-reports-cis.mdx index ed22ba3225..0306866931 100644 --- a/calico-cloud_versioned_docs/version-23-2/compliance/compliance-reports-cis.mdx +++ b/calico-cloud_versioned_docs/version-23-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports for clusters connected t :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-23-2/compliance/enable-compliance.mdx b/calico-cloud_versioned_docs/version-23-2/compliance/enable-compliance.mdx index 0a85f039e1..e3fe3b512c 100644 --- a/calico-cloud_versioned_docs/version-23-2/compliance/enable-compliance.mdx +++ b/calico-cloud_versioned_docs/version-23-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Activate compliance reporting components on clusters connected to C :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-23-2/compliance/overview.mdx b/calico-cloud_versioned_docs/version-23-2/compliance/overview.mdx index 31d8fcc6a6..55813ef0ee 100644 --- a/calico-cloud_versioned_docs/version-23-2/compliance/overview.mdx +++ b/calico-cloud_versioned_docs/version-23-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Cloud compliance reports against Kubernetes :::warning[deprecation and removal notice] Compliance reports are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-cloud_versioned_docs/version-23-2/release-notes/index.mdx b/calico-cloud_versioned_docs/version-23-2/release-notes/index.mdx index 8371ff642c..a06d18f54d 100644 --- a/calico-cloud_versioned_docs/version-23-2/release-notes/index.mdx +++ b/calico-cloud_versioned_docs/version-23-2/release-notes/index.mdx @@ -556,7 +556,6 @@ For more information see [Deploy a dual ToR cluster](../networking/configuring/d ### Deprecated and removed features * All compliance reporting features are deprecated and will be removed in a future release. - We're building a new compliance reporting system that will eventually replace the current one. ### Updating diff --git a/calico-enterprise/about/calico-product-editions.mdx b/calico-enterprise/about/calico-product-editions.mdx index 4808160a01..3ec34cedf4 100644 --- a/calico-enterprise/about/calico-product-editions.mdx +++ b/calico-enterprise/about/calico-product-editions.mdx @@ -62,7 +62,6 @@ import { CalicoProducts } from '/src/___new___/components'; | Deep packet inspection | | | | | | DDoS protection | | | | | | Workload-centric WAF | | | | | -| Compliance reporting and alerts | | | | | | SIEM integrations | | | | | | **Network Security for VMs and Bare Metal** | | | | | | Restrict traffic to/from hosts and VMs using network policy | | | | | diff --git a/calico-enterprise/about/index.mdx b/calico-enterprise/about/index.mdx index 414d02dc93..dfcee21ecb 100644 --- a/calico-enterprise/about/index.mdx +++ b/calico-enterprise/about/index.mdx @@ -190,7 +190,6 @@ All of this is built on Calico Open Source, the most widely used container netwo | Deep packet inspection | | | | | | DDoS protection | | | | | | Workload-centric WAF | | | | | -| Compliance reporting and alerts | | | | | | SIEM integrations | | | | | | **Network Security for VMs and Bare Metal** | | | | | | Restrict traffic to/from hosts and VMs using network policy | | | | | diff --git a/calico-enterprise/compliance/compliance-reports-cis.mdx b/calico-enterprise/compliance/compliance-reports-cis.mdx deleted file mode 100644 index dd3258e609..0000000000 --- a/calico-enterprise/compliance/compliance-reports-cis.mdx +++ /dev/null @@ -1,199 +0,0 @@ ---- -description: Configure CIS Kubernetes benchmark reports in Calico Enterprise to assess node and cluster compliance and download results from the in-cluster reporter as CSV. ---- - -# Configure CIS benchmark reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Use the $[prodname] Kubernetes CIS benchmark report to assess compliance for all assets in a Kubernetes cluster. - -## Value - -A standard requirement for an organization’s security and compliance posture is to assess your Kubernetes clusters against CIS benchmarks. The $[prodname] Kubernetes CIS benchmark report provides this comprehensive view into your Kubernetes clusters while strengthening your threat detection capability by looking beyond networking data. - -## Concepts - -### Default settings and configuration - -During $[prodname] installation, each node starts a pod named, `compliance-benchmarker`. A preconfigured Kubernetes CIS benchmark report is generated every hour. You can view the report in **Compliance**, **Compliance Reports**, download it to .csv format. - -To schedule the CIS benchmark report or change settings, use the **global report** resource. Global reports are configured as YAML files and are applied using `kubectl`. - -### Best practices - -We recommend that you review the CIS benchmark best practices for securing cluster component configurations here: [CIS benchmarks downloads](https://learn.cisecurity.org/benchmarks). - -## Before you begin - -**Required** - -* You [Enabled compliance reports](../compliance/enable-compliance) - -**Limitations** - -CIS benchmarks runs only on nodes where $[prodname] is running. This limitation may exclude control plane nodes in some managed cloud platforms (AKS, EKS, GKE). Because the user has limited control over installation of control plane nodes in managed cloud platforms, these reports may have limited use for cloud users. - -## How to - -- [Configure and schedule CIS benchmark reports](#configure-and-schedule-cis-benchmark-reports) -- [View report generation status](#view-report-generation-status) -- [Review and address CIS benchmark results](#review-and-address-cis-benchmark-results) -- [Manually run reports](#manually-run-reports) -- [Troubleshooting](#troubleshooting) - -### Configure and schedule CIS benchmark reports - -Verify that the `compliance-benchmarker` is running and the `cis-benchmark` report type is installed. - -```bash -kubectl get -n tigera-compliance daemonset compliance-benchmarker -kubectl get globalreporttype cis-benchmark -``` - -In the following example, we use a **GlobalReport** with CIS benchmark fields to schedule and filter results. The report is scheduled to run at midnight of the next day (in UTC), and the benchmark items 1.1.4 and 1.2.5 will be omitted from the results. - -| **Fields** | **Description** | -| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| schedule | The start and end time of the report using [crontab format](https://en.wikipedia.org/wiki/Cron). To allow for archiving, reports are generated approximately 30 minutes after the end time. A single report is limited to a maximum of two per hour. | -| highThreshold | **Optional**. Integer percentage value that determines the lower limit of passing tests to consider a node as healthy. Default: 100 | -| medThreshold | **Optional**. Integer percentage value that determines the lower limit of passing tests to consider a node as unhealthy. Default: 50 | -| includeUnscoredTests | **Optional**. Boolean value that when false, applies a filter to exclude tests that are marked as “Unscored” by the CIS benchmark standard. If true, the tests will be included in the report. Default: true | -| numFailedTests | **Optional**. Integer value that sets the number of tests to display in the Top-failed Tests section of the CIS benchmark report. Default: 5 | -| resultsFilter | **Optional**. An include or exclude filter to apply on the test results that will appear on the report. | - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-results - labels: - deployment: production -spec: - reportType: cis-benchmark - schedule: 0 0 * * * - cis: - highThreshold: 100 - medThreshold: 50 - includeUnscoredTests: true - numFailedTests: 5 - resultsFilters: - - benchmarkSelection: { kubernetesVersion: '1.13' } - exclude: ['1.1.4', '1.2.5'] -``` - -### View report generation status - -To view the status of a report, you must use the `kubectl` command. For example: - -```bash -kubectl get globalreports.projectcalico.org daily-cis-results -o yaml -``` - -In a report, the job status types are: - -- **lastScheduledReportJob**: - The most recently scheduled job for generating the report. Because reports are scheduled in order, the “end time” of - this report will be the “start time” of the next scheduled report. -- **activeReportJobs**: - Default = allows up to 5 concurrent report generation jobs. -- **lastFailedReportJobs**: - Default = keeps the 3 most recent failed jobs and deletes older ones. A single report generation job will be retried - up to 6 times (by default) before it is marked as failed. -- **lastSuccessfulReportJobs**: - Default = keeps the 2 most recent successful jobs and deletes older ones. - -#### Change the default report generation time - -By default, reports are generated 30 minutes after the end of the report, to ensure all of the audit data is archived. -(However, this gap does not affect the data collected “start/end time” for a report.) - -You can adjust the time for audit data for cases like initial report testing, to demo a report, or when manually -creating a report that is not counted in global report status. - -To change the delay, go to the installation manifest, and uncomment and set the environment variable -`TIGERA_COMPLIANCE_JOB_START_DELAY`. Specify value as a [Duration string][parse-duration]. - -### Review and address CIS benchmark results - -We recommend the following approach to CIS benchmark reports results: - -1. Download the Kubernetes CIS benchmarks and export your full CIS benchmark results in .csv format. -1. In the compliance dashboard, review the "Top-Failed Tests" section to identify which tests are the most problematic. -1. Cross-reference the top-failed tests to identify which nodes are failing that test. -1. Look up those tests in the [Kubernetes benchmark document](https://downloads.cisecurity.org/#/) and follow the remediation steps to resolve the failure. -1. Discuss with your infrastructure and security team if this remediation is viable within your organization. -1. If so, update your nodes with the fix and ensure that the test passes on the next generation of the report. -1. If the fix is not viable but is an acceptable risk to take within the organization, configure the report specification to exclude that test index so that it no longer appears in the report. -1. If the fix is not viable and not an acceptable risk to take on, keep the failing test within the report so that your team is reminded to address the issue as soon as possible. - -### Manually run reports - -You can manually run reports at any time. For example, run a manual report: - -- To specify a different start/end time -- If a scheduled report fails - -$[prodname] GlobalReport schedules Kubernetes Jobs which create a single-run pod to generate a report and store it in Elasticsearch. Because you need to run manual reports as a pod, you need higher permissions: allow `create` access for pods in namespace `tigera-compliance` using the `tigera-compliance-reporter` service account. - -To manually run a report: - -1. Download the pod template corresponding to your installation method. - **Operator** - - For management and standalone clusters: - - ```bash - curl -O $[filesUrl]/manifests/compliance-reporter-pod.yaml - ``` - - For managed clusters: - - ```bash - curl $[filesUrl]/manifests/compliance-reporter-pod-managed.yaml -o compliance-reporter-pod.yaml - ``` - -1. Edit the template as follows: - - - Edit the pod name if required. - - If you are using your own docker repository, update the container image name with your repo and image tag. - - Set the following environments according to the instructions in the downloaded manifest: - - `TIGERA_COMPLIANCE_REPORT_NAME` - - `TIGERA_COMPLIANCE_REPORT_START_TIME` - - `TIGERA_COMPLIANCE_REPORT_END_TIME` - -1. Apply the updated manifest, and query the status of the pod to ensure it completes. - Upon completion, the report is available in the web console. - - ```bash - # Apply the compliance report pod - kubectl apply -f compliance-reporter-pod.yaml - # Query the status of the pod - kubectl get pod -n=tigera-compliance - ``` - -:::note - -Manually-generated reports do not appear in GlobalReport status. - -::: - -### Troubleshooting - -**Problem**: Compliance reports can fail to generate if the `compliance-benchmarker` component cannot find the required `kubelet` or `kubectl` binaries to determine the Kubernetes version running on the cluster. - -**Solution or workaround**: If a node is running within a container (not running `kubelet` as a binary), make sure the `kubectl` binary is available in the `/usr/bin` directory. - -## Additional resources - -- For details on configuring and scheduling reports, see [Global reports](../reference/resources/globalreport.mdx) -- For other predefined compliance reports, see [Compliance reports](../reference/resources/compliance-reports/index.mdx) - -[parse-duration]: https://golang.org/pkg/time/#ParseDuration diff --git a/calico-enterprise/compliance/enable-compliance.mdx b/calico-enterprise/compliance/enable-compliance.mdx deleted file mode 100644 index 8c60a2c317..0000000000 --- a/calico-enterprise/compliance/enable-compliance.mdx +++ /dev/null @@ -1,49 +0,0 @@ ---- -description: Turn on the in-cluster compliance reporter, controller, snapshotter, and server components that produce Calico Enterprise compliance reports and CIS benchmarks. ---- - -# Enable compliance reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Enabling compliance reports improves the cluster's compliance posture. It involves generating compliance reports for Kubernetes clusters based on archived flow and audit logs for Calico Enterprise and Kubernetes resources. The process includes components for snapshotting configurations, generating reports, managing jobs, providing APIs with RBAC, and benchmarking security. - -## Value - -The compliance system consists of several key components that work together to ensure comprehensive compliance monitoring and reporting: - - - `compliance-snapshotter` : Lists required configurations and pushes snapshots to Elasticsearch, providing visibility into configuration changes. - - `compliance-reporter` : Generates reports by analyzing configuration history, determining configuration evolution and identifying "worst-case outliers." - - `compliance-controller` : Manages the creation, deletion, and monitoring of report generation jobs. - - `compliance-server` : Offers API for report management and enforces RBAC. - - `compliance-benchmarker` : Runs CIS Kubernetes Benchmark checks on each node to ensure secure deployment. - -**Required** - -* For managed clusters, ensure that compliance reporting is enabled in the management cluster. - -### Enable compliance reports using kubectl - -* Create a compliance custom resource, named `tigera-secure`, in the cluster. - -```bash -kubectl apply -f - < \ No newline at end of file diff --git a/calico-enterprise/compliance/index.mdx b/calico-enterprise/compliance/index.mdx index 4cf8b13d87..d561170195 100644 --- a/calico-enterprise/compliance/index.mdx +++ b/calico-enterprise/compliance/index.mdx @@ -1,19 +1,15 @@ --- -description: Generate compliance reports and encrypt in-cluster traffic in your Calico Enterprise cluster, with archived flow logs, audit logs, CIS benchmarks, and WireGuard. +description: Encrypt in-cluster traffic with WireGuard and configure security options for your Calico Enterprise cluster. hide_table_of_contents: true --- import { DocCardLink, DocCardLinkLayout } from '/src/___new___/components'; -# Compliance and security +# Security -Get reports on Kubernetes workloads and environments for regulatory compliance. -Encrypt traffic in your cluster with WireGuard. +Encrypt traffic in your cluster with WireGuard, and configure security options for your $[prodname] cluster. - - - diff --git a/calico-enterprise/compliance/overview.mdx b/calico-enterprise/compliance/overview.mdx deleted file mode 100644 index 1e4ac16448..0000000000 --- a/calico-enterprise/compliance/overview.mdx +++ /dev/null @@ -1,382 +0,0 @@ ---- -description: Schedule and run Calico Enterprise compliance reports against Kubernetes workloads using archived flow logs and audit logs stored in Elasticsearch. ---- - -# Schedule and run compliance reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Schedule and run compliance reports to assess Kubernetes workloads and environments for regulatory compliance. - -## Value - -Compliance tools that rely on periodic snapshots, do not provide accurate assessments of Kubernetes workloads against your compliance standards. $[prodname] compliance dashboard and reports provide a complete inventory of regulated workloads, along with evidence of enforcement of network controls for these workloads. Additionally, audit reports are available to see changes to any network security controls. - -## Concepts - -### Compliance reports at a glance - -Compliance report are based on archived flow logs and audit logs for all of your $[prodname] resources, plus any audit logs you've configured for Kubernetes resources in the Kubernetes API server: - -- Pods -- Host endpoints -- Service accounts -- Namespaces -- Kubernetes service endpoints -- Global network sets -- Calico and Kubernetes network policies -- Global network policies - -Compliance reports provide the following high-level information: - -- **Protection** - - - Endpoints explicitly protected using ingress or egress policy - - Endpoints with Envoy enabled - -- **Policies and services** - - - Policies and services associated with endpoints - - Policy audit logs - -- **Traffic** - - Allowed ingress/egress traffic to/from namespaces - - Allowed ingress/egress traffic to/from the internet - -![compliance-reporting](/img/calico-enterprise/compliance-reporting.png) - -## Before you begin - -**Unsupported** - -- AKS -- GKE -- OpenShift -- TKG - -**Required** - -* You [Enabled compliance reports](../compliance/enable-compliance) - -- Ensure that all nodes in your Kubernetes clusters are time-synchronized using NTP or similar (for accurate audit log timestamps) - -- [Configure audit logs for Kubernetes resources](../observability/elastic/audit-overview.mdx) - - You must configure audit logs for Kubernetes resources through the Kubernetes API to get a complete view of all resources. - -## How to - -- [Configure report permissions](#configure-report-permissions) -- [Configure and schedule reports](#configure-and-schedule-reports) -- [View report generation status](#view-report-generation-status) -- [Run reports](#run-reports) - -### Configure report permissions - -Report permissions are granted using the standard Kubernetes RBAC based on ClusterRole and ClusterRoleBindings. The following table outlines the required RBAC verbs for each resource type for a specific user actions. - -| **Action** | **globalreporttypes** | **globalreports** | **globalreports/status** | -| ------------------------------------------------------- | ------------------------------- | --------------------------------- | ------------------------ | -| Manage reports (create/modify/delete) | | \* | get | -| View status of report generation through kubectl | | get | get | -| List the generated reports and summary status in the UI | | list + get (for required reports) | | -| Export the generated reports from the UI | get (for the particular report) | get (for required reports) | | - -The following sample manifest creates RBAC for three users: Paul, Candice and David. - -- Paul has permissions to create/modify/delete the report schedules and configuration, but does not have permission to export generated reports from the UI. -- Candice has permissions to list and export generated reports from the UI, but cannot modify the report schedule or configuration. -- David has permissions to list and export generated `dev-inventory` reports from the UI, but cannot list or download other reports, nor modify the report - schedule or configuration. - -```yaml -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-manage-report-config -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['*'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreports/status'] - verbs: ['get', 'list', 'watch'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-manage-report-config -subjects: - - kind: User - name: paul - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-manage-report-config - apiGroup: rbac.authorization.k8s.io - ---- -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-all-reports -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['get', 'list'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreporttypes'] - verbs: ['get'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-all-reports -subjects: - - kind: User - name: candice - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-list-download-all-reports - apiGroup: rbac.authorization.k8s.io - ---- -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-dev-inventory -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['list'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['get'] - resourceNames: ['dev-inventory'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreporttypes'] - verbs: ['get'] - resourceNames: ['dev-inventory'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-dev-inventory -subjects: - - kind: User - name: david - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-list-download-dev-inventory - apiGroup: rbac.authorization.k8s.io -``` - -### Configure and schedule reports - -To configure and schedule a compliance report, create a [GlobalReport](../reference/resources/globalreport.mdx) with the following information. - -| **Fields** | **Description** | -| --------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| name | Unique name for your report. | -| reportType | One of the following predefined report types: `inventory`, `network-access`, `policy-audit`. | -| schedule | The start and end time of the report using [crontab format](https://en.wikipedia.org/wiki/Cron). To allow for archiving, reports are generated approximately 30 minutes after the end time. A single report is limited to a maximum of two per hour. | -| endpoints | **Optional**. For inventory and network-access reports, specifies the endpoints to include in the report. For the policy-audit report, restricts audit logs to include only policies that apply to the selected endpoints. If not specified, the report includes all endpoints and audit logs. | -| jobNodeSelector | **Optional**. Limits report generation jobs to specific nodes. | -| suspend | **Optional**. Suspends report generation. All in-flight reports will complete, and future scheduled reports are suspended. | - -:::note - -GlobalReports can only be configured using kubectl (not calicoctl); and they cannot be edited in the Tigera -Secure EE the web console. - -::: - -The following sections provide sample schedules for the predefined reports. - -### Weekly reports, all endpoints - -The following report schedules weekly inventory reports for _all_ endpoints. The jobs that create the reports will run -on the infrastructure nodes (e.g. nodetype == 'infrastructure'). - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: weekly-full-inventory -spec: - reportType: inventory - schedule: 0 0 * * 0 - jobNodeSelector: - nodetype: infrastructure -``` - -### Daily reports, selected endpoints - -The following report schedules daily inventory reports for production endpoints (e.g. deployment == ‘production’). - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-production-inventory -spec: - reportType: inventory - endpoints: - selector: deployment == 'production' - schedule: 0 0 * * * -``` - -### Hourly reports, endpoints in named namespaces - -The following report schedules hourly network-access reports for the accounts department endpoints, that are -specified using the namespace names: **payable**, **collections** and **payroll**. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: hourly-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - names: ['payable', 'collections', 'payroll'] - schedule: 0 * * * * -``` - -### Daily reports, endpoints in selected namespaces - -The following report schedules daily network-access reports for the accounts department with endpoints specified using -a namespace selector. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - selector: department == 'accounts' - schedule: 0 0 * * * -``` - -### Monthly reports, endpoints for named service accounts in named namespaces - -The following schedules monthly audit reports. The audited policy is restricted to policy that applies to -widgets/controller endpoints specified by the namespace **widgets** and service account **controller**. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: monthly-widgets-controller-tigera-policy-audit -spec: - reportType: policy-audit - schedule: 0 0 1 * * - endpoints: - serviceAccounts: - names: ['controller'] - namespaces: - names: ['widgets'] -``` - -### View report generation status - -To view the status of a report, you must use the `kubectl` command. For example: - -```bash -kubectl get globalreports.projectcalico.org daily-inventory.p -o yaml -``` - -In a report, the job status types are: - -- **lastScheduledReportJob**: - The most recently scheduled job for generating the report. Because reports are scheduled in order, the “end time” of - this report will be the “start time” of the next scheduled report. -- **activeReportJobs**: - Default = allows up to 5 concurrent report generation jobs. -- **lastFailedReportJobs**: - Default = keeps the 3 most recent failed jobs and deletes older ones. A single report generation job will be retried - up to 6 times (by default) before it is marked as failed. -- **lastSuccessfulReportJobs**: - Default = keeps the 2 most recent successful jobs and deletes older ones. - -### Change the default report generation time - -By default, reports are generated 30 minutes after the end of the report, to ensure all of the audit data is archived. -(However, this gap does not affect the data collected “start/end time” for a report.) - -You can adjust the time for audit data for cases like initial report testing, to demo a report, or when manually -creating a report that is not counted in global report status. - -To change the delay, go to the installation manifest, and uncomment and set the environment -`TIGERA_COMPLIANCE_JOB_START_DELAY`. Specify value as a [Duration string][parse-duration]. - -### Run reports - -You can run reports at any time to specify a different start/end time, and if a scheduled report fails. - -$[prodname] GlobalReport schedules Kubernetes Jobs, which create a single-run pod to generate a report and store it -in Elasticsearch. Because you need to run reports as a pod, you need higher permissions: allow `create` access for pods in namespace `tigera-compliance` using the `tigera-compliance-reporter` service account. - -To run a report on demand: - -1. Download the pod template corresponding to your installation method. - - For management and standalone clusters: - - ```bash - curl -O $[filesUrl]/manifests/compliance-reporter-pod.yaml - ``` - - For managed clusters: - - ```bash - curl $[filesUrl]/manifests/compliance-reporter-pod-managed.yaml -o compliance-reporter-pod.yaml - ``` - -1. Edit the template as follows: - - Edit the pod name if required. - - If you are using your own docker repository, update the container image name with your repo and image tag. - - Set the following environments according to the instructions in the downloaded manifest: - - `TIGERA_COMPLIANCE_REPORT_NAME` - - `TIGERA_COMPLIANCE_REPORT_START_TIME` - - `TIGERA_COMPLIANCE_REPORT_END_TIME` -1. Apply the updated manifest, and query the status of the pod to ensure it completes. - Upon completion, the report is available in the $[prodname] web console. - - ```bash - # Apply the compliance report pod - kubectl apply -f compliance-reporter-pod.yaml - - # Query the status of the pod - kubectl get pod -n tigera-compliance - ``` - -:::note - -Manually-generated reports do not appear in GlobalReport status. - -::: - -## Additional resources - -- For details on configuring and scheduling reports, see [Global reports](../reference/resources/globalreport.mdx) -- For report field descriptions, see [Compliance reports](../reference/resources/compliance-reports/index.mdx) -- [CIS benchmarks](compliance-reports-cis.mdx) - -[parse-duration]: https://golang.org/pkg/time/#ParseDuration diff --git a/calico-enterprise/observability/get-started-cem.mdx b/calico-enterprise/observability/get-started-cem.mdx index 2910289ad2..5ca9a5357e 100644 --- a/calico-enterprise/observability/get-started-cem.mdx +++ b/calico-enterprise/observability/get-started-cem.mdx @@ -111,20 +111,6 @@ This page is where you switch views between clusters in the web console. When yo ![managed-clusters](/img/calico-enterprise/managed-clusters.png) -## Compliance Reports - -> From the left navbar, click **Compliance**. - -Compliance tools that rely on periodic snapshots, do not provide accurate assessments of Kubernetes workloads against your compliance standards. $[prodname] compliance dashboard and reports provide a complete inventory of regulated workloads, along with evidence of enforcement of network controls for these workloads. Additionally, audit reports are available to see changes to any network security controls. - -**Compliance reports** are based on archived flow logs and audit logs for all $[prodname] resources, and audit logs for Kubernetes resources in the Kubernetes API server. - -![cis-benchmark](/img/calico-enterprise/cis-benchmark.png) - -Using the filter, you can select report types. - -![compliance-filter](/img/calico-enterprise/compliance-filter.png) - ## Activity > From the left navbar, select **Activity**, **Timeline**. diff --git a/calico-enterprise/operations/cnx/roles-and-permissions.mdx b/calico-enterprise/operations/cnx/roles-and-permissions.mdx index 3e88e18a39..1c183ccad2 100644 --- a/calico-enterprise/operations/cnx/roles-and-permissions.mdx +++ b/calico-enterprise/operations/cnx/roles-and-permissions.mdx @@ -21,7 +21,6 @@ The [Calico Enterprise API server](../../reference/installation/api.mdx#apiserve | Features | RBAC controls for... | | ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Network policy | - Tiered policy, including AWS security groups and federated services.
- Kubernetes network policy (in default tier)
- $[prodname] network policies including namespaces
- Staged policy, policy recommendation, policy preview | -| Compliance | Report management, generation, export, and status. | | Visibility and troubleshooting | Elasticsearch logs: flow, audit, dns, intrusion detection, bgp | | Multi-cluster management | Management and managed clusters in single management plane. | @@ -47,5 +46,4 @@ For RBAC details on any given feature, see the feature. For example: - [Policy preview RBAC](../../network-policy/policy-impact-preview.mdx) - [Staged policy RBAC](../../network-policy/staged-network-policies.mdx) - [Elasticsearch logs RBAC](../../observability/elastic/rbac-elasticsearch.mdx) -- [Compliance reports RBAC](../../compliance/overview.mdx) - [Multi-cluster management RBAC](../../multicluster/set-up-multi-cluster-management/standard-install/create-a-management-cluster.mdx) diff --git a/calico-enterprise/operations/troubleshoot/troubleshooting.mdx b/calico-enterprise/operations/troubleshoot/troubleshooting.mdx index 31c9f17327..08bf914c5c 100644 --- a/calico-enterprise/operations/troubleshoot/troubleshooting.mdx +++ b/calico-enterprise/operations/troubleshoot/troubleshooting.mdx @@ -141,13 +141,6 @@ sysctl -w net.netfilter.nf_conntrack_max=1000000 echo "net.netfilter.nf_conntrack_max=1000000" >> /etc/sysctl.conf ``` -## Compliance report is not generating at expected time - -By design, reports are scheduled to generate 30 minutes after the specified end time. The reason for this is to allow a certain amount of -time to pass for all the relevant data within the specified start and end time to be fully processed and stored. This delay can be modified -by setting the `TIGERA_COMPLIANCE_JOB_START_DELAY` environment variable on the `compliance-controller` deployment to the -desired [Golang duration](https://godoc.org/time#Duration). - ## GlobalAlert reports error "Trying to create too many buckets" ``` diff --git a/calico-enterprise/reference/index.mdx b/calico-enterprise/reference/index.mdx index 3e2808cdc5..726992ad39 100644 --- a/calico-enterprise/reference/index.mdx +++ b/calico-enterprise/reference/index.mdx @@ -74,11 +74,6 @@ APIs, CLI, architecture and design, and FAQ. - - - - - @@ -87,7 +82,6 @@ APIs, CLI, architecture and design, and FAQ. - diff --git a/calico-enterprise/reference/installation/_api.mdx b/calico-enterprise/reference/installation/_api.mdx index 581bf232e7..943cd61444 100644 --- a/calico-enterprise/reference/installation/_api.mdx +++ b/calico-enterprise/reference/installation/_api.mdx @@ -14,7 +14,6 @@ Resource Types - [APIServer](#apiserver) - [ApplicationLayer](#applicationlayer) - [Authentication](#authentication) -- [Compliance](#compliance) - [EgressGateway](#egressgateway) - [GatewayAPI](#gatewayapi) - [Goldmane](#goldmane) @@ -1260,486 +1259,6 @@ _Appears in:_ | `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | Define resources requests and limits for single Pods. | -### Compliance - - - -Compliance installs the components required for Tigera compliance reporting. At most one instance -of this resource is supported. It must be named "tigera-secure". - -| Field | Description | -| --- | --- | -| `apiVersion` _string_ | `operator.tigera.io/v1` | -| `kind` _string_ | `Compliance` | -| `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | -| `spec` _[ComplianceSpec](#compliancespec)_ | Specification of the desired state for Tigera compliance reporting. | -| `status` _[ComplianceStatus](#compliancestatus)_ | Most recently observed state for Tigera compliance reporting. | - - -### ComplianceBenchmarkerDaemonSet - - - -ComplianceBenchmarkerDaemonSet is the configuration for the Compliance Benchmarker DaemonSet. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceBenchmarkerDaemonSetSpec](#compliancebenchmarkerdaemonsetspec)_ | (Optional) Spec is the specification of the Compliance Benchmarker DaemonSet. | - - -### ComplianceBenchmarkerDaemonSetContainer - - - -ComplianceBenchmarkerDaemonSetContainer is a Compliance Benchmarker DaemonSet container. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the Compliance Benchmarker DaemonSet container by name.
Supported values are: compliance-benchmarker | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named Compliance Benchmarker DaemonSet container's resources. If omitted, the Compliance Benchmarker DaemonSet will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceBenchmarkerDaemonSetInitContainer - - - -ComplianceBenchmarkerDaemonSetInitContainer is a Compliance Benchmarker DaemonSet init container. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the Compliance Benchmarker DaemonSet init container by name.
Supported values are: tigera-compliance-benchmarker-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named Compliance Benchmarker DaemonSet init container's resources. If omitted, the Compliance Benchmarker DaemonSet will use its default value for this init container's resources. | - - -### ComplianceBenchmarkerDaemonSetPodSpec - - - -ComplianceBenchmarkerDaemonSetPodSpec is the Compliance Benchmarker DaemonSet's PodSpec. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodTemplateSpec](#compliancebenchmarkerdaemonsetpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceBenchmarkerDaemonSetInitContainer](#compliancebenchmarkerdaemonsetinitcontainer) array_ | (Optional) InitContainers is a list of Compliance benchmark init containers. If specified, this overrides the specified Compliance Benchmarker DaemonSet init containers. If omitted, the Compliance Benchmarker DaemonSet will use its default values for its init containers. | -| `containers` _[ComplianceBenchmarkerDaemonSetContainer](#compliancebenchmarkerdaemonsetcontainer) array_ | (Optional) Containers is a list of Compliance benchmark containers. If specified, this overrides the specified Compliance Benchmarker DaemonSet containers. If omitted, the Compliance Benchmarker DaemonSet will use its default values for its containers. | - - -### ComplianceBenchmarkerDaemonSetPodTemplateSpec - - - -ComplianceBenchmarkerDaemonSetPodTemplateSpec is the Compliance Benchmarker DaemonSet's PodTemplateSpec - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetSpec](#compliancebenchmarkerdaemonsetspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec)_ | (Optional) Spec is the Compliance Benchmarker DaemonSet's PodSpec. | - - -### ComplianceBenchmarkerDaemonSetSpec - - - -ComplianceBenchmarkerDaemonSetSpec defines configuration for the Compliance Benchmarker DaemonSet. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSet](#compliancebenchmarkerdaemonset) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceBenchmarkerDaemonSetPodTemplateSpec](#compliancebenchmarkerdaemonsetpodtemplatespec)_ | (Optional) Template describes the Compliance Benchmarker DaemonSet pod that will be created. | - - -### ComplianceControllerDeployment - - - -ComplianceControllerDeployment is the configuration for the compliance controller Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceControllerDeploymentSpec](#compliancecontrollerdeploymentspec)_ | (Optional) Spec is the specification of the compliance controller Deployment. | - - -### ComplianceControllerDeploymentContainer - - - -ComplianceControllerDeploymentContainer is a compliance controller Deployment container. - -_Appears in:_ -- [ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance controller Deployment container by name.
Supported values are: compliance-controller | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance controller Deployment container's resources. If omitted, the compliance controller Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceControllerDeploymentInitContainer - - - -ComplianceControllerDeploymentInitContainer is a compliance controller Deployment init container. - -_Appears in:_ -- [ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance controller Deployment init container by name.
Supported values are: tigera-compliance-controller-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance controller Deployment init container's resources. If omitted, the compliance controller Deployment will use its default value for this init container's resources. | - - -### ComplianceControllerDeploymentPodSpec - - - -ComplianceControllerDeploymentPodSpec is the compliance controller Deployment's PodSpec. - -_Appears in:_ -- [ComplianceControllerDeploymentPodTemplateSpec](#compliancecontrollerdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceControllerDeploymentInitContainer](#compliancecontrollerdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of compliance controller init containers. If specified, this overrides the specified compliance controller Deployment init containers. If omitted, the compliance controller Deployment will use its default values for its init containers. | -| `containers` _[ComplianceControllerDeploymentContainer](#compliancecontrollerdeploymentcontainer) array_ | (Optional) Containers is a list of compliance controller containers. If specified, this overrides the specified compliance controller Deployment containers. If omitted, the compliance controller Deployment will use its default values for its containers. | - - -### ComplianceControllerDeploymentPodTemplateSpec - - - -ComplianceControllerDeploymentPodTemplateSpec is the compliance controller Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceControllerDeploymentSpec](#compliancecontrollerdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec)_ | (Optional) Spec is the compliance controller Deployment's PodSpec. | - - -### ComplianceControllerDeploymentSpec - - - -ComplianceControllerDeploymentSpec defines configuration for the compliance controller Deployment. - -_Appears in:_ -- [ComplianceControllerDeployment](#compliancecontrollerdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceControllerDeploymentPodTemplateSpec](#compliancecontrollerdeploymentpodtemplatespec)_ | (Optional) Template describes the compliance controller Deployment pod that will be created. | - - -### ComplianceReporterPodSpec - - - -ComplianceReporterPodSpec is the ComplianceReporter PodSpec. - -_Appears in:_ -- [ComplianceReporterPodTemplateSpec](#compliancereporterpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceReporterPodTemplateInitContainer](#compliancereporterpodtemplateinitcontainer) array_ | (Optional) InitContainers is a list of ComplianceReporter PodSpec init containers. If specified, this overrides the specified ComplianceReporter PodSpec init containers. If omitted, the ComplianceServer Deployment will use its default values for its init containers. | -| `containers` _[ComplianceReporterPodTemplateContainer](#compliancereporterpodtemplatecontainer) array_ | (Optional) Containers is a list of ComplianceServer containers. If specified, this overrides the specified ComplianceReporter PodSpec containers. If omitted, the ComplianceServer Deployment will use its default values for its containers. | - - -### ComplianceReporterPodTemplate - - - -ComplianceReporterPodTemplate is the configuration for the ComplianceReporter PodTemplate. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceReporterPodTemplateSpec](#compliancereporterpodtemplatespec)_ | (Optional) Spec is the specification of the ComplianceReporter PodTemplateSpec. | - - -### ComplianceReporterPodTemplateContainer - - - -ComplianceReporterPodTemplateContainer is a ComplianceServer Deployment container. - -_Appears in:_ -- [ComplianceReporterPodSpec](#compliancereporterpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment container by name.
Supported values are: reporter | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment container's resources. If omitted, the ComplianceServer Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceReporterPodTemplateInitContainer - - - -ComplianceReporterPodTemplateInitContainer is a ComplianceServer Deployment init container. - -_Appears in:_ -- [ComplianceReporterPodSpec](#compliancereporterpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceReporter PodSpec init container by name.
Supported values are: tigera-compliance-reporter-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceReporter PodSpec init container's resources. If omitted, the ComplianceServer Deployment will use its default value for this init container's resources. | - - -### ComplianceReporterPodTemplateSpec - - - -ComplianceReporterPodTemplateSpec is the ComplianceReporter PodTemplateSpec. - -_Appears in:_ -- [ComplianceReporterPodTemplate](#compliancereporterpodtemplate) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceReporterPodSpec](#compliancereporterpodspec)_ | (Optional) Spec is the ComplianceReporter PodTemplate's PodSpec. | - - -### ComplianceServerDeployment - - - -ComplianceServerDeployment is the configuration for the ComplianceServer Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceServerDeploymentSpec](#complianceserverdeploymentspec)_ | (Optional) Spec is the specification of the ComplianceServer Deployment. | - - -### ComplianceServerDeploymentContainer - - - -ComplianceServerDeploymentContainer is a ComplianceServer Deployment container. - -_Appears in:_ -- [ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment container by name.
Supported values are: compliance-server | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment container's resources. If omitted, the ComplianceServer Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceServerDeploymentInitContainer - - - -ComplianceServerDeploymentInitContainer is a ComplianceServer Deployment init container. - -_Appears in:_ -- [ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment init container by name.
Supported values are: tigera-compliance-server-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment init container's resources. If omitted, the ComplianceServer Deployment will use its default value for this init container's resources. | - - -### ComplianceServerDeploymentPodSpec - - - -ComplianceServerDeploymentPodSpec is the ComplianceServer Deployment's PodSpec. - -_Appears in:_ -- [ComplianceServerDeploymentPodTemplateSpec](#complianceserverdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceServerDeploymentInitContainer](#complianceserverdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of ComplianceServer init containers. If specified, this overrides the specified ComplianceServer Deployment init containers. If omitted, the ComplianceServer Deployment will use its default values for its init containers. | -| `containers` _[ComplianceServerDeploymentContainer](#complianceserverdeploymentcontainer) array_ | (Optional) Containers is a list of ComplianceServer containers. If specified, this overrides the specified ComplianceServer Deployment containers. If omitted, the ComplianceServer Deployment will use its default values for its containers. | - - -### ComplianceServerDeploymentPodTemplateSpec - - - -ComplianceServerDeploymentPodTemplateSpec is the ComplianceServer Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceServerDeploymentSpec](#complianceserverdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec)_ | (Optional) Spec is the ComplianceServer Deployment's PodSpec. | - - -### ComplianceServerDeploymentSpec - - - -ComplianceServerDeploymentSpec defines configuration for the ComplianceServer Deployment. - -_Appears in:_ -- [ComplianceServerDeployment](#complianceserverdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceServerDeploymentPodTemplateSpec](#complianceserverdeploymentpodtemplatespec)_ | (Optional) Template describes the ComplianceServer Deployment pod that will be created. | - - -### ComplianceSnapshotterDeployment - - - -ComplianceSnapshotterDeployment is the configuration for the compliance snapshotter Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceSnapshotterDeploymentSpec](#compliancesnapshotterdeploymentspec)_ | (Optional) Spec is the specification of the compliance snapshotter Deployment. | - - -### ComplianceSnapshotterDeploymentContainer - - - -ComplianceSnapshotterDeploymentContainer is a compliance snapshotter Deployment container. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance snapshotter Deployment container by name.
Supported values are: compliance-snapshotter | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance snapshotter Deployment container's resources. If omitted, the compliance snapshotter Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceSnapshotterDeploymentInitContainer - - - -ComplianceSnapshotterDeploymentInitContainer is a compliance snapshotter Deployment init container. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance snapshotter Deployment init container by name.
Supported values are: tigera-compliance-snapshotter-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance snapshotter Deployment init container's resources. If omitted, the compliance snapshotter Deployment will use its default value for this init container's resources. | - - -### ComplianceSnapshotterDeploymentPodSpec - - - -ComplianceSnapshotterDeploymentPodSpec is the compliance snapshotter Deployment's PodSpec. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodTemplateSpec](#compliancesnapshotterdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceSnapshotterDeploymentInitContainer](#compliancesnapshotterdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of compliance snapshotter init containers. If specified, this overrides the specified compliance snapshotter Deployment init containers. If omitted, the compliance snapshotter Deployment will use its default values for its init containers. | -| `containers` _[ComplianceSnapshotterDeploymentContainer](#compliancesnapshotterdeploymentcontainer) array_ | (Optional) Containers is a list of compliance snapshotter containers. If specified, this overrides the specified compliance snapshotter Deployment containers. If omitted, the compliance snapshotter Deployment will use its default values for its containers. | - - -### ComplianceSnapshotterDeploymentPodTemplateSpec - - - -ComplianceSnapshotterDeploymentPodTemplateSpec is the compliance snapshotter Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceSnapshotterDeploymentSpec](#compliancesnapshotterdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec)_ | (Optional) Spec is the compliance snapshotter Deployment's PodSpec. | - - -### ComplianceSnapshotterDeploymentSpec - - - -ComplianceSnapshotterDeploymentSpec defines configuration for the compliance snapshotter Deployment. - -_Appears in:_ -- [ComplianceSnapshotterDeployment](#compliancesnapshotterdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceSnapshotterDeploymentPodTemplateSpec](#compliancesnapshotterdeploymentpodtemplatespec)_ | (Optional) Template describes the compliance snapshotter Deployment pod that will be created. | - - -### ComplianceSpec - - - -ComplianceSpec defines the desired state of Tigera compliance reporting capabilities. - -_Appears in:_ -- [Compliance](#compliance) - -| Field | Description | -| --- | --- | -| `complianceControllerDeployment` _[ComplianceControllerDeployment](#compliancecontrollerdeployment)_ | (Optional) ComplianceControllerDeployment configures the Compliance Controller Deployment. | -| `complianceSnapshotterDeployment` _[ComplianceSnapshotterDeployment](#compliancesnapshotterdeployment)_ | (Optional) ComplianceSnapshotterDeployment configures the Compliance Snapshotter Deployment. | -| `complianceBenchmarkerDaemonSet` _[ComplianceBenchmarkerDaemonSet](#compliancebenchmarkerdaemonset)_ | (Optional) ComplianceBenchmarkerDaemonSet configures the Compliance Benchmarker DaemonSet. | -| `complianceServerDeployment` _[ComplianceServerDeployment](#complianceserverdeployment)_ | (Optional) ComplianceServerDeployment configures the Compliance Server Deployment. | -| `complianceReporterPodTemplate` _[ComplianceReporterPodTemplate](#compliancereporterpodtemplate)_ | (Optional) ComplianceReporterPodTemplate configures the Compliance Reporter PodTemplate. | - - -### ComplianceStatus - - - -ComplianceStatus defines the observed state of Tigera compliance reporting capabilities. - -_Appears in:_ -- [Compliance](#compliance) - -| Field | Description | -| --- | --- | -| `state` _string_ | State provides user-readable status. | -| `conditions` _[Condition](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#condition-v1-meta) array_ | (Optional) Conditions represents the latest observed set of conditions for the component. A component may be one or more of Ready, Progressing, Degraded or other customer types. | - - ### ComponentName _Underlying type:_ _string_ @@ -5644,11 +5163,6 @@ _Appears in:_ - [CalicoNodeWindowsDaemonSetContainer](#caliconodewindowsdaemonsetcontainer) - [CalicoWebhooksDeploymentContainer](#calicowebhooksdeploymentcontainer) - [CalicoWindowsUpgradeDaemonSetContainer](#calicowindowsupgradedaemonsetcontainer) -- [ComplianceBenchmarkerDaemonSetContainer](#compliancebenchmarkerdaemonsetcontainer) -- [ComplianceControllerDeploymentContainer](#compliancecontrollerdeploymentcontainer) -- [ComplianceReporterPodTemplateContainer](#compliancereporterpodtemplatecontainer) -- [ComplianceServerDeploymentContainer](#complianceserverdeploymentcontainer) -- [ComplianceSnapshotterDeploymentContainer](#compliancesnapshotterdeploymentcontainer) - [DashboardsJobContainer](#dashboardsjobcontainer) - [DexDeploymentContainer](#dexdeploymentcontainer) - [ECKOperatorStatefulSetContainer](#eckoperatorstatefulsetcontainer) diff --git a/calico-enterprise/reference/installation/_crd-ref-docs/config.yaml b/calico-enterprise/reference/installation/_crd-ref-docs/config.yaml index fd123b9c48..e7b0103bba 100644 --- a/calico-enterprise/reference/installation/_crd-ref-docs/config.yaml +++ b/calico-enterprise/reference/installation/_crd-ref-docs/config.yaml @@ -3,6 +3,7 @@ processor: ignoreTypes: - "List$" - "Tenant*" + - "^Compliance" # RE2 regular expressions describing type fields that should be excluded from the generated documentation. ignoreFields: - "TypeMeta$" diff --git a/calico-enterprise/reference/installation/helm_customization.mdx b/calico-enterprise/reference/installation/helm_customization.mdx index f9595a106e..92d4e6064f 100644 --- a/calico-enterprise/reference/installation/helm_customization.mdx +++ b/calico-enterprise/reference/installation/helm_customization.mdx @@ -8,7 +8,6 @@ You can customize the following resources and settings during $[prodname] Helm-b - [Installation](api.mdx#installationspec) - [Api server](api.mdx#apiserverspec) -- [Compliance](api.mdx#compliancespec) - [Intrusion detection](api.mdx#intrusiondetectionspec) - [Log collector](api.mdx#logcollectorspec) - [Log storage](api.mdx#logstoragespec) @@ -63,10 +62,6 @@ monitor: enabled: true -compliance: - enabled: true - - policyRecommendation: enabled: true @@ -120,8 +115,6 @@ You can define pod affinity for the following Tigera components. Update the appr - calico-apiserver: through ApiServer resource - calico-nodes: through CalicoNodeDaemonSet property in the Installation resource - calico-kube-controllers: through CalicoKubeControllersDeployment property in the Installation resource -- compliance deployment pods (compliance-snapshotter, compliance-server, compliance-controller, compliance-benchmarker, -compliance-scaleloader, compliance-reporter): through Compliance resource - elasticsearch pods: through LogStorage resource - for more info on this option please checkout [Advanced Node Scheduling](../../operations/logstorage/advanced-node-scheduling.mdx) ### Encryption using WireGuard diff --git a/calico-enterprise/reference/installation/tigerastatus.mdx b/calico-enterprise/reference/installation/tigerastatus.mdx index cf68a274d2..aaef840282 100644 --- a/calico-enterprise/reference/installation/tigerastatus.mdx +++ b/calico-enterprise/reference/installation/tigerastatus.mdx @@ -11,7 +11,6 @@ Installing $[prodname] on your Kubernetes cluster is managed by the Tigera Opera - authentication - calico - calico-windows -- compliance - egressgateway - intrusion detection - log-collector @@ -40,7 +39,7 @@ For detailed output (including messages and further details on any non-functioni ## Log storage -Log storage provides persistent storage for $[prodname] Elasticsearch logs (flow, dns, l7, bgp, audit, etc.), and compliance reports. +Log storage provides persistent storage for $[prodname] Elasticsearch logs (flow, dns, l7, bgp, audit, etc.). To check log storage status, run the following command: diff --git a/calico-enterprise/reference/resources/compliance-reports/cis-benchmark.mdx b/calico-enterprise/reference/resources/compliance-reports/cis-benchmark.mdx deleted file mode 100644 index 92184ddb25..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/cis-benchmark.mdx +++ /dev/null @@ -1,71 +0,0 @@ ---- -description: Reference for the CIS benchmark compliance report in Calico Enterprise that audits Kubernetes nodes against CIS recommendations. ---- - -# CIS benchmark report - -To create a CIS benchmark report, create a `GlobalReport` with the `reportType` set to `cis-benchmark`. - -The following sample command uses a GlobalReport to create a daily CIS benchmark report that run on all the nodes. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-benchmark-report -spec: - reportType: cis-benchmark - schedule: 0 0 * * * -EOF -``` - -## OpenShift - -While there is no extra setup configuration required by the user to generate a benchmark report for OpenShift, the result sets will be different than a report generated for regular Kubernetes clusters. Use the [OpenShift Container Platform Security Guide](https://static.open-scap.org/ssg-guides/ssg-ocp4-guide-index.html) to cross-reference the benchmark results. - -## Downloadable reports - -## total-summary.csv - -A textual representation of the dashboard. - -| Heading | Description | Format | -| ---------------------- | ----------------------------------------------------------------- | -------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval start time. | RFC3339 string | -| type | The type of benchmark report | string | -| hiPercentageThreshold | The percentage of passing tests required to rate a node as high | int | -| medPercentageThreshold | The percentage of passing tests required to rate a node as medium | int | -| hiNodeCount | The number of nodes rated as high | int | -| medNodeCount | The number of nodes rated as medium | int | -| lowNodeCount | The number of nodes rated as low | int | - -## node-summary.csv - -A .csv file of test result summaries per node. - -| Heading | Description | Format | -| ------------ | ---------------------------------------------------------------------------------- | ------ | -| node | The name of the node. | string | -| version | The version of the platform. | string | -| status | The rating of the node based on percentage of tests passing. | string | -| testsPassing | The number of tests passing. | int | -| testsFailing | The number of tests failing. | int | -| testsUnknown | The number of tests whose results are undetermined due to automation restrictions. | int | -| testsTotal | The total number of tests executed. | int | - -### failed-tests.csv - -A .csv file of tests that have failed. - -| Heading | Description | Format | -| --------- | -------------------------------------------------------------------------------------- | ------ | -| nodeName | Node where the test is executed. | string | -| testIndex | Index of the test on the Kubernetes CIS benchmark. | string | -| status | Test results: PASS, FAIL, INFO. | string | -| scored | Indicates whether the Kubernetes CIS benchmark counts this test towards their scoring. | string | - -### all-tests.csv - -A .csv file with tests that were executed on all nodes. Format remains the same as above. diff --git a/calico-enterprise/reference/resources/compliance-reports/index.mdx b/calico-enterprise/reference/resources/compliance-reports/index.mdx deleted file mode 100644 index deb390a14f..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/index.mdx +++ /dev/null @@ -1,11 +0,0 @@ ---- -description: Reference index for compliance report types available with Calico Enterprise covering inventory, network access, policy audit, and CIS benchmark. -hide_table_of_contents: true ---- - -# Compliance reports (deprecated) - -import DocCardList from '@theme/DocCardList'; -import { useCurrentSidebarCategory } from '@docusaurus/theme-common'; - - diff --git a/calico-enterprise/reference/resources/compliance-reports/inventory.mdx b/calico-enterprise/reference/resources/compliance-reports/inventory.mdx deleted file mode 100644 index 4e2585393d..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/inventory.mdx +++ /dev/null @@ -1,86 +0,0 @@ ---- -description: Reference for the inventory compliance report in Calico Enterprise that catalogs endpoints, namespaces, and policies in scope at report time. ---- - -# Inventory report - -To create an Inventory report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `inventory`. - -The following sample command creates a GlobalReport that results in a daily inventory report for -endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-inventory-report - labels: - deployment: production -spec: - reportType: inventory - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ----------------------------- | ----------------------------------------------------------------------------------------------------------- | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| endpointsNumInScope | The number of enumerated endpoints that are in-scope according to the requested endpoint selection options. | number | -| endpointsNumIngressProtected | The number of in-scope endpoints that were always ingress protected during the report interval. | number | -| endpointsNumEgressProtected | The number of in-scope endpoints that were always egress protected during the report interval. | number | -| namespacesNumInScope | The number of namespaces containing in-scope endpoints. | number | -| namespacesNumIngressProtected | The number of namespaces whose in-scope endpoints were always ingress protected during the report interval. | number | -| namespacesNumEgressProtected | The number of namespaces whose in-scope endpoints were always egress protected during the report interval. | number | -| serviceAccountsNumInScope | The number of service accounts associated with in-scope endpoints. | number | - -### endpoints.csv - -An endpoints CSV file that includes per-endpoint information. - -| Heading | Description | Format | -| ---------------- | --------------------------------------------------------------------------------------------- | ----------------------------------- | -| endpoint | The name of the endpoint. | string | -| ingressProtected | Whether the endpoint was always ingress protected during the report interval. | bool | -| egressProtected | Whether the endpoint was always egress protected during the report interval. | bool | -| envoyEnabled | Whether the endpoint was always Envoy enabled during the report interval. | bool | -| appliedPolicies | The full set of policies that applied to the endpoint at any time during the report interval. | ";" separated list of policy names | -| services | The full set of services that included this endpoint at any time during the report interval. | ";" separated list of service names | - -### namespaces.csv - -A namespaces CSV file that includes per-namespace information. - -| Heading | Description | Format | -| ---------------- | ------------------------------------------------------------------------------------------------------------- | ------ | -| namespace | The name of the namespace. | string | -| ingressProtected | Whether all in-scope endpoints within the namespace were always ingress protected during the report interval. | bool | -| egressProtected | Whether all in-scope endpoints within the namespace were always egress protected during the report interval. | bool | -| envoyEnabled | Whether all in-scope endpoints within the namespace were always Envoy enabled during the report interval. | bool | - -### services.csv - -A services CSV file that includes per-service information. - -| Heading | Description | Format | -| ---------------- | ---------------------------------------------------------------------------------------------------------------- | ------ | -| service | The name of the service. | string | -| ingressProtected | Whether all in-scope endpoints that are in the service were always ingress protected during the report interval. | bool | -| envoyEnabled | Whether all in-scope endpoints that are in the service were always Envoy enabled during the report interval. | bool | diff --git a/calico-enterprise/reference/resources/compliance-reports/network-access.mdx b/calico-enterprise/reference/resources/compliance-reports/network-access.mdx deleted file mode 100644 index e01798e591..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/network-access.mdx +++ /dev/null @@ -1,92 +0,0 @@ ---- -description: Reference for the network access compliance report in Calico Enterprise that summarizes which endpoints could communicate based on policy. ---- - -# Network Access report - -To create an Inventory report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `network-access`. - -The following sample command creates a GlobalReport that results in a daily network access report for -endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-network-access-report - labels: - deployment: production -spec: - reportType: network-access - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -:::note - -There is a known issue that audit logs do not contain deletion events for resources that were -deleted implicitly as part of a namespace deletion event. Currently, this means policies and pods that have been -deleted in this way may still appear in the reports that cover any period within the next day. - -::: - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| endpointsNumIngressProtected | The number of in-scope endpoints that were always ingress protected during the report interval. | number | -| endpointsNumEgressProtected | The number of in-scope endpoints that were always egress protected during the report interval. | number | -| endpointsNumIngressUnprotected | The number of in-scope endpoints that were ingress unprotected at any point during the report interval. | number | -| endpointsNumEgressUnprotected | The number of in-scope endpoints that were egress unprotected at any point during the report interval. | number | -| endpointsNumIngressFromInternet | The number of in-scope endpoints that allowed ingress traffic from the public internet at any point during the report interval. | number | -| endpointsNumEgressToInternet | The number of in-scope endpoints that allowed egress traffic to the public internet at any point during the report interval. | number | -| endpointsNumIngressFromOtherNamespace | The number of in-scope endpoints that allowed ingress traffic from another namespace at any point during the report interval. | number | -| endpointsNumEgressToOtherNamespace | The number of in-scope endpoints that allowed egress traffic to another namespace at any point during the report interval. | number | -| endpointsNumEnvoyEnabled | The number of in-scope endpoints that were always Envoy enabled during the report interval. | number | - -### endpoints.csv - -An endpoints CSV file that includes per-endpoint information. - -| Heading | Description | Format | -| ------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------- | -| endpoint | The name of the endpoint. | string | -| ingressProtected | Whether the endpoint was always ingress protected during the report interval. | bool | -| egressProtected | Whether the endpoint was always egress protected during the report interval. | bool | -| ingressFromInternet | Whether the endpoint allowed ingress traffic from the public internet at any point during the report interval. | number | -| egressToInternet | Whether the endpoint allowed egress traffic to the public internet at any point during the report interval. | number | -| ingressFromOtherNamespace | Whether the endpoint allowed ingress traffic from another namespace at any point during the report interval. | number | -| egressToOtherNamespace | Whether the endpoint allowed egress traffic to another namespace at any point during the report interval. | number | -| envoyEnabled | Whether the endpoint was always Envoy enabled during the report interval. | bool | -| appliedPolicies | The full set of policies that applied to the endpoint at any time during the report interval. | ";" separated list of policy names | -| services | The full set of services that included this endpoint at any time during the report interval. | ";" separated list of service names | -| trafficAggregationPrefix\* | The flow log aggregation prefix. | string | -| endpointsGeneratingTrafficToThisEndpoint\* | The set of endpoints that were generating traffic to this endpoint. | ";" separated list of service names | -| endpointsReceivingTrafficFromThisEndpoint\* | The set of endpoints that this endpoint is generating traffic to. | ";" separated list of service names | - -\* Traffic data is determined from flow logs. By default, $[prodname] aggregates flow logs so that flows to -and from pods in the same replica set are summarized if the flows are accepted. (Denied flows are not aggregated this -way by default). This means that the per-endpoint traffic details do not refer specifically to that endpoint, but -rather the set of endpoints specified by the trafficAggregationPrefix. - -If you want per-endpoint detail you should turn down the level of aggregation. To do so, -set the value of `flowLogsFileAggregationKindForAllowed` to 1 using a [FelixConfiguration][felixconfig] - -[felixconfig]: ../felixconfig.mdx diff --git a/calico-enterprise/reference/resources/compliance-reports/overview.mdx b/calico-enterprise/reference/resources/compliance-reports/overview.mdx deleted file mode 100644 index ec0cafe0e5..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/overview.mdx +++ /dev/null @@ -1,102 +0,0 @@ ---- -description: Reference overview of compliance reporting in Calico Enterprise covering schedules, report scope, and the GlobalReport resource. ---- - -# Compliance reports (deprecated) - -The $[prodname] compliance reporting feature provides the following compliance reports: - -- [Inventory](inventory.mdx) -- [Network Access](network-access.mdx) -- [Policy Audit](policy-audit.mdx) -- [CIS Benchmark](cis-benchmark.mdx) - -Create a [`GlobalReport`](../globalreport.mdx) resource to automatically schedule report generation, and specify the report scope (resources to include in the report). - -## Concepts - -### In-scope asset - -An asset (Pod or HostEndpoint) is flagged as in-scope by endpoint labels, namespace and/or namespace labels, and service -account and/or service account labels. - -_How this applies to the report_: -The report includes all resources that were in-scope at any point during the report interval. The resource is included -when it is first flagged as in-scope according to the configured label selector and name selections. The resource is -included even if the resource is deleted or goes out-of-scope before the end of the report interval. - -### Ingress protected - -An endpoint is ingress protected if it has at least one Ingress policy that is applied to it. - -A service is ingress protected if all of the in-scope endpoints within that service are ingress protected. - -A namespace is ingress protected if all of the in-scope endpoints within that namespace are ingress protected. - -_How this applies to the report_: -An endpoint is ingress protected only if it was ingress protected throughout the entire report interval. - -### Egress protected - -As per ingress, but with egress policy rules. Note that egress statistics are not obtained for services. - -### Allows ingress traffic from another namespace - -An endpoint is flagged as allowing ingress traffic from another namespace if it has one or more policies that apply to -it with an ingress allow rule that: - -- has an explicit namespace selector configured, or -- has no source selector or source CIDR configured, or -- (for GlobalNetworkPolicy) has no source CIDR. - -A service is flagged as allowing ingress traffic from another namespace if any of the in-scope endpoints within that -service are flagged. - -A namespace is flagged as allowing ingress traffic from another namespace if all of the in-scope endpoints within that -namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as allowing ingress traffic from another namespace if it was flagged at any time during the -report interval. - -### Allows egress traffic to another namespace - -As per ingress, but with egress policy rules and destination selector/CIDR. Note that egress statistics are not obtained -for services. - -### Allows ingress traffic from the internet - -An endpoint is flagged as allowing ingress traffic from the internet if it has one or more policies that apply to it -with an ingress allow rule that: - -- has no source selector or source CIDR configured, or -- has a source CIDR in the non-private IP ranges and has no source selector, or -- has a source selector that matches one or more NetworkSets that contain at least one non-private IP. - -A service is flagged as allowing ingress traffic from the internet if any of the in-scope endpoints within that service -are flagged. - -A namespace is flagged as allowing ingress traffic from the internet if all of the in-scope endpoints within that -namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as allowing ingress traffic from the internet if it was flagged as such at any time during the -report interval. - -### Allows egress traffic to the internet - -As per ingress, but with egress policy rules and destination selector/CIDR. Note that egress statistics are not obtained -for services. - -### Envoy enabled - -An endpoint is flagged as Envoy Enabled if the associated Pod Spec and Annotations indicate that an Istio init and main -container are deployed in the Pod. Provided Istio is appropriately configured on the cluster, this can be extrapolated -to be indication of whether mTLS is enabled for the endpoint. - -A service is flagged as Envoy enabled if all of the in-scope endpoints within that service are flagged. - -A namespace is flagged as Envoy enabled if all of the in-scope endpoints within that namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as Envoy enabled if it was flagged as such throughout the entire report interval. diff --git a/calico-enterprise/reference/resources/compliance-reports/policy-audit.mdx b/calico-enterprise/reference/resources/compliance-reports/policy-audit.mdx deleted file mode 100644 index 67d19a5b84..0000000000 --- a/calico-enterprise/reference/resources/compliance-reports/policy-audit.mdx +++ /dev/null @@ -1,56 +0,0 @@ ---- -description: Reference for the policy audit compliance report in Calico Enterprise that records changes to network policies during the report period. ---- - -# Policy audit report - -To create a Policy Audit report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `policy-audit`. - -The following sample command creates a GlobalReport that results in a daily policy audit report for -policies that are applied to endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-policy-audit-report - labels: - deployment: production -spec: - reportType: policy-audit - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ----------------------- | ------------------------------------------------------------------------------------------------------ | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| numCreatedPolicies | The number of policies that apply to in-scope endpoints that were created during the report interval. | number | -| numModifiedPolicies | The number of policies that apply to in-scope endpoints that were modified during the report interval. | number | -| numDeletedPolicies | The number of policies that apply to in-scope endpoints that were deleted during the report interval. | number | - -### events.json - -Events formatted in JSON. - -### events.yaml - -Events formatted in YAML. diff --git a/calico-enterprise/reference/resources/globalreport.mdx b/calico-enterprise/reference/resources/globalreport.mdx deleted file mode 100644 index 16e2c70171..0000000000 --- a/calico-enterprise/reference/resources/globalreport.mdx +++ /dev/null @@ -1,149 +0,0 @@ ---- -description: Reference for the GlobalReport resource in Calico Enterprise that schedules compliance reports against cluster network and policy state. ---- - -# Global report - -A global report resource is a configuration for generating compliance reports. A global report configuration in $[prodname] lets you: - -- Specify report contents, frequency, and data filtering -- Specify the node(s) on which to run the report generation jobs -- Enable/disable creation of new jobs for generating the report - -For `kubectl` [commands](https://kubernetes.io/docs/reference/kubectl/overview/), the following case-insensitive aliases -may be used to specify the resource type on the CLI: -`globalreport.projectcalico.org`, `globalreports.projectcalico.org` and abbreviations such as -`globalreport.p` and `globalreports.p`. - -## Sample YAML - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: weekly-full-inventory -spec: - reportType: inventory - schedule: 0 0 * * 0 - jobNodeSelector: - nodetype: infrastructure - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: hourly-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - names: ['payable', 'collections', 'payroll'] - schedule: 0 * * * * - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: monthly-widgets-controller-tigera-policy-audit -spec: - reportType: policy-audit - schedule: 0 0 1 * * - endpoints: - serviceAccounts: - names: ['controller'] - namespaces: - names: ['widgets'] - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-benchmark -spec: - reportType: cis-benchmark - schedule: 0 0 * * * - cis: - resultsFilters: - - benchmarkSelection: { kubernetesVersion: '1.13' } - exclude: ['1.1.4', '1.2.5'] -``` - -## GlobalReport Definition - -### Metadata - -| Field | Description | Accepted Values | Schema | -| ------ | ---------------------------------------- | ------------------------------------------------ | ------ | -| name | The name of this report. | Lower-case alphanumeric with optional `-` or `.` | string | -| labels | A set of labels to apply to this report. | | map | - -### Spec - -| Field | Description | Required | Accepted Values | Schema | -| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------- | -| reportType | The type of report to produce. This field controls the content of the report - see the links for each type for more details. | Yes | [cis‑benchmark](compliance-reports/cis-benchmark.mdx), [inventory](compliance-reports/inventory.mdx), [network‑access](compliance-reports/network-access.mdx), [policy‑audit](compliance-reports/policy-audit.mdx) | string | -| endpoints | Specify which endpoints are in scope. If omitted, selects everything. | | | [EndpointsSelection](#endpointsselection) | -| schedule | Configure report frequency by specifying start and end time in [cron-format][cron-format]. Reports are started 30 minutes (configurable) after the scheduled value to allow enough time for data archival. A maximum limit of 12 schedules per hour is enforced (an average of one report every 5 minutes). | Yes | | string | -| jobNodeSelector | Specify the node(s) for scheduling the report jobs using selectors. | | | map | -| suspend | Disable future scheduled report jobs. In-flight reports are not affected. | | | bool | -| cis | Parameters related to generating a CIS benchmark report. | | | [CISBenchmarkParams](#cisbenchmarkparams) | - -### EndpointsSelection - -| Field | Description | Schema | -| --------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------- | -| selector | Endpoint label selector to restrict endpoint selection. | string | -| namespaces | Namespace name and label selector to restrict endpoints by selected namespaces. | [NamesAndLabelsMatch](#namesandlabelsmatch) | -| serviceAccounts | Service account name and label selector to restrict endpoints by selected service accounts. | [NamesAndLabelsMatch](#namesandlabelsmatch) | - -### CISBenchmarkParams - -| Fields | Description | Required | Schema | -| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----------------------------------------- | -| highThreshold | Integer percentage value that determines the lower limit of passing tests to consider a node as healthy. Default: 100 | No | int | -| medThreshold | Integer percentage value that determines the lower limit of passing tests to consider a node as unhealthy. Default: 50 | No | int | -| includeUnscoredTests | Boolean value that when false, applies a filter to exclude tests that are marked as “Unscored” by the CIS benchmark standard. If true, the tests will be included in the report. Default: false | No | bool | -| numFailedTests | Integer value that sets the number of tests to display in the Top-failed Tests section of the CIS benchmark report. Default: 5 | No | int | -| resultsFilters | Specifies an include or exclude filter to apply on the test results that will appear on the report. | No | [CISBenchmarkFilter](#cisbenchmarkfilter) | - -### CISBenchmarkFilter - -| Fields | Description | Required | Schema | -| ------------------ | ---------------------------------------------------------------------------------------------- | -------- | ----------------------------------------------- | -| benchmarkSelection | Specify which set of benchmarks that this filter should apply to. Selects all benchmark types. | No | [CISBenchmarkSelection](#cisbenchmarkselection) | -| exclude | Specify which benchmark tests to exclude | No | array of strings | -| include | Specify which benchmark tests to include only (higher precedence than exclude) | No | array of strings | - -### CISBenchmarkSelection - -| Fields | Description | Required | Schema | -| ----------------- | -------------------------------------- | -------- | ------ | -| kubernetesVersion | Specifies a version of the benchmarks. | Yes | string | - -### NamesAndLabelsMatch - -| Field | Description | Schema | -| -------- | ------------------------------------ | ------ | -| names | Set of resource names. | list | -| selector | Selects a set of resources by label. | string | - -Use the `NamesAndLabelsMatch`to limit the scope of endpoints. If both `names` -and `selector` are specified, the resource is identified using label _AND_ name -match. - -:::note - -To use the $[prodname] compliance reporting feature, you must ensure all required resource types -are being audited and the logs archived in Elasticsearch. You must explicitly configure the [Kubernetes API Server](../../observability/kube-audit.mdx) - to send audit logs for Kubernetes-owned resources -to Elasticsearch. - -::: - -## Supported operations - -| Datastore type | Create/Delete | Update | Get/List | Notes | -| --------------------- | ------------- | ------ | -------- | ----- | -| Kubernetes API server | Yes | Yes | Yes | | - -[cron-format]: https://en.wikipedia.org/wiki/Cron diff --git a/calico-enterprise/reference/resources/overview.mdx b/calico-enterprise/reference/resources/overview.mdx index a70cdfda35..69e8943535 100644 --- a/calico-enterprise/reference/resources/overview.mdx +++ b/calico-enterprise/reference/resources/overview.mdx @@ -54,7 +54,6 @@ The following resources are supported: - [GlobalAlert](globalalert.mdx) - [GlobalNetworkPolicy](globalnetworkpolicy.mdx) - [GlobalNetworkSet](globalnetworkset.mdx) -- [GlobalReport](globalreport.mdx) - [GlobalThreatFeed](globalthreatfeed.mdx) - [HostEndpoint](hostendpoint.mdx) - [IPPool](ippool.mdx) diff --git a/calico-enterprise/release-notes/index.mdx b/calico-enterprise/release-notes/index.mdx index a4501972fc..d284035956 100644 --- a/calico-enterprise/release-notes/index.mdx +++ b/calico-enterprise/release-notes/index.mdx @@ -28,6 +28,7 @@ This version of Calico Enterprise is based on [Calico Open Source $[openSourceVe ### Deprecated and removed features +- The compliance reporting feature has been removed from the $[prodname] web console. - $[prodname] is moving the `projectcalico.org/v3` API from the aggregated API server to native Kubernetes CRDs. Both mechanisms will be supported until native v3 CRDs are compatible with all supported platforms, after which the aggregated API server will be removed. ## Technology Preview features diff --git a/calico-enterprise_versioned_docs/version-3.20-2/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.20-2/compliance/compliance-reports-cis.mdx index afb915b1c0..dc965fbe54 100644 --- a/calico-enterprise_versioned_docs/version-3.20-2/compliance/compliance-reports-cis.mdx +++ b/calico-enterprise_versioned_docs/version-3.20-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure reports to assess compliance for all assets in a Kubernet :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.20-2/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.20-2/compliance/enable-compliance.mdx index 462ccdcad2..be8f5f9850 100644 --- a/calico-enterprise_versioned_docs/version-3.20-2/compliance/enable-compliance.mdx +++ b/calico-enterprise_versioned_docs/version-3.20-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Enable compliance reports to configure reports to assess compliance :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.20-2/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.20-2/compliance/overview.mdx index 51a89b42d1..a3c3cdc389 100644 --- a/calico-enterprise_versioned_docs/version-3.20-2/compliance/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.20-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Get the reports for regulatory compliance on Kubernetes workloads a :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.20-2/release-notes/index.mdx b/calico-enterprise_versioned_docs/version-3.20-2/release-notes/index.mdx index 1a153ea0a4..da21b944be 100644 --- a/calico-enterprise_versioned_docs/version-3.20-2/release-notes/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.20-2/release-notes/index.mdx @@ -78,7 +78,6 @@ For more information, see [Packet capture](../observability/packetcapture.mdx), ## Deprecated and removed features * All compliance reporting features are deprecated and will be removed in a future release. - We're building a new compliance reporting system that will eventually replace the current one. * The honeypods feature has been removed from this release. ## Bug fixes diff --git a/calico-enterprise_versioned_docs/version-3.21-2/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.21-2/compliance/compliance-reports-cis.mdx index afb915b1c0..dc965fbe54 100644 --- a/calico-enterprise_versioned_docs/version-3.21-2/compliance/compliance-reports-cis.mdx +++ b/calico-enterprise_versioned_docs/version-3.21-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure reports to assess compliance for all assets in a Kubernet :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.21-2/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.21-2/compliance/enable-compliance.mdx index 462ccdcad2..be8f5f9850 100644 --- a/calico-enterprise_versioned_docs/version-3.21-2/compliance/enable-compliance.mdx +++ b/calico-enterprise_versioned_docs/version-3.21-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Enable compliance reports to configure reports to assess compliance :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.21-2/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.21-2/compliance/overview.mdx index 51a89b42d1..a3c3cdc389 100644 --- a/calico-enterprise_versioned_docs/version-3.21-2/compliance/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.21-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Get the reports for regulatory compliance on Kubernetes workloads a :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.22-2/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.22-2/compliance/compliance-reports-cis.mdx index dd3258e609..b7f30715ce 100644 --- a/calico-enterprise_versioned_docs/version-3.22-2/compliance/compliance-reports-cis.mdx +++ b/calico-enterprise_versioned_docs/version-3.22-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports in Calico Enterprise to :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.22-2/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.22-2/compliance/enable-compliance.mdx index 8c60a2c317..8033d59188 100644 --- a/calico-enterprise_versioned_docs/version-3.22-2/compliance/enable-compliance.mdx +++ b/calico-enterprise_versioned_docs/version-3.22-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Turn on the in-cluster compliance reporter, controller, snapshotter :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.22-2/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.22-2/compliance/overview.mdx index 1e4ac16448..76f4abdc46 100644 --- a/calico-enterprise_versioned_docs/version-3.22-2/compliance/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.22-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Enterprise compliance reports against Kuber :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.23-2/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.23-2/compliance/compliance-reports-cis.mdx index dd3258e609..b7f30715ce 100644 --- a/calico-enterprise_versioned_docs/version-3.23-2/compliance/compliance-reports-cis.mdx +++ b/calico-enterprise_versioned_docs/version-3.23-2/compliance/compliance-reports-cis.mdx @@ -7,7 +7,6 @@ description: Configure CIS Kubernetes benchmark reports in Calico Enterprise to :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.23-2/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.23-2/compliance/enable-compliance.mdx index 8c60a2c317..8033d59188 100644 --- a/calico-enterprise_versioned_docs/version-3.23-2/compliance/enable-compliance.mdx +++ b/calico-enterprise_versioned_docs/version-3.23-2/compliance/enable-compliance.mdx @@ -7,7 +7,6 @@ description: Turn on the in-cluster compliance reporter, controller, snapshotter :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.23-2/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.23-2/compliance/overview.mdx index 1e4ac16448..76f4abdc46 100644 --- a/calico-enterprise_versioned_docs/version-3.23-2/compliance/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.23-2/compliance/overview.mdx @@ -7,7 +7,6 @@ description: Schedule and run Calico Enterprise compliance reports against Kuber :::info[deprecation notice] The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. ::: diff --git a/calico-enterprise_versioned_docs/version-3.24-1/about/calico-product-editions.mdx b/calico-enterprise_versioned_docs/version-3.24-1/about/calico-product-editions.mdx index 4808160a01..3ec34cedf4 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/about/calico-product-editions.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/about/calico-product-editions.mdx @@ -62,7 +62,6 @@ import { CalicoProducts } from '/src/___new___/components'; | Deep packet inspection | | | | | | DDoS protection | | | | | | Workload-centric WAF | | | | | -| Compliance reporting and alerts | | | | | | SIEM integrations | | | | | | **Network Security for VMs and Bare Metal** | | | | | | Restrict traffic to/from hosts and VMs using network policy | | | | | diff --git a/calico-enterprise_versioned_docs/version-3.24-1/about/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/about/index.mdx index 414d02dc93..dfcee21ecb 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/about/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/about/index.mdx @@ -190,7 +190,6 @@ All of this is built on Calico Open Source, the most widely used container netwo | Deep packet inspection | | | | | | DDoS protection | | | | | | Workload-centric WAF | | | | | -| Compliance reporting and alerts | | | | | | SIEM integrations | | | | | | **Network Security for VMs and Bare Metal** | | | | | | Restrict traffic to/from hosts and VMs using network policy | | | | | diff --git a/calico-enterprise_versioned_docs/version-3.24-1/compliance/compliance-reports-cis.mdx b/calico-enterprise_versioned_docs/version-3.24-1/compliance/compliance-reports-cis.mdx deleted file mode 100644 index dd3258e609..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/compliance/compliance-reports-cis.mdx +++ /dev/null @@ -1,199 +0,0 @@ ---- -description: Configure CIS Kubernetes benchmark reports in Calico Enterprise to assess node and cluster compliance and download results from the in-cluster reporter as CSV. ---- - -# Configure CIS benchmark reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Use the $[prodname] Kubernetes CIS benchmark report to assess compliance for all assets in a Kubernetes cluster. - -## Value - -A standard requirement for an organization’s security and compliance posture is to assess your Kubernetes clusters against CIS benchmarks. The $[prodname] Kubernetes CIS benchmark report provides this comprehensive view into your Kubernetes clusters while strengthening your threat detection capability by looking beyond networking data. - -## Concepts - -### Default settings and configuration - -During $[prodname] installation, each node starts a pod named, `compliance-benchmarker`. A preconfigured Kubernetes CIS benchmark report is generated every hour. You can view the report in **Compliance**, **Compliance Reports**, download it to .csv format. - -To schedule the CIS benchmark report or change settings, use the **global report** resource. Global reports are configured as YAML files and are applied using `kubectl`. - -### Best practices - -We recommend that you review the CIS benchmark best practices for securing cluster component configurations here: [CIS benchmarks downloads](https://learn.cisecurity.org/benchmarks). - -## Before you begin - -**Required** - -* You [Enabled compliance reports](../compliance/enable-compliance) - -**Limitations** - -CIS benchmarks runs only on nodes where $[prodname] is running. This limitation may exclude control plane nodes in some managed cloud platforms (AKS, EKS, GKE). Because the user has limited control over installation of control plane nodes in managed cloud platforms, these reports may have limited use for cloud users. - -## How to - -- [Configure and schedule CIS benchmark reports](#configure-and-schedule-cis-benchmark-reports) -- [View report generation status](#view-report-generation-status) -- [Review and address CIS benchmark results](#review-and-address-cis-benchmark-results) -- [Manually run reports](#manually-run-reports) -- [Troubleshooting](#troubleshooting) - -### Configure and schedule CIS benchmark reports - -Verify that the `compliance-benchmarker` is running and the `cis-benchmark` report type is installed. - -```bash -kubectl get -n tigera-compliance daemonset compliance-benchmarker -kubectl get globalreporttype cis-benchmark -``` - -In the following example, we use a **GlobalReport** with CIS benchmark fields to schedule and filter results. The report is scheduled to run at midnight of the next day (in UTC), and the benchmark items 1.1.4 and 1.2.5 will be omitted from the results. - -| **Fields** | **Description** | -| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| schedule | The start and end time of the report using [crontab format](https://en.wikipedia.org/wiki/Cron). To allow for archiving, reports are generated approximately 30 minutes after the end time. A single report is limited to a maximum of two per hour. | -| highThreshold | **Optional**. Integer percentage value that determines the lower limit of passing tests to consider a node as healthy. Default: 100 | -| medThreshold | **Optional**. Integer percentage value that determines the lower limit of passing tests to consider a node as unhealthy. Default: 50 | -| includeUnscoredTests | **Optional**. Boolean value that when false, applies a filter to exclude tests that are marked as “Unscored” by the CIS benchmark standard. If true, the tests will be included in the report. Default: true | -| numFailedTests | **Optional**. Integer value that sets the number of tests to display in the Top-failed Tests section of the CIS benchmark report. Default: 5 | -| resultsFilter | **Optional**. An include or exclude filter to apply on the test results that will appear on the report. | - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-results - labels: - deployment: production -spec: - reportType: cis-benchmark - schedule: 0 0 * * * - cis: - highThreshold: 100 - medThreshold: 50 - includeUnscoredTests: true - numFailedTests: 5 - resultsFilters: - - benchmarkSelection: { kubernetesVersion: '1.13' } - exclude: ['1.1.4', '1.2.5'] -``` - -### View report generation status - -To view the status of a report, you must use the `kubectl` command. For example: - -```bash -kubectl get globalreports.projectcalico.org daily-cis-results -o yaml -``` - -In a report, the job status types are: - -- **lastScheduledReportJob**: - The most recently scheduled job for generating the report. Because reports are scheduled in order, the “end time” of - this report will be the “start time” of the next scheduled report. -- **activeReportJobs**: - Default = allows up to 5 concurrent report generation jobs. -- **lastFailedReportJobs**: - Default = keeps the 3 most recent failed jobs and deletes older ones. A single report generation job will be retried - up to 6 times (by default) before it is marked as failed. -- **lastSuccessfulReportJobs**: - Default = keeps the 2 most recent successful jobs and deletes older ones. - -#### Change the default report generation time - -By default, reports are generated 30 minutes after the end of the report, to ensure all of the audit data is archived. -(However, this gap does not affect the data collected “start/end time” for a report.) - -You can adjust the time for audit data for cases like initial report testing, to demo a report, or when manually -creating a report that is not counted in global report status. - -To change the delay, go to the installation manifest, and uncomment and set the environment variable -`TIGERA_COMPLIANCE_JOB_START_DELAY`. Specify value as a [Duration string][parse-duration]. - -### Review and address CIS benchmark results - -We recommend the following approach to CIS benchmark reports results: - -1. Download the Kubernetes CIS benchmarks and export your full CIS benchmark results in .csv format. -1. In the compliance dashboard, review the "Top-Failed Tests" section to identify which tests are the most problematic. -1. Cross-reference the top-failed tests to identify which nodes are failing that test. -1. Look up those tests in the [Kubernetes benchmark document](https://downloads.cisecurity.org/#/) and follow the remediation steps to resolve the failure. -1. Discuss with your infrastructure and security team if this remediation is viable within your organization. -1. If so, update your nodes with the fix and ensure that the test passes on the next generation of the report. -1. If the fix is not viable but is an acceptable risk to take within the organization, configure the report specification to exclude that test index so that it no longer appears in the report. -1. If the fix is not viable and not an acceptable risk to take on, keep the failing test within the report so that your team is reminded to address the issue as soon as possible. - -### Manually run reports - -You can manually run reports at any time. For example, run a manual report: - -- To specify a different start/end time -- If a scheduled report fails - -$[prodname] GlobalReport schedules Kubernetes Jobs which create a single-run pod to generate a report and store it in Elasticsearch. Because you need to run manual reports as a pod, you need higher permissions: allow `create` access for pods in namespace `tigera-compliance` using the `tigera-compliance-reporter` service account. - -To manually run a report: - -1. Download the pod template corresponding to your installation method. - **Operator** - - For management and standalone clusters: - - ```bash - curl -O $[filesUrl]/manifests/compliance-reporter-pod.yaml - ``` - - For managed clusters: - - ```bash - curl $[filesUrl]/manifests/compliance-reporter-pod-managed.yaml -o compliance-reporter-pod.yaml - ``` - -1. Edit the template as follows: - - - Edit the pod name if required. - - If you are using your own docker repository, update the container image name with your repo and image tag. - - Set the following environments according to the instructions in the downloaded manifest: - - `TIGERA_COMPLIANCE_REPORT_NAME` - - `TIGERA_COMPLIANCE_REPORT_START_TIME` - - `TIGERA_COMPLIANCE_REPORT_END_TIME` - -1. Apply the updated manifest, and query the status of the pod to ensure it completes. - Upon completion, the report is available in the web console. - - ```bash - # Apply the compliance report pod - kubectl apply -f compliance-reporter-pod.yaml - # Query the status of the pod - kubectl get pod -n=tigera-compliance - ``` - -:::note - -Manually-generated reports do not appear in GlobalReport status. - -::: - -### Troubleshooting - -**Problem**: Compliance reports can fail to generate if the `compliance-benchmarker` component cannot find the required `kubelet` or `kubectl` binaries to determine the Kubernetes version running on the cluster. - -**Solution or workaround**: If a node is running within a container (not running `kubelet` as a binary), make sure the `kubectl` binary is available in the `/usr/bin` directory. - -## Additional resources - -- For details on configuring and scheduling reports, see [Global reports](../reference/resources/globalreport.mdx) -- For other predefined compliance reports, see [Compliance reports](../reference/resources/compliance-reports/index.mdx) - -[parse-duration]: https://golang.org/pkg/time/#ParseDuration diff --git a/calico-enterprise_versioned_docs/version-3.24-1/compliance/enable-compliance.mdx b/calico-enterprise_versioned_docs/version-3.24-1/compliance/enable-compliance.mdx deleted file mode 100644 index 8c60a2c317..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/compliance/enable-compliance.mdx +++ /dev/null @@ -1,49 +0,0 @@ ---- -description: Turn on the in-cluster compliance reporter, controller, snapshotter, and server components that produce Calico Enterprise compliance reports and CIS benchmarks. ---- - -# Enable compliance reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Enabling compliance reports improves the cluster's compliance posture. It involves generating compliance reports for Kubernetes clusters based on archived flow and audit logs for Calico Enterprise and Kubernetes resources. The process includes components for snapshotting configurations, generating reports, managing jobs, providing APIs with RBAC, and benchmarking security. - -## Value - -The compliance system consists of several key components that work together to ensure comprehensive compliance monitoring and reporting: - - - `compliance-snapshotter` : Lists required configurations and pushes snapshots to Elasticsearch, providing visibility into configuration changes. - - `compliance-reporter` : Generates reports by analyzing configuration history, determining configuration evolution and identifying "worst-case outliers." - - `compliance-controller` : Manages the creation, deletion, and monitoring of report generation jobs. - - `compliance-server` : Offers API for report management and enforces RBAC. - - `compliance-benchmarker` : Runs CIS Kubernetes Benchmark checks on each node to ensure secure deployment. - -**Required** - -* For managed clusters, ensure that compliance reporting is enabled in the management cluster. - -### Enable compliance reports using kubectl - -* Create a compliance custom resource, named `tigera-secure`, in the cluster. - -```bash -kubectl apply -f - < \ No newline at end of file diff --git a/calico-enterprise_versioned_docs/version-3.24-1/compliance/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/compliance/index.mdx index 4cf8b13d87..d561170195 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/compliance/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/compliance/index.mdx @@ -1,19 +1,15 @@ --- -description: Generate compliance reports and encrypt in-cluster traffic in your Calico Enterprise cluster, with archived flow logs, audit logs, CIS benchmarks, and WireGuard. +description: Encrypt in-cluster traffic with WireGuard and configure security options for your Calico Enterprise cluster. hide_table_of_contents: true --- import { DocCardLink, DocCardLinkLayout } from '/src/___new___/components'; -# Compliance and security +# Security -Get reports on Kubernetes workloads and environments for regulatory compliance. -Encrypt traffic in your cluster with WireGuard. +Encrypt traffic in your cluster with WireGuard, and configure security options for your $[prodname] cluster. - - - diff --git a/calico-enterprise_versioned_docs/version-3.24-1/compliance/overview.mdx b/calico-enterprise_versioned_docs/version-3.24-1/compliance/overview.mdx deleted file mode 100644 index 1e4ac16448..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/compliance/overview.mdx +++ /dev/null @@ -1,382 +0,0 @@ ---- -description: Schedule and run Calico Enterprise compliance reports against Kubernetes workloads using archived flow logs and audit logs stored in Elasticsearch. ---- - -# Schedule and run compliance reports - -:::info[deprecation notice] - -The compliance features described on this page are deprecated and will be removed in a future release. -We're building a new compliance reporting system that will eventually replace the current one. - -::: - -## Big picture - -Schedule and run compliance reports to assess Kubernetes workloads and environments for regulatory compliance. - -## Value - -Compliance tools that rely on periodic snapshots, do not provide accurate assessments of Kubernetes workloads against your compliance standards. $[prodname] compliance dashboard and reports provide a complete inventory of regulated workloads, along with evidence of enforcement of network controls for these workloads. Additionally, audit reports are available to see changes to any network security controls. - -## Concepts - -### Compliance reports at a glance - -Compliance report are based on archived flow logs and audit logs for all of your $[prodname] resources, plus any audit logs you've configured for Kubernetes resources in the Kubernetes API server: - -- Pods -- Host endpoints -- Service accounts -- Namespaces -- Kubernetes service endpoints -- Global network sets -- Calico and Kubernetes network policies -- Global network policies - -Compliance reports provide the following high-level information: - -- **Protection** - - - Endpoints explicitly protected using ingress or egress policy - - Endpoints with Envoy enabled - -- **Policies and services** - - - Policies and services associated with endpoints - - Policy audit logs - -- **Traffic** - - Allowed ingress/egress traffic to/from namespaces - - Allowed ingress/egress traffic to/from the internet - -![compliance-reporting](/img/calico-enterprise/compliance-reporting.png) - -## Before you begin - -**Unsupported** - -- AKS -- GKE -- OpenShift -- TKG - -**Required** - -* You [Enabled compliance reports](../compliance/enable-compliance) - -- Ensure that all nodes in your Kubernetes clusters are time-synchronized using NTP or similar (for accurate audit log timestamps) - -- [Configure audit logs for Kubernetes resources](../observability/elastic/audit-overview.mdx) - - You must configure audit logs for Kubernetes resources through the Kubernetes API to get a complete view of all resources. - -## How to - -- [Configure report permissions](#configure-report-permissions) -- [Configure and schedule reports](#configure-and-schedule-reports) -- [View report generation status](#view-report-generation-status) -- [Run reports](#run-reports) - -### Configure report permissions - -Report permissions are granted using the standard Kubernetes RBAC based on ClusterRole and ClusterRoleBindings. The following table outlines the required RBAC verbs for each resource type for a specific user actions. - -| **Action** | **globalreporttypes** | **globalreports** | **globalreports/status** | -| ------------------------------------------------------- | ------------------------------- | --------------------------------- | ------------------------ | -| Manage reports (create/modify/delete) | | \* | get | -| View status of report generation through kubectl | | get | get | -| List the generated reports and summary status in the UI | | list + get (for required reports) | | -| Export the generated reports from the UI | get (for the particular report) | get (for required reports) | | - -The following sample manifest creates RBAC for three users: Paul, Candice and David. - -- Paul has permissions to create/modify/delete the report schedules and configuration, but does not have permission to export generated reports from the UI. -- Candice has permissions to list and export generated reports from the UI, but cannot modify the report schedule or configuration. -- David has permissions to list and export generated `dev-inventory` reports from the UI, but cannot list or download other reports, nor modify the report - schedule or configuration. - -```yaml -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-manage-report-config -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['*'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreports/status'] - verbs: ['get', 'list', 'watch'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-manage-report-config -subjects: - - kind: User - name: paul - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-manage-report-config - apiGroup: rbac.authorization.k8s.io - ---- -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-all-reports -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['get', 'list'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreporttypes'] - verbs: ['get'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-all-reports -subjects: - - kind: User - name: candice - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-list-download-all-reports - apiGroup: rbac.authorization.k8s.io - ---- -kind: ClusterRole -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-dev-inventory -rules: - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['list'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreports'] - verbs: ['get'] - resourceNames: ['dev-inventory'] - - apiGroups: ['projectcalico.org'] - resources: ['globalreporttypes'] - verbs: ['get'] - resourceNames: ['dev-inventory'] - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: tigera-compliance-list-download-dev-inventory -subjects: - - kind: User - name: david - apiGroup: rbac.authorization.k8s.io -roleRef: - kind: ClusterRole - name: tigera-compliance-list-download-dev-inventory - apiGroup: rbac.authorization.k8s.io -``` - -### Configure and schedule reports - -To configure and schedule a compliance report, create a [GlobalReport](../reference/resources/globalreport.mdx) with the following information. - -| **Fields** | **Description** | -| --------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| name | Unique name for your report. | -| reportType | One of the following predefined report types: `inventory`, `network-access`, `policy-audit`. | -| schedule | The start and end time of the report using [crontab format](https://en.wikipedia.org/wiki/Cron). To allow for archiving, reports are generated approximately 30 minutes after the end time. A single report is limited to a maximum of two per hour. | -| endpoints | **Optional**. For inventory and network-access reports, specifies the endpoints to include in the report. For the policy-audit report, restricts audit logs to include only policies that apply to the selected endpoints. If not specified, the report includes all endpoints and audit logs. | -| jobNodeSelector | **Optional**. Limits report generation jobs to specific nodes. | -| suspend | **Optional**. Suspends report generation. All in-flight reports will complete, and future scheduled reports are suspended. | - -:::note - -GlobalReports can only be configured using kubectl (not calicoctl); and they cannot be edited in the Tigera -Secure EE the web console. - -::: - -The following sections provide sample schedules for the predefined reports. - -### Weekly reports, all endpoints - -The following report schedules weekly inventory reports for _all_ endpoints. The jobs that create the reports will run -on the infrastructure nodes (e.g. nodetype == 'infrastructure'). - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: weekly-full-inventory -spec: - reportType: inventory - schedule: 0 0 * * 0 - jobNodeSelector: - nodetype: infrastructure -``` - -### Daily reports, selected endpoints - -The following report schedules daily inventory reports for production endpoints (e.g. deployment == ‘production’). - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-production-inventory -spec: - reportType: inventory - endpoints: - selector: deployment == 'production' - schedule: 0 0 * * * -``` - -### Hourly reports, endpoints in named namespaces - -The following report schedules hourly network-access reports for the accounts department endpoints, that are -specified using the namespace names: **payable**, **collections** and **payroll**. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: hourly-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - names: ['payable', 'collections', 'payroll'] - schedule: 0 * * * * -``` - -### Daily reports, endpoints in selected namespaces - -The following report schedules daily network-access reports for the accounts department with endpoints specified using -a namespace selector. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - selector: department == 'accounts' - schedule: 0 0 * * * -``` - -### Monthly reports, endpoints for named service accounts in named namespaces - -The following schedules monthly audit reports. The audited policy is restricted to policy that applies to -widgets/controller endpoints specified by the namespace **widgets** and service account **controller**. - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: monthly-widgets-controller-tigera-policy-audit -spec: - reportType: policy-audit - schedule: 0 0 1 * * - endpoints: - serviceAccounts: - names: ['controller'] - namespaces: - names: ['widgets'] -``` - -### View report generation status - -To view the status of a report, you must use the `kubectl` command. For example: - -```bash -kubectl get globalreports.projectcalico.org daily-inventory.p -o yaml -``` - -In a report, the job status types are: - -- **lastScheduledReportJob**: - The most recently scheduled job for generating the report. Because reports are scheduled in order, the “end time” of - this report will be the “start time” of the next scheduled report. -- **activeReportJobs**: - Default = allows up to 5 concurrent report generation jobs. -- **lastFailedReportJobs**: - Default = keeps the 3 most recent failed jobs and deletes older ones. A single report generation job will be retried - up to 6 times (by default) before it is marked as failed. -- **lastSuccessfulReportJobs**: - Default = keeps the 2 most recent successful jobs and deletes older ones. - -### Change the default report generation time - -By default, reports are generated 30 minutes after the end of the report, to ensure all of the audit data is archived. -(However, this gap does not affect the data collected “start/end time” for a report.) - -You can adjust the time for audit data for cases like initial report testing, to demo a report, or when manually -creating a report that is not counted in global report status. - -To change the delay, go to the installation manifest, and uncomment and set the environment -`TIGERA_COMPLIANCE_JOB_START_DELAY`. Specify value as a [Duration string][parse-duration]. - -### Run reports - -You can run reports at any time to specify a different start/end time, and if a scheduled report fails. - -$[prodname] GlobalReport schedules Kubernetes Jobs, which create a single-run pod to generate a report and store it -in Elasticsearch. Because you need to run reports as a pod, you need higher permissions: allow `create` access for pods in namespace `tigera-compliance` using the `tigera-compliance-reporter` service account. - -To run a report on demand: - -1. Download the pod template corresponding to your installation method. - - For management and standalone clusters: - - ```bash - curl -O $[filesUrl]/manifests/compliance-reporter-pod.yaml - ``` - - For managed clusters: - - ```bash - curl $[filesUrl]/manifests/compliance-reporter-pod-managed.yaml -o compliance-reporter-pod.yaml - ``` - -1. Edit the template as follows: - - Edit the pod name if required. - - If you are using your own docker repository, update the container image name with your repo and image tag. - - Set the following environments according to the instructions in the downloaded manifest: - - `TIGERA_COMPLIANCE_REPORT_NAME` - - `TIGERA_COMPLIANCE_REPORT_START_TIME` - - `TIGERA_COMPLIANCE_REPORT_END_TIME` -1. Apply the updated manifest, and query the status of the pod to ensure it completes. - Upon completion, the report is available in the $[prodname] web console. - - ```bash - # Apply the compliance report pod - kubectl apply -f compliance-reporter-pod.yaml - - # Query the status of the pod - kubectl get pod -n tigera-compliance - ``` - -:::note - -Manually-generated reports do not appear in GlobalReport status. - -::: - -## Additional resources - -- For details on configuring and scheduling reports, see [Global reports](../reference/resources/globalreport.mdx) -- For report field descriptions, see [Compliance reports](../reference/resources/compliance-reports/index.mdx) -- [CIS benchmarks](compliance-reports-cis.mdx) - -[parse-duration]: https://golang.org/pkg/time/#ParseDuration diff --git a/calico-enterprise_versioned_docs/version-3.24-1/observability/get-started-cem.mdx b/calico-enterprise_versioned_docs/version-3.24-1/observability/get-started-cem.mdx index 2910289ad2..5ca9a5357e 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/observability/get-started-cem.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/observability/get-started-cem.mdx @@ -111,20 +111,6 @@ This page is where you switch views between clusters in the web console. When yo ![managed-clusters](/img/calico-enterprise/managed-clusters.png) -## Compliance Reports - -> From the left navbar, click **Compliance**. - -Compliance tools that rely on periodic snapshots, do not provide accurate assessments of Kubernetes workloads against your compliance standards. $[prodname] compliance dashboard and reports provide a complete inventory of regulated workloads, along with evidence of enforcement of network controls for these workloads. Additionally, audit reports are available to see changes to any network security controls. - -**Compliance reports** are based on archived flow logs and audit logs for all $[prodname] resources, and audit logs for Kubernetes resources in the Kubernetes API server. - -![cis-benchmark](/img/calico-enterprise/cis-benchmark.png) - -Using the filter, you can select report types. - -![compliance-filter](/img/calico-enterprise/compliance-filter.png) - ## Activity > From the left navbar, select **Activity**, **Timeline**. diff --git a/calico-enterprise_versioned_docs/version-3.24-1/operations/cnx/roles-and-permissions.mdx b/calico-enterprise_versioned_docs/version-3.24-1/operations/cnx/roles-and-permissions.mdx index 3e88e18a39..1c183ccad2 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/operations/cnx/roles-and-permissions.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/operations/cnx/roles-and-permissions.mdx @@ -21,7 +21,6 @@ The [Calico Enterprise API server](../../reference/installation/api.mdx#apiserve | Features | RBAC controls for... | | ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Network policy | - Tiered policy, including AWS security groups and federated services.
- Kubernetes network policy (in default tier)
- $[prodname] network policies including namespaces
- Staged policy, policy recommendation, policy preview | -| Compliance | Report management, generation, export, and status. | | Visibility and troubleshooting | Elasticsearch logs: flow, audit, dns, intrusion detection, bgp | | Multi-cluster management | Management and managed clusters in single management plane. | @@ -47,5 +46,4 @@ For RBAC details on any given feature, see the feature. For example: - [Policy preview RBAC](../../network-policy/policy-impact-preview.mdx) - [Staged policy RBAC](../../network-policy/staged-network-policies.mdx) - [Elasticsearch logs RBAC](../../observability/elastic/rbac-elasticsearch.mdx) -- [Compliance reports RBAC](../../compliance/overview.mdx) - [Multi-cluster management RBAC](../../multicluster/set-up-multi-cluster-management/standard-install/create-a-management-cluster.mdx) diff --git a/calico-enterprise_versioned_docs/version-3.24-1/operations/troubleshoot/troubleshooting.mdx b/calico-enterprise_versioned_docs/version-3.24-1/operations/troubleshoot/troubleshooting.mdx index 31c9f17327..08bf914c5c 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/operations/troubleshoot/troubleshooting.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/operations/troubleshoot/troubleshooting.mdx @@ -141,13 +141,6 @@ sysctl -w net.netfilter.nf_conntrack_max=1000000 echo "net.netfilter.nf_conntrack_max=1000000" >> /etc/sysctl.conf ``` -## Compliance report is not generating at expected time - -By design, reports are scheduled to generate 30 minutes after the specified end time. The reason for this is to allow a certain amount of -time to pass for all the relevant data within the specified start and end time to be fully processed and stored. This delay can be modified -by setting the `TIGERA_COMPLIANCE_JOB_START_DELAY` environment variable on the `compliance-controller` deployment to the -desired [Golang duration](https://godoc.org/time#Duration). - ## GlobalAlert reports error "Trying to create too many buckets" ``` diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/index.mdx index 3e2808cdc5..726992ad39 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/index.mdx @@ -74,11 +74,6 @@ APIs, CLI, architecture and design, and FAQ. - - - - - @@ -87,7 +82,6 @@ APIs, CLI, architecture and design, and FAQ. - diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_api.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_api.mdx index 581bf232e7..943cd61444 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_api.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_api.mdx @@ -14,7 +14,6 @@ Resource Types - [APIServer](#apiserver) - [ApplicationLayer](#applicationlayer) - [Authentication](#authentication) -- [Compliance](#compliance) - [EgressGateway](#egressgateway) - [GatewayAPI](#gatewayapi) - [Goldmane](#goldmane) @@ -1260,486 +1259,6 @@ _Appears in:_ | `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | Define resources requests and limits for single Pods. | -### Compliance - - - -Compliance installs the components required for Tigera compliance reporting. At most one instance -of this resource is supported. It must be named "tigera-secure". - -| Field | Description | -| --- | --- | -| `apiVersion` _string_ | `operator.tigera.io/v1` | -| `kind` _string_ | `Compliance` | -| `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | -| `spec` _[ComplianceSpec](#compliancespec)_ | Specification of the desired state for Tigera compliance reporting. | -| `status` _[ComplianceStatus](#compliancestatus)_ | Most recently observed state for Tigera compliance reporting. | - - -### ComplianceBenchmarkerDaemonSet - - - -ComplianceBenchmarkerDaemonSet is the configuration for the Compliance Benchmarker DaemonSet. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceBenchmarkerDaemonSetSpec](#compliancebenchmarkerdaemonsetspec)_ | (Optional) Spec is the specification of the Compliance Benchmarker DaemonSet. | - - -### ComplianceBenchmarkerDaemonSetContainer - - - -ComplianceBenchmarkerDaemonSetContainer is a Compliance Benchmarker DaemonSet container. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the Compliance Benchmarker DaemonSet container by name.
Supported values are: compliance-benchmarker | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named Compliance Benchmarker DaemonSet container's resources. If omitted, the Compliance Benchmarker DaemonSet will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceBenchmarkerDaemonSetInitContainer - - - -ComplianceBenchmarkerDaemonSetInitContainer is a Compliance Benchmarker DaemonSet init container. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the Compliance Benchmarker DaemonSet init container by name.
Supported values are: tigera-compliance-benchmarker-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named Compliance Benchmarker DaemonSet init container's resources. If omitted, the Compliance Benchmarker DaemonSet will use its default value for this init container's resources. | - - -### ComplianceBenchmarkerDaemonSetPodSpec - - - -ComplianceBenchmarkerDaemonSetPodSpec is the Compliance Benchmarker DaemonSet's PodSpec. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetPodTemplateSpec](#compliancebenchmarkerdaemonsetpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceBenchmarkerDaemonSetInitContainer](#compliancebenchmarkerdaemonsetinitcontainer) array_ | (Optional) InitContainers is a list of Compliance benchmark init containers. If specified, this overrides the specified Compliance Benchmarker DaemonSet init containers. If omitted, the Compliance Benchmarker DaemonSet will use its default values for its init containers. | -| `containers` _[ComplianceBenchmarkerDaemonSetContainer](#compliancebenchmarkerdaemonsetcontainer) array_ | (Optional) Containers is a list of Compliance benchmark containers. If specified, this overrides the specified Compliance Benchmarker DaemonSet containers. If omitted, the Compliance Benchmarker DaemonSet will use its default values for its containers. | - - -### ComplianceBenchmarkerDaemonSetPodTemplateSpec - - - -ComplianceBenchmarkerDaemonSetPodTemplateSpec is the Compliance Benchmarker DaemonSet's PodTemplateSpec - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSetSpec](#compliancebenchmarkerdaemonsetspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceBenchmarkerDaemonSetPodSpec](#compliancebenchmarkerdaemonsetpodspec)_ | (Optional) Spec is the Compliance Benchmarker DaemonSet's PodSpec. | - - -### ComplianceBenchmarkerDaemonSetSpec - - - -ComplianceBenchmarkerDaemonSetSpec defines configuration for the Compliance Benchmarker DaemonSet. - -_Appears in:_ -- [ComplianceBenchmarkerDaemonSet](#compliancebenchmarkerdaemonset) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceBenchmarkerDaemonSetPodTemplateSpec](#compliancebenchmarkerdaemonsetpodtemplatespec)_ | (Optional) Template describes the Compliance Benchmarker DaemonSet pod that will be created. | - - -### ComplianceControllerDeployment - - - -ComplianceControllerDeployment is the configuration for the compliance controller Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceControllerDeploymentSpec](#compliancecontrollerdeploymentspec)_ | (Optional) Spec is the specification of the compliance controller Deployment. | - - -### ComplianceControllerDeploymentContainer - - - -ComplianceControllerDeploymentContainer is a compliance controller Deployment container. - -_Appears in:_ -- [ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance controller Deployment container by name.
Supported values are: compliance-controller | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance controller Deployment container's resources. If omitted, the compliance controller Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceControllerDeploymentInitContainer - - - -ComplianceControllerDeploymentInitContainer is a compliance controller Deployment init container. - -_Appears in:_ -- [ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance controller Deployment init container by name.
Supported values are: tigera-compliance-controller-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance controller Deployment init container's resources. If omitted, the compliance controller Deployment will use its default value for this init container's resources. | - - -### ComplianceControllerDeploymentPodSpec - - - -ComplianceControllerDeploymentPodSpec is the compliance controller Deployment's PodSpec. - -_Appears in:_ -- [ComplianceControllerDeploymentPodTemplateSpec](#compliancecontrollerdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceControllerDeploymentInitContainer](#compliancecontrollerdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of compliance controller init containers. If specified, this overrides the specified compliance controller Deployment init containers. If omitted, the compliance controller Deployment will use its default values for its init containers. | -| `containers` _[ComplianceControllerDeploymentContainer](#compliancecontrollerdeploymentcontainer) array_ | (Optional) Containers is a list of compliance controller containers. If specified, this overrides the specified compliance controller Deployment containers. If omitted, the compliance controller Deployment will use its default values for its containers. | - - -### ComplianceControllerDeploymentPodTemplateSpec - - - -ComplianceControllerDeploymentPodTemplateSpec is the compliance controller Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceControllerDeploymentSpec](#compliancecontrollerdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceControllerDeploymentPodSpec](#compliancecontrollerdeploymentpodspec)_ | (Optional) Spec is the compliance controller Deployment's PodSpec. | - - -### ComplianceControllerDeploymentSpec - - - -ComplianceControllerDeploymentSpec defines configuration for the compliance controller Deployment. - -_Appears in:_ -- [ComplianceControllerDeployment](#compliancecontrollerdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceControllerDeploymentPodTemplateSpec](#compliancecontrollerdeploymentpodtemplatespec)_ | (Optional) Template describes the compliance controller Deployment pod that will be created. | - - -### ComplianceReporterPodSpec - - - -ComplianceReporterPodSpec is the ComplianceReporter PodSpec. - -_Appears in:_ -- [ComplianceReporterPodTemplateSpec](#compliancereporterpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceReporterPodTemplateInitContainer](#compliancereporterpodtemplateinitcontainer) array_ | (Optional) InitContainers is a list of ComplianceReporter PodSpec init containers. If specified, this overrides the specified ComplianceReporter PodSpec init containers. If omitted, the ComplianceServer Deployment will use its default values for its init containers. | -| `containers` _[ComplianceReporterPodTemplateContainer](#compliancereporterpodtemplatecontainer) array_ | (Optional) Containers is a list of ComplianceServer containers. If specified, this overrides the specified ComplianceReporter PodSpec containers. If omitted, the ComplianceServer Deployment will use its default values for its containers. | - - -### ComplianceReporterPodTemplate - - - -ComplianceReporterPodTemplate is the configuration for the ComplianceReporter PodTemplate. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceReporterPodTemplateSpec](#compliancereporterpodtemplatespec)_ | (Optional) Spec is the specification of the ComplianceReporter PodTemplateSpec. | - - -### ComplianceReporterPodTemplateContainer - - - -ComplianceReporterPodTemplateContainer is a ComplianceServer Deployment container. - -_Appears in:_ -- [ComplianceReporterPodSpec](#compliancereporterpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment container by name.
Supported values are: reporter | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment container's resources. If omitted, the ComplianceServer Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceReporterPodTemplateInitContainer - - - -ComplianceReporterPodTemplateInitContainer is a ComplianceServer Deployment init container. - -_Appears in:_ -- [ComplianceReporterPodSpec](#compliancereporterpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceReporter PodSpec init container by name.
Supported values are: tigera-compliance-reporter-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceReporter PodSpec init container's resources. If omitted, the ComplianceServer Deployment will use its default value for this init container's resources. | - - -### ComplianceReporterPodTemplateSpec - - - -ComplianceReporterPodTemplateSpec is the ComplianceReporter PodTemplateSpec. - -_Appears in:_ -- [ComplianceReporterPodTemplate](#compliancereporterpodtemplate) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceReporterPodSpec](#compliancereporterpodspec)_ | (Optional) Spec is the ComplianceReporter PodTemplate's PodSpec. | - - -### ComplianceServerDeployment - - - -ComplianceServerDeployment is the configuration for the ComplianceServer Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceServerDeploymentSpec](#complianceserverdeploymentspec)_ | (Optional) Spec is the specification of the ComplianceServer Deployment. | - - -### ComplianceServerDeploymentContainer - - - -ComplianceServerDeploymentContainer is a ComplianceServer Deployment container. - -_Appears in:_ -- [ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment container by name.
Supported values are: compliance-server | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment container's resources. If omitted, the ComplianceServer Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceServerDeploymentInitContainer - - - -ComplianceServerDeploymentInitContainer is a ComplianceServer Deployment init container. - -_Appears in:_ -- [ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the ComplianceServer Deployment init container by name.
Supported values are: tigera-compliance-server-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named ComplianceServer Deployment init container's resources. If omitted, the ComplianceServer Deployment will use its default value for this init container's resources. | - - -### ComplianceServerDeploymentPodSpec - - - -ComplianceServerDeploymentPodSpec is the ComplianceServer Deployment's PodSpec. - -_Appears in:_ -- [ComplianceServerDeploymentPodTemplateSpec](#complianceserverdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceServerDeploymentInitContainer](#complianceserverdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of ComplianceServer init containers. If specified, this overrides the specified ComplianceServer Deployment init containers. If omitted, the ComplianceServer Deployment will use its default values for its init containers. | -| `containers` _[ComplianceServerDeploymentContainer](#complianceserverdeploymentcontainer) array_ | (Optional) Containers is a list of ComplianceServer containers. If specified, this overrides the specified ComplianceServer Deployment containers. If omitted, the ComplianceServer Deployment will use its default values for its containers. | - - -### ComplianceServerDeploymentPodTemplateSpec - - - -ComplianceServerDeploymentPodTemplateSpec is the ComplianceServer Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceServerDeploymentSpec](#complianceserverdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceServerDeploymentPodSpec](#complianceserverdeploymentpodspec)_ | (Optional) Spec is the ComplianceServer Deployment's PodSpec. | - - -### ComplianceServerDeploymentSpec - - - -ComplianceServerDeploymentSpec defines configuration for the ComplianceServer Deployment. - -_Appears in:_ -- [ComplianceServerDeployment](#complianceserverdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceServerDeploymentPodTemplateSpec](#complianceserverdeploymentpodtemplatespec)_ | (Optional) Template describes the ComplianceServer Deployment pod that will be created. | - - -### ComplianceSnapshotterDeployment - - - -ComplianceSnapshotterDeployment is the configuration for the compliance snapshotter Deployment. - -_Appears in:_ -- [ComplianceSpec](#compliancespec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceSnapshotterDeploymentSpec](#compliancesnapshotterdeploymentspec)_ | (Optional) Spec is the specification of the compliance snapshotter Deployment. | - - -### ComplianceSnapshotterDeploymentContainer - - - -ComplianceSnapshotterDeploymentContainer is a compliance snapshotter Deployment container. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance snapshotter Deployment container by name.
Supported values are: compliance-snapshotter | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance snapshotter Deployment container's resources. If omitted, the compliance snapshotter Deployment will use its default value for this container's resources. | -| `readinessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) ReadinessProbe allows customization of the readiness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | -| `livenessProbe` _[ProbeOverride](#probeoverride)_ | (Optional) LivenessProbe allows customization of the liveness probe timing parameters. The probe handler is set by the operator and cannot be overridden. | - - -### ComplianceSnapshotterDeploymentInitContainer - - - -ComplianceSnapshotterDeploymentInitContainer is a compliance snapshotter Deployment init container. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec) - -| Field | Description | -| --- | --- | -| `name` _string_ | Name is an enum which identifies the compliance snapshotter Deployment init container by name.
Supported values are: tigera-compliance-snapshotter-tls-key-cert-provisioner | -| `resources` _[ResourceRequirements](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#resourcerequirements-v1-core)_ | (Optional) Resources allows customization of limits and requests for compute resources such as cpu and memory. If specified, this overrides the named compliance snapshotter Deployment init container's resources. If omitted, the compliance snapshotter Deployment will use its default value for this init container's resources. | - - -### ComplianceSnapshotterDeploymentPodSpec - - - -ComplianceSnapshotterDeploymentPodSpec is the compliance snapshotter Deployment's PodSpec. - -_Appears in:_ -- [ComplianceSnapshotterDeploymentPodTemplateSpec](#compliancesnapshotterdeploymentpodtemplatespec) - -| Field | Description | -| --- | --- | -| `initContainers` _[ComplianceSnapshotterDeploymentInitContainer](#compliancesnapshotterdeploymentinitcontainer) array_ | (Optional) InitContainers is a list of compliance snapshotter init containers. If specified, this overrides the specified compliance snapshotter Deployment init containers. If omitted, the compliance snapshotter Deployment will use its default values for its init containers. | -| `containers` _[ComplianceSnapshotterDeploymentContainer](#compliancesnapshotterdeploymentcontainer) array_ | (Optional) Containers is a list of compliance snapshotter containers. If specified, this overrides the specified compliance snapshotter Deployment containers. If omitted, the compliance snapshotter Deployment will use its default values for its containers. | - - -### ComplianceSnapshotterDeploymentPodTemplateSpec - - - -ComplianceSnapshotterDeploymentPodTemplateSpec is the compliance snapshotter Deployment's PodTemplateSpec - -_Appears in:_ -- [ComplianceSnapshotterDeploymentSpec](#compliancesnapshotterdeploymentspec) - -| Field | Description | -| --- | --- | -| `spec` _[ComplianceSnapshotterDeploymentPodSpec](#compliancesnapshotterdeploymentpodspec)_ | (Optional) Spec is the compliance snapshotter Deployment's PodSpec. | - - -### ComplianceSnapshotterDeploymentSpec - - - -ComplianceSnapshotterDeploymentSpec defines configuration for the compliance snapshotter Deployment. - -_Appears in:_ -- [ComplianceSnapshotterDeployment](#compliancesnapshotterdeployment) - -| Field | Description | -| --- | --- | -| `template` _[ComplianceSnapshotterDeploymentPodTemplateSpec](#compliancesnapshotterdeploymentpodtemplatespec)_ | (Optional) Template describes the compliance snapshotter Deployment pod that will be created. | - - -### ComplianceSpec - - - -ComplianceSpec defines the desired state of Tigera compliance reporting capabilities. - -_Appears in:_ -- [Compliance](#compliance) - -| Field | Description | -| --- | --- | -| `complianceControllerDeployment` _[ComplianceControllerDeployment](#compliancecontrollerdeployment)_ | (Optional) ComplianceControllerDeployment configures the Compliance Controller Deployment. | -| `complianceSnapshotterDeployment` _[ComplianceSnapshotterDeployment](#compliancesnapshotterdeployment)_ | (Optional) ComplianceSnapshotterDeployment configures the Compliance Snapshotter Deployment. | -| `complianceBenchmarkerDaemonSet` _[ComplianceBenchmarkerDaemonSet](#compliancebenchmarkerdaemonset)_ | (Optional) ComplianceBenchmarkerDaemonSet configures the Compliance Benchmarker DaemonSet. | -| `complianceServerDeployment` _[ComplianceServerDeployment](#complianceserverdeployment)_ | (Optional) ComplianceServerDeployment configures the Compliance Server Deployment. | -| `complianceReporterPodTemplate` _[ComplianceReporterPodTemplate](#compliancereporterpodtemplate)_ | (Optional) ComplianceReporterPodTemplate configures the Compliance Reporter PodTemplate. | - - -### ComplianceStatus - - - -ComplianceStatus defines the observed state of Tigera compliance reporting capabilities. - -_Appears in:_ -- [Compliance](#compliance) - -| Field | Description | -| --- | --- | -| `state` _string_ | State provides user-readable status. | -| `conditions` _[Condition](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.32/#condition-v1-meta) array_ | (Optional) Conditions represents the latest observed set of conditions for the component. A component may be one or more of Ready, Progressing, Degraded or other customer types. | - - ### ComponentName _Underlying type:_ _string_ @@ -5644,11 +5163,6 @@ _Appears in:_ - [CalicoNodeWindowsDaemonSetContainer](#caliconodewindowsdaemonsetcontainer) - [CalicoWebhooksDeploymentContainer](#calicowebhooksdeploymentcontainer) - [CalicoWindowsUpgradeDaemonSetContainer](#calicowindowsupgradedaemonsetcontainer) -- [ComplianceBenchmarkerDaemonSetContainer](#compliancebenchmarkerdaemonsetcontainer) -- [ComplianceControllerDeploymentContainer](#compliancecontrollerdeploymentcontainer) -- [ComplianceReporterPodTemplateContainer](#compliancereporterpodtemplatecontainer) -- [ComplianceServerDeploymentContainer](#complianceserverdeploymentcontainer) -- [ComplianceSnapshotterDeploymentContainer](#compliancesnapshotterdeploymentcontainer) - [DashboardsJobContainer](#dashboardsjobcontainer) - [DexDeploymentContainer](#dexdeploymentcontainer) - [ECKOperatorStatefulSetContainer](#eckoperatorstatefulsetcontainer) diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_crd-ref-docs/config.yaml b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_crd-ref-docs/config.yaml index fd123b9c48..e7b0103bba 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_crd-ref-docs/config.yaml +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/_crd-ref-docs/config.yaml @@ -3,6 +3,7 @@ processor: ignoreTypes: - "List$" - "Tenant*" + - "^Compliance" # RE2 regular expressions describing type fields that should be excluded from the generated documentation. ignoreFields: - "TypeMeta$" diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/helm_customization.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/helm_customization.mdx index f9595a106e..92d4e6064f 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/helm_customization.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/helm_customization.mdx @@ -8,7 +8,6 @@ You can customize the following resources and settings during $[prodname] Helm-b - [Installation](api.mdx#installationspec) - [Api server](api.mdx#apiserverspec) -- [Compliance](api.mdx#compliancespec) - [Intrusion detection](api.mdx#intrusiondetectionspec) - [Log collector](api.mdx#logcollectorspec) - [Log storage](api.mdx#logstoragespec) @@ -63,10 +62,6 @@ monitor: enabled: true -compliance: - enabled: true - - policyRecommendation: enabled: true @@ -120,8 +115,6 @@ You can define pod affinity for the following Tigera components. Update the appr - calico-apiserver: through ApiServer resource - calico-nodes: through CalicoNodeDaemonSet property in the Installation resource - calico-kube-controllers: through CalicoKubeControllersDeployment property in the Installation resource -- compliance deployment pods (compliance-snapshotter, compliance-server, compliance-controller, compliance-benchmarker, -compliance-scaleloader, compliance-reporter): through Compliance resource - elasticsearch pods: through LogStorage resource - for more info on this option please checkout [Advanced Node Scheduling](../../operations/logstorage/advanced-node-scheduling.mdx) ### Encryption using WireGuard diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/tigerastatus.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/tigerastatus.mdx index cf68a274d2..aaef840282 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/tigerastatus.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/installation/tigerastatus.mdx @@ -11,7 +11,6 @@ Installing $[prodname] on your Kubernetes cluster is managed by the Tigera Opera - authentication - calico - calico-windows -- compliance - egressgateway - intrusion detection - log-collector @@ -40,7 +39,7 @@ For detailed output (including messages and further details on any non-functioni ## Log storage -Log storage provides persistent storage for $[prodname] Elasticsearch logs (flow, dns, l7, bgp, audit, etc.), and compliance reports. +Log storage provides persistent storage for $[prodname] Elasticsearch logs (flow, dns, l7, bgp, audit, etc.). To check log storage status, run the following command: diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/cis-benchmark.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/cis-benchmark.mdx deleted file mode 100644 index 92184ddb25..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/cis-benchmark.mdx +++ /dev/null @@ -1,71 +0,0 @@ ---- -description: Reference for the CIS benchmark compliance report in Calico Enterprise that audits Kubernetes nodes against CIS recommendations. ---- - -# CIS benchmark report - -To create a CIS benchmark report, create a `GlobalReport` with the `reportType` set to `cis-benchmark`. - -The following sample command uses a GlobalReport to create a daily CIS benchmark report that run on all the nodes. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-benchmark-report -spec: - reportType: cis-benchmark - schedule: 0 0 * * * -EOF -``` - -## OpenShift - -While there is no extra setup configuration required by the user to generate a benchmark report for OpenShift, the result sets will be different than a report generated for regular Kubernetes clusters. Use the [OpenShift Container Platform Security Guide](https://static.open-scap.org/ssg-guides/ssg-ocp4-guide-index.html) to cross-reference the benchmark results. - -## Downloadable reports - -## total-summary.csv - -A textual representation of the dashboard. - -| Heading | Description | Format | -| ---------------------- | ----------------------------------------------------------------- | -------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval start time. | RFC3339 string | -| type | The type of benchmark report | string | -| hiPercentageThreshold | The percentage of passing tests required to rate a node as high | int | -| medPercentageThreshold | The percentage of passing tests required to rate a node as medium | int | -| hiNodeCount | The number of nodes rated as high | int | -| medNodeCount | The number of nodes rated as medium | int | -| lowNodeCount | The number of nodes rated as low | int | - -## node-summary.csv - -A .csv file of test result summaries per node. - -| Heading | Description | Format | -| ------------ | ---------------------------------------------------------------------------------- | ------ | -| node | The name of the node. | string | -| version | The version of the platform. | string | -| status | The rating of the node based on percentage of tests passing. | string | -| testsPassing | The number of tests passing. | int | -| testsFailing | The number of tests failing. | int | -| testsUnknown | The number of tests whose results are undetermined due to automation restrictions. | int | -| testsTotal | The total number of tests executed. | int | - -### failed-tests.csv - -A .csv file of tests that have failed. - -| Heading | Description | Format | -| --------- | -------------------------------------------------------------------------------------- | ------ | -| nodeName | Node where the test is executed. | string | -| testIndex | Index of the test on the Kubernetes CIS benchmark. | string | -| status | Test results: PASS, FAIL, INFO. | string | -| scored | Indicates whether the Kubernetes CIS benchmark counts this test towards their scoring. | string | - -### all-tests.csv - -A .csv file with tests that were executed on all nodes. Format remains the same as above. diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/index.mdx deleted file mode 100644 index deb390a14f..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/index.mdx +++ /dev/null @@ -1,11 +0,0 @@ ---- -description: Reference index for compliance report types available with Calico Enterprise covering inventory, network access, policy audit, and CIS benchmark. -hide_table_of_contents: true ---- - -# Compliance reports (deprecated) - -import DocCardList from '@theme/DocCardList'; -import { useCurrentSidebarCategory } from '@docusaurus/theme-common'; - - diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/inventory.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/inventory.mdx deleted file mode 100644 index 4e2585393d..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/inventory.mdx +++ /dev/null @@ -1,86 +0,0 @@ ---- -description: Reference for the inventory compliance report in Calico Enterprise that catalogs endpoints, namespaces, and policies in scope at report time. ---- - -# Inventory report - -To create an Inventory report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `inventory`. - -The following sample command creates a GlobalReport that results in a daily inventory report for -endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-inventory-report - labels: - deployment: production -spec: - reportType: inventory - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ----------------------------- | ----------------------------------------------------------------------------------------------------------- | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| endpointsNumInScope | The number of enumerated endpoints that are in-scope according to the requested endpoint selection options. | number | -| endpointsNumIngressProtected | The number of in-scope endpoints that were always ingress protected during the report interval. | number | -| endpointsNumEgressProtected | The number of in-scope endpoints that were always egress protected during the report interval. | number | -| namespacesNumInScope | The number of namespaces containing in-scope endpoints. | number | -| namespacesNumIngressProtected | The number of namespaces whose in-scope endpoints were always ingress protected during the report interval. | number | -| namespacesNumEgressProtected | The number of namespaces whose in-scope endpoints were always egress protected during the report interval. | number | -| serviceAccountsNumInScope | The number of service accounts associated with in-scope endpoints. | number | - -### endpoints.csv - -An endpoints CSV file that includes per-endpoint information. - -| Heading | Description | Format | -| ---------------- | --------------------------------------------------------------------------------------------- | ----------------------------------- | -| endpoint | The name of the endpoint. | string | -| ingressProtected | Whether the endpoint was always ingress protected during the report interval. | bool | -| egressProtected | Whether the endpoint was always egress protected during the report interval. | bool | -| envoyEnabled | Whether the endpoint was always Envoy enabled during the report interval. | bool | -| appliedPolicies | The full set of policies that applied to the endpoint at any time during the report interval. | ";" separated list of policy names | -| services | The full set of services that included this endpoint at any time during the report interval. | ";" separated list of service names | - -### namespaces.csv - -A namespaces CSV file that includes per-namespace information. - -| Heading | Description | Format | -| ---------------- | ------------------------------------------------------------------------------------------------------------- | ------ | -| namespace | The name of the namespace. | string | -| ingressProtected | Whether all in-scope endpoints within the namespace were always ingress protected during the report interval. | bool | -| egressProtected | Whether all in-scope endpoints within the namespace were always egress protected during the report interval. | bool | -| envoyEnabled | Whether all in-scope endpoints within the namespace were always Envoy enabled during the report interval. | bool | - -### services.csv - -A services CSV file that includes per-service information. - -| Heading | Description | Format | -| ---------------- | ---------------------------------------------------------------------------------------------------------------- | ------ | -| service | The name of the service. | string | -| ingressProtected | Whether all in-scope endpoints that are in the service were always ingress protected during the report interval. | bool | -| envoyEnabled | Whether all in-scope endpoints that are in the service were always Envoy enabled during the report interval. | bool | diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/network-access.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/network-access.mdx deleted file mode 100644 index e01798e591..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/network-access.mdx +++ /dev/null @@ -1,92 +0,0 @@ ---- -description: Reference for the network access compliance report in Calico Enterprise that summarizes which endpoints could communicate based on policy. ---- - -# Network Access report - -To create an Inventory report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `network-access`. - -The following sample command creates a GlobalReport that results in a daily network access report for -endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-network-access-report - labels: - deployment: production -spec: - reportType: network-access - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -:::note - -There is a known issue that audit logs do not contain deletion events for resources that were -deleted implicitly as part of a namespace deletion event. Currently, this means policies and pods that have been -deleted in this way may still appear in the reports that cover any period within the next day. - -::: - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| endpointsNumIngressProtected | The number of in-scope endpoints that were always ingress protected during the report interval. | number | -| endpointsNumEgressProtected | The number of in-scope endpoints that were always egress protected during the report interval. | number | -| endpointsNumIngressUnprotected | The number of in-scope endpoints that were ingress unprotected at any point during the report interval. | number | -| endpointsNumEgressUnprotected | The number of in-scope endpoints that were egress unprotected at any point during the report interval. | number | -| endpointsNumIngressFromInternet | The number of in-scope endpoints that allowed ingress traffic from the public internet at any point during the report interval. | number | -| endpointsNumEgressToInternet | The number of in-scope endpoints that allowed egress traffic to the public internet at any point during the report interval. | number | -| endpointsNumIngressFromOtherNamespace | The number of in-scope endpoints that allowed ingress traffic from another namespace at any point during the report interval. | number | -| endpointsNumEgressToOtherNamespace | The number of in-scope endpoints that allowed egress traffic to another namespace at any point during the report interval. | number | -| endpointsNumEnvoyEnabled | The number of in-scope endpoints that were always Envoy enabled during the report interval. | number | - -### endpoints.csv - -An endpoints CSV file that includes per-endpoint information. - -| Heading | Description | Format | -| ------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | ----------------------------------- | -| endpoint | The name of the endpoint. | string | -| ingressProtected | Whether the endpoint was always ingress protected during the report interval. | bool | -| egressProtected | Whether the endpoint was always egress protected during the report interval. | bool | -| ingressFromInternet | Whether the endpoint allowed ingress traffic from the public internet at any point during the report interval. | number | -| egressToInternet | Whether the endpoint allowed egress traffic to the public internet at any point during the report interval. | number | -| ingressFromOtherNamespace | Whether the endpoint allowed ingress traffic from another namespace at any point during the report interval. | number | -| egressToOtherNamespace | Whether the endpoint allowed egress traffic to another namespace at any point during the report interval. | number | -| envoyEnabled | Whether the endpoint was always Envoy enabled during the report interval. | bool | -| appliedPolicies | The full set of policies that applied to the endpoint at any time during the report interval. | ";" separated list of policy names | -| services | The full set of services that included this endpoint at any time during the report interval. | ";" separated list of service names | -| trafficAggregationPrefix\* | The flow log aggregation prefix. | string | -| endpointsGeneratingTrafficToThisEndpoint\* | The set of endpoints that were generating traffic to this endpoint. | ";" separated list of service names | -| endpointsReceivingTrafficFromThisEndpoint\* | The set of endpoints that this endpoint is generating traffic to. | ";" separated list of service names | - -\* Traffic data is determined from flow logs. By default, $[prodname] aggregates flow logs so that flows to -and from pods in the same replica set are summarized if the flows are accepted. (Denied flows are not aggregated this -way by default). This means that the per-endpoint traffic details do not refer specifically to that endpoint, but -rather the set of endpoints specified by the trafficAggregationPrefix. - -If you want per-endpoint detail you should turn down the level of aggregation. To do so, -set the value of `flowLogsFileAggregationKindForAllowed` to 1 using a [FelixConfiguration][felixconfig] - -[felixconfig]: ../felixconfig.mdx diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/overview.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/overview.mdx deleted file mode 100644 index ec0cafe0e5..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/overview.mdx +++ /dev/null @@ -1,102 +0,0 @@ ---- -description: Reference overview of compliance reporting in Calico Enterprise covering schedules, report scope, and the GlobalReport resource. ---- - -# Compliance reports (deprecated) - -The $[prodname] compliance reporting feature provides the following compliance reports: - -- [Inventory](inventory.mdx) -- [Network Access](network-access.mdx) -- [Policy Audit](policy-audit.mdx) -- [CIS Benchmark](cis-benchmark.mdx) - -Create a [`GlobalReport`](../globalreport.mdx) resource to automatically schedule report generation, and specify the report scope (resources to include in the report). - -## Concepts - -### In-scope asset - -An asset (Pod or HostEndpoint) is flagged as in-scope by endpoint labels, namespace and/or namespace labels, and service -account and/or service account labels. - -_How this applies to the report_: -The report includes all resources that were in-scope at any point during the report interval. The resource is included -when it is first flagged as in-scope according to the configured label selector and name selections. The resource is -included even if the resource is deleted or goes out-of-scope before the end of the report interval. - -### Ingress protected - -An endpoint is ingress protected if it has at least one Ingress policy that is applied to it. - -A service is ingress protected if all of the in-scope endpoints within that service are ingress protected. - -A namespace is ingress protected if all of the in-scope endpoints within that namespace are ingress protected. - -_How this applies to the report_: -An endpoint is ingress protected only if it was ingress protected throughout the entire report interval. - -### Egress protected - -As per ingress, but with egress policy rules. Note that egress statistics are not obtained for services. - -### Allows ingress traffic from another namespace - -An endpoint is flagged as allowing ingress traffic from another namespace if it has one or more policies that apply to -it with an ingress allow rule that: - -- has an explicit namespace selector configured, or -- has no source selector or source CIDR configured, or -- (for GlobalNetworkPolicy) has no source CIDR. - -A service is flagged as allowing ingress traffic from another namespace if any of the in-scope endpoints within that -service are flagged. - -A namespace is flagged as allowing ingress traffic from another namespace if all of the in-scope endpoints within that -namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as allowing ingress traffic from another namespace if it was flagged at any time during the -report interval. - -### Allows egress traffic to another namespace - -As per ingress, but with egress policy rules and destination selector/CIDR. Note that egress statistics are not obtained -for services. - -### Allows ingress traffic from the internet - -An endpoint is flagged as allowing ingress traffic from the internet if it has one or more policies that apply to it -with an ingress allow rule that: - -- has no source selector or source CIDR configured, or -- has a source CIDR in the non-private IP ranges and has no source selector, or -- has a source selector that matches one or more NetworkSets that contain at least one non-private IP. - -A service is flagged as allowing ingress traffic from the internet if any of the in-scope endpoints within that service -are flagged. - -A namespace is flagged as allowing ingress traffic from the internet if all of the in-scope endpoints within that -namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as allowing ingress traffic from the internet if it was flagged as such at any time during the -report interval. - -### Allows egress traffic to the internet - -As per ingress, but with egress policy rules and destination selector/CIDR. Note that egress statistics are not obtained -for services. - -### Envoy enabled - -An endpoint is flagged as Envoy Enabled if the associated Pod Spec and Annotations indicate that an Istio init and main -container are deployed in the Pod. Provided Istio is appropriately configured on the cluster, this can be extrapolated -to be indication of whether mTLS is enabled for the endpoint. - -A service is flagged as Envoy enabled if all of the in-scope endpoints within that service are flagged. - -A namespace is flagged as Envoy enabled if all of the in-scope endpoints within that namespace are flagged. - -_How this applies to the report_: -An endpoint is flagged as Envoy enabled if it was flagged as such throughout the entire report interval. diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/policy-audit.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/policy-audit.mdx deleted file mode 100644 index 67d19a5b84..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/compliance-reports/policy-audit.mdx +++ /dev/null @@ -1,56 +0,0 @@ ---- -description: Reference for the policy audit compliance report in Calico Enterprise that records changes to network policies during the report period. ---- - -# Policy audit report - -To create a Policy Audit report, create a [`GlobalReport`](../globalreport.mdx) with the `reportType` -set to `policy-audit`. - -The following sample command creates a GlobalReport that results in a daily policy audit report for -policies that are applied to endpoints in the `public` namespace. - -```bash -kubectl apply -f - << EOF -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-public-policy-audit-report - labels: - deployment: production -spec: - reportType: policy-audit - endpoints: - namespaces: - names: - - public - schedule: 0 0 * * * -EOF -``` - -## Downloadable reports - -### summary.csv - -A summary CSV file that includes details about the report parameters and the top level counts. - -| Heading | Description | Format | -| ----------------------- | ------------------------------------------------------------------------------------------------------ | ------------------------------------------- | -| startTime | The report interval start time. | RFC3339 string | -| endTime | The report interval end time. | RFC3339 string | -| endpointSelector | The endpoint selector used to restrict in-scope endpoints by endpoint label selection. | selector string | -| namespaceNames | The set of namespace names used to restrict in-scope endpoints by namespace. | ";" separated list of namespace names | -| namespaceSelector | The namespace selector used to restrict in-scope endpoints by namespace label selection. | selector string | -| serviceAccountNames | The set of service account names used to restrict in-scope endpoints by service account. | ";" separated list of service account names | -| serviceAccountSelectors | The service account selector used to restrict in-scope endpoints by service account label selection. | selector string | -| numCreatedPolicies | The number of policies that apply to in-scope endpoints that were created during the report interval. | number | -| numModifiedPolicies | The number of policies that apply to in-scope endpoints that were modified during the report interval. | number | -| numDeletedPolicies | The number of policies that apply to in-scope endpoints that were deleted during the report interval. | number | - -### events.json - -Events formatted in JSON. - -### events.yaml - -Events formatted in YAML. diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/globalreport.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/globalreport.mdx deleted file mode 100644 index 16e2c70171..0000000000 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/globalreport.mdx +++ /dev/null @@ -1,149 +0,0 @@ ---- -description: Reference for the GlobalReport resource in Calico Enterprise that schedules compliance reports against cluster network and policy state. ---- - -# Global report - -A global report resource is a configuration for generating compliance reports. A global report configuration in $[prodname] lets you: - -- Specify report contents, frequency, and data filtering -- Specify the node(s) on which to run the report generation jobs -- Enable/disable creation of new jobs for generating the report - -For `kubectl` [commands](https://kubernetes.io/docs/reference/kubectl/overview/), the following case-insensitive aliases -may be used to specify the resource type on the CLI: -`globalreport.projectcalico.org`, `globalreports.projectcalico.org` and abbreviations such as -`globalreport.p` and `globalreports.p`. - -## Sample YAML - -```yaml -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: weekly-full-inventory -spec: - reportType: inventory - schedule: 0 0 * * 0 - jobNodeSelector: - nodetype: infrastructure - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: hourly-accounts-networkaccess -spec: - reportType: network-access - endpoints: - namespaces: - names: ['payable', 'collections', 'payroll'] - schedule: 0 * * * * - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: monthly-widgets-controller-tigera-policy-audit -spec: - reportType: policy-audit - schedule: 0 0 1 * * - endpoints: - serviceAccounts: - names: ['controller'] - namespaces: - names: ['widgets'] - ---- -apiVersion: projectcalico.org/v3 -kind: GlobalReport -metadata: - name: daily-cis-benchmark -spec: - reportType: cis-benchmark - schedule: 0 0 * * * - cis: - resultsFilters: - - benchmarkSelection: { kubernetesVersion: '1.13' } - exclude: ['1.1.4', '1.2.5'] -``` - -## GlobalReport Definition - -### Metadata - -| Field | Description | Accepted Values | Schema | -| ------ | ---------------------------------------- | ------------------------------------------------ | ------ | -| name | The name of this report. | Lower-case alphanumeric with optional `-` or `.` | string | -| labels | A set of labels to apply to this report. | | map | - -### Spec - -| Field | Description | Required | Accepted Values | Schema | -| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------- | -| reportType | The type of report to produce. This field controls the content of the report - see the links for each type for more details. | Yes | [cis‑benchmark](compliance-reports/cis-benchmark.mdx), [inventory](compliance-reports/inventory.mdx), [network‑access](compliance-reports/network-access.mdx), [policy‑audit](compliance-reports/policy-audit.mdx) | string | -| endpoints | Specify which endpoints are in scope. If omitted, selects everything. | | | [EndpointsSelection](#endpointsselection) | -| schedule | Configure report frequency by specifying start and end time in [cron-format][cron-format]. Reports are started 30 minutes (configurable) after the scheduled value to allow enough time for data archival. A maximum limit of 12 schedules per hour is enforced (an average of one report every 5 minutes). | Yes | | string | -| jobNodeSelector | Specify the node(s) for scheduling the report jobs using selectors. | | | map | -| suspend | Disable future scheduled report jobs. In-flight reports are not affected. | | | bool | -| cis | Parameters related to generating a CIS benchmark report. | | | [CISBenchmarkParams](#cisbenchmarkparams) | - -### EndpointsSelection - -| Field | Description | Schema | -| --------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------- | -| selector | Endpoint label selector to restrict endpoint selection. | string | -| namespaces | Namespace name and label selector to restrict endpoints by selected namespaces. | [NamesAndLabelsMatch](#namesandlabelsmatch) | -| serviceAccounts | Service account name and label selector to restrict endpoints by selected service accounts. | [NamesAndLabelsMatch](#namesandlabelsmatch) | - -### CISBenchmarkParams - -| Fields | Description | Required | Schema | -| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----------------------------------------- | -| highThreshold | Integer percentage value that determines the lower limit of passing tests to consider a node as healthy. Default: 100 | No | int | -| medThreshold | Integer percentage value that determines the lower limit of passing tests to consider a node as unhealthy. Default: 50 | No | int | -| includeUnscoredTests | Boolean value that when false, applies a filter to exclude tests that are marked as “Unscored” by the CIS benchmark standard. If true, the tests will be included in the report. Default: false | No | bool | -| numFailedTests | Integer value that sets the number of tests to display in the Top-failed Tests section of the CIS benchmark report. Default: 5 | No | int | -| resultsFilters | Specifies an include or exclude filter to apply on the test results that will appear on the report. | No | [CISBenchmarkFilter](#cisbenchmarkfilter) | - -### CISBenchmarkFilter - -| Fields | Description | Required | Schema | -| ------------------ | ---------------------------------------------------------------------------------------------- | -------- | ----------------------------------------------- | -| benchmarkSelection | Specify which set of benchmarks that this filter should apply to. Selects all benchmark types. | No | [CISBenchmarkSelection](#cisbenchmarkselection) | -| exclude | Specify which benchmark tests to exclude | No | array of strings | -| include | Specify which benchmark tests to include only (higher precedence than exclude) | No | array of strings | - -### CISBenchmarkSelection - -| Fields | Description | Required | Schema | -| ----------------- | -------------------------------------- | -------- | ------ | -| kubernetesVersion | Specifies a version of the benchmarks. | Yes | string | - -### NamesAndLabelsMatch - -| Field | Description | Schema | -| -------- | ------------------------------------ | ------ | -| names | Set of resource names. | list | -| selector | Selects a set of resources by label. | string | - -Use the `NamesAndLabelsMatch`to limit the scope of endpoints. If both `names` -and `selector` are specified, the resource is identified using label _AND_ name -match. - -:::note - -To use the $[prodname] compliance reporting feature, you must ensure all required resource types -are being audited and the logs archived in Elasticsearch. You must explicitly configure the [Kubernetes API Server](../../observability/kube-audit.mdx) - to send audit logs for Kubernetes-owned resources -to Elasticsearch. - -::: - -## Supported operations - -| Datastore type | Create/Delete | Update | Get/List | Notes | -| --------------------- | ------------- | ------ | -------- | ----- | -| Kubernetes API server | Yes | Yes | Yes | | - -[cron-format]: https://en.wikipedia.org/wiki/Cron diff --git a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/overview.mdx b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/overview.mdx index a70cdfda35..69e8943535 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/overview.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/reference/resources/overview.mdx @@ -54,7 +54,6 @@ The following resources are supported: - [GlobalAlert](globalalert.mdx) - [GlobalNetworkPolicy](globalnetworkpolicy.mdx) - [GlobalNetworkSet](globalnetworkset.mdx) -- [GlobalReport](globalreport.mdx) - [GlobalThreatFeed](globalthreatfeed.mdx) - [HostEndpoint](hostendpoint.mdx) - [IPPool](ippool.mdx) diff --git a/calico-enterprise_versioned_docs/version-3.24-1/release-notes/index.mdx b/calico-enterprise_versioned_docs/version-3.24-1/release-notes/index.mdx index cdf3ca79ea..e360611981 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/release-notes/index.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/release-notes/index.mdx @@ -63,6 +63,7 @@ For more information, see [L2 reachability for pods and services without BGP](.. ### Deprecated and removed features +- The compliance reporting feature has been removed from the $[prodname] web console. - $[prodname] is moving the `projectcalico.org/v3` API from the aggregated API server to native Kubernetes CRDs. Both mechanisms will be supported until native v3 CRDs are compatible with all supported platforms, after which the aggregated API server will be removed. ## Technology Preview features diff --git a/calico-enterprise_versioned_sidebars/version-3.24-1-sidebars.json b/calico-enterprise_versioned_sidebars/version-3.24-1-sidebars.json index bf09a1148b..5ac9289392 100644 --- a/calico-enterprise_versioned_sidebars/version-3.24-1-sidebars.json +++ b/calico-enterprise_versioned_sidebars/version-3.24-1-sidebars.json @@ -646,7 +646,7 @@ }, { "type": "category", - "label": "Compliance and security", + "label": "Security", "link": { "type": "doc", "id": "compliance/index" @@ -661,9 +661,6 @@ "compliance/istio/deploy-istio-ambient" ] }, - "compliance/enable-compliance", - "compliance/overview", - "compliance/compliance-reports-cis", "compliance/encrypt-cluster-pod-traffic", "compliance/configure-http-proxy" ] @@ -1000,21 +997,6 @@ "reference/resources/bgpfilter", "reference/resources/blockaffinity", "reference/resources/caliconodestatus", - { - "type": "category", - "label": "Compliance reports", - "link": { - "type": "doc", - "id": "reference/resources/compliance-reports/index" - }, - "items": [ - "reference/resources/compliance-reports/overview", - "reference/resources/compliance-reports/inventory", - "reference/resources/compliance-reports/network-access", - "reference/resources/compliance-reports/policy-audit", - "reference/resources/compliance-reports/cis-benchmark" - ] - }, "reference/resources/deeppacketinspection", "reference/resources/earlynetworkconfiguration", "reference/resources/egressgatewaypolicy", @@ -1023,7 +1005,6 @@ "reference/resources/globalalert", "reference/resources/globalnetworkpolicy", "reference/resources/globalnetworkset", - "reference/resources/globalreport", "reference/resources/globalthreatfeed", "reference/resources/hostendpoint", "reference/resources/ippool", diff --git a/sidebars-calico-enterprise.js b/sidebars-calico-enterprise.js index 8dd7e80742..06d2a9331b 100644 --- a/sidebars-calico-enterprise.js +++ b/sidebars-calico-enterprise.js @@ -503,7 +503,7 @@ module.exports = { }, { type: 'category', - label: 'Compliance and security', + label: 'Security', link: { type: 'doc', id: 'compliance/index' }, items: [ { @@ -515,9 +515,6 @@ module.exports = { 'compliance/istio/deploy-istio-ambient', ], }, - 'compliance/enable-compliance', - 'compliance/overview', - 'compliance/compliance-reports-cis', 'compliance/encrypt-cluster-pod-traffic', 'compliance/configure-http-proxy', ], @@ -768,18 +765,6 @@ module.exports = { 'reference/resources/bgpfilter', 'reference/resources/blockaffinity', 'reference/resources/caliconodestatus', - { - type: 'category', - label: 'Compliance reports', - link: { type: 'doc', id: 'reference/resources/compliance-reports/index' }, - items: [ - 'reference/resources/compliance-reports/overview', - 'reference/resources/compliance-reports/inventory', - 'reference/resources/compliance-reports/network-access', - 'reference/resources/compliance-reports/policy-audit', - 'reference/resources/compliance-reports/cis-benchmark', - ], - }, 'reference/resources/deeppacketinspection', 'reference/resources/earlynetworkconfiguration', 'reference/resources/egressgatewaypolicy', @@ -788,7 +773,6 @@ module.exports = { 'reference/resources/globalalert', 'reference/resources/globalnetworkpolicy', 'reference/resources/globalnetworkset', - 'reference/resources/globalreport', 'reference/resources/globalthreatfeed', 'reference/resources/hostendpoint', 'reference/resources/ippool',