diff --git a/helm-chart/Chart.yaml b/helm-chart/Chart.yaml index 5c73f9700..311986032 100644 --- a/helm-chart/Chart.yaml +++ b/helm-chart/Chart.yaml @@ -1,6 +1,6 @@ apiVersion: v2 name: kubeshark -version: "52.3.92" +version: "52.3.93" description: The API Traffic Analyzer for Kubernetes home: https://kubeshark.co keywords: diff --git a/helm-chart/values.yaml b/helm-chart/values.yaml index 4d367a0a3..81b2a3e8a 100644 --- a/helm-chart/values.yaml +++ b/helm-chart/values.yaml @@ -85,6 +85,10 @@ tap: filter: "" canDownloadPCAP: true canUseScripting: true + scriptingPermissions: + canSave: true + canActivate: true + canDelete: true canUpdateTargetedPods: true canStopTrafficCapturing: true showAdminConsoleLink: true @@ -134,7 +138,8 @@ tap: - syscall - ws - ldap - customMacros: {} + customMacros: + https: tls and (http or http2) metrics: port: 49100 pprof: diff --git a/manifests/complete.yaml b/manifests/complete.yaml index 5e40a2317..2416f19ea 100644 --- a/manifests/complete.yaml +++ b/manifests/complete.yaml @@ -4,10 +4,10 @@ apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-hub-network-policy @@ -34,10 +34,10 @@ apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-front-network-policy @@ -61,10 +61,10 @@ apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-worker-network-policy @@ -90,10 +90,10 @@ apiVersion: v1 kind: ServiceAccount metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-service-account @@ -107,10 +107,10 @@ metadata: namespace: default labels: app.kubeshark.co/app: hub - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm stringData: LICENSE: '' @@ -124,10 +124,10 @@ metadata: namespace: default labels: app.kubeshark.co/app: hub - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm stringData: AUTH_SAML_X509_CRT: | @@ -140,10 +140,10 @@ metadata: namespace: default labels: app.kubeshark.co/app: hub - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm stringData: AUTH_SAML_X509_KEY: | @@ -155,10 +155,10 @@ metadata: name: kubeshark-nginx-config-map namespace: default labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm data: default.conf: | @@ -219,10 +219,10 @@ metadata: namespace: default labels: app.kubeshark.co/app: hub - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm data: POD_REGEX: '.*' @@ -256,7 +256,7 @@ data: CLOUD_LICENSE_ENABLED: 'true' DUPLICATE_TIMEFRAME: '200ms' ENABLED_DISSECTORS: 'amqp,dns,http,icmp,kafka,redis,sctp,syscall,ws,ldap' - CUSTOM_MACROS: '{}' + CUSTOM_MACROS: '{"https":"tls and (http or http2)"}' DISSECTORS_UPDATING_ENABLED: 'true' DETECT_DUPLICATES: 'false' PCAP_DUMP_ENABLE: 'true' @@ -270,10 +270,10 @@ apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-cluster-role-default @@ -318,10 +318,10 @@ apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-cluster-role-binding-default @@ -340,10 +340,10 @@ apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-self-config-role @@ -370,10 +370,10 @@ apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-self-config-role-binding @@ -393,10 +393,10 @@ kind: Service metadata: labels: app.kubeshark.co/app: hub - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-hub @@ -415,10 +415,10 @@ apiVersion: v1 kind: Service metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-front @@ -437,10 +437,10 @@ kind: Service apiVersion: v1 metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: prometheus.io/scrape: 'true' @@ -450,10 +450,10 @@ metadata: spec: selector: app.kubeshark.co/app: worker - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm ports: - name: metrics @@ -466,10 +466,10 @@ kind: Service apiVersion: v1 metadata: labels: - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: prometheus.io/scrape: 'true' @@ -479,10 +479,10 @@ metadata: spec: selector: app.kubeshark.co/app: hub - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm ports: - name: metrics @@ -497,10 +497,10 @@ metadata: labels: app.kubeshark.co/app: worker sidecar.istio.io/inject: "false" - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-worker-daemon-set @@ -515,10 +515,10 @@ spec: metadata: labels: app.kubeshark.co/app: worker - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm name: kubeshark-worker-daemon-set namespace: kubeshark @@ -528,7 +528,7 @@ spec: - /bin/sh - -c - mkdir -p /sys/fs/bpf && mount | grep -q '/sys/fs/bpf' || mount -t bpf bpf /sys/fs/bpf - image: 'docker.io/kubeshark/worker:v52.3.92' + image: 'docker.io/kubeshark/worker:v52.3.93' imagePullPolicy: Always name: check-bpf securityContext: @@ -540,7 +540,7 @@ spec: - command: - ./tracer - -init-bpf - image: 'docker.io/kubeshark/worker:v52.3.92' + image: 'docker.io/kubeshark/worker:v52.3.93' imagePullPolicy: Always name: init-bpf securityContext: @@ -570,7 +570,7 @@ spec: - 'auto' - -staletimeout - '30' - image: 'docker.io/kubeshark/worker:v52.3.92' + image: 'docker.io/kubeshark/worker:v52.3.93' imagePullPolicy: Always name: sniffer ports: @@ -656,7 +656,7 @@ spec: - -disable-tls-log # - -loglevel # - 'warning' - image: 'docker.io/kubeshark/worker:v52.3.92' + image: 'docker.io/kubeshark/worker:v52.3.93' imagePullPolicy: Always name: tracer env: @@ -758,10 +758,10 @@ kind: Deployment metadata: labels: app.kubeshark.co/app: hub - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-hub @@ -777,10 +777,10 @@ spec: metadata: labels: app.kubeshark.co/app: hub - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm spec: dnsPolicy: ClusterFirstWithHostNet @@ -810,7 +810,7 @@ spec: value: 'https://api.kubeshark.co' - name: PROFILING_ENABLED value: 'false' - image: 'docker.io/kubeshark/hub:v52.3.92' + image: 'docker.io/kubeshark/hub:v52.3.93' imagePullPolicy: Always readinessProbe: periodSeconds: 1 @@ -864,10 +864,10 @@ kind: Deployment metadata: labels: app.kubeshark.co/app: front - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm annotations: name: kubeshark-front @@ -883,10 +883,10 @@ spec: metadata: labels: app.kubeshark.co/app: front - helm.sh/chart: kubeshark-52.3.92 + helm.sh/chart: kubeshark-52.3.93 app.kubernetes.io/name: kubeshark app.kubernetes.io/instance: kubeshark - app.kubernetes.io/version: "52.3.92" + app.kubernetes.io/version: "52.3.93" app.kubernetes.io/managed-by: Helm spec: containers: @@ -921,7 +921,7 @@ spec: value: 'false' - name: REACT_APP_SENTRY_ENVIRONMENT value: 'production' - image: 'docker.io/kubeshark/front:v52.3.92' + image: 'docker.io/kubeshark/front:v52.3.93' imagePullPolicy: Always name: kubeshark-front livenessProbe: