checkpoint/cp-nano-k8s-workload-protection本Docker镜像为一个轻量级(nano)代理容器,专为Kubernetes集群设计,主要用于提供访问控制执行功能,确保集群内资源访问的安全性和合规性。通过在集群中部署该代理,可实现对Pod、服务、配置等资源访问的精细化控制与策略执行。
bashdocker run -d \ --name nano-access-agent \ -e K8S_API_SERVER=[***] \ -e POLICY_CONFIG=/etc/agent/policy.yaml \ -v /path/to/your/policy.yaml:/etc/agent/policy.yaml \ -v /var/run/secrets/kubernetes.io/serviceaccount:/var/run/secrets/kubernetes.io/serviceaccount \ your-registry/nano-access-agent:latest
yamlapiVersion: apps/v1 kind: DaemonSet metadata: name: nano-access-agent namespace: kube-system spec: selector: matchLabels: app: nano-access-agent template: metadata: labels: app: nano-access-agent spec: containers: - name: nano-access-agent image: your-registry/nano-access-agent:latest env: - name: K8S_API_SERVER value: "[***]" - name: LOG_LEVEL value: "info" volumeMounts: - name: policy-config mountPath: /etc/agent/policy.yaml subPath: policy.yaml - name: sa-token mountPath: /var/run/secrets/kubernetes.io/serviceaccount readOnly: true volumes: - name: policy-config configMap: name: nano-agent-policy - name: sa-token secret: secretName: default-token-xxxx
| 环境变量名 | 描述 | 默认值 | 可选值 |
|---|---|---|---|
K8S_API_SERVER | Kubernetes API服务器地址 | [***] | 有效的K8S API地址 |
POLICY_CONFIG | 访问控制策略配置文件路径 | /etc/agent/policy.yaml | 容器内可访问的文件路径 |
LOG_LEVEL | 日志级别 | info | debug, info, warn, error |
SYNC_INTERVAL | 策略同步间隔(秒) | 30 | 正整数 |
yamlapiVersion: access-agent.nano/v1 kind: AccessPolicy rules: - resource: apiGroup: "" resource: "pods" verbs: ["get", "list", "watch"] subjects: - kind: "ServiceAccount" name: "default" namespace: "default" action: "allow" - resource: apiGroup: "apps" resource: "deployments" verbs: ["create", "update", "delete"] subjects: - kind: "Group" name: "admin" action: "allow" - action: "deny" # 默认拒绝所有未匹配规则的请求
resources: {limits: {cpu: "100m", memory: "128Mi"}, requests: {cpu: "50m", memory: "64Mi"}})以避免资源竞争TLS_CERT_PATH与TLS_KEY_PATH环境变量)以保障通信安全manifest unknown 错误
TLS 证书验证失败
DNS 解析超时
410 错误:版本过低
402 错误:流量耗尽
身份认证失败错误
429 限流错误
凭证保存错误
来自真实用户的反馈,见证轩辕镜像的优质服务