diff --git a/security/envs/dev/Chart.yaml b/security/envs/dev/Chart.yaml index 5e2ff5a2a..72966fdf2 100644 --- a/security/envs/dev/Chart.yaml +++ b/security/envs/dev/Chart.yaml @@ -1,5 +1,5 @@ apiVersion: v1 appVersion: "1.0" -name: dev-security-ebs-encryption -description: App of apps chart for the dev EKS environment using security best practices. +name: dev-security +description: App of apps chart for the dev EKS environment using security best practices version: 0.1.0 diff --git a/security/envs/dev/templates/team-danger.yaml b/security/envs/dev/templates/team-danger.yaml new file mode 100644 index 000000000..b64d29d8b --- /dev/null +++ b/security/envs/dev/templates/team-danger.yaml @@ -0,0 +1,23 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: team-danger + namespace: argocd + labels: + {{- toYaml .Values.labels | nindent 4 }} + finalizers: + - resources-finalizer.argocd.argoproj.io +spec: + destination: + namespace: danger + server: {{ .Values.spec.destination.server }} + project: default + source: + path: teams/team-danger/dev + repoURL: {{ .Values.spec.source.repoURL }} + targetRevision: {{ .Values.spec.source.targetRevision }} + syncPolicy: + automated: + prune: true + syncOptions: + - CreateNamespace=true diff --git a/teams/team-danger/dev/Chart.yaml b/teams/team-danger/dev/Chart.yaml new file mode 100644 index 000000000..ea5868121 --- /dev/null +++ b/teams/team-danger/dev/Chart.yaml @@ -0,0 +1,5 @@ +apiVersion: v1 +appVersion: "1.0" +name: team-danger-dev +description: Team Danger applications for the Dev environment. +version: 0.1.0 diff --git a/teams/team-danger/dev/templates/privileged-pod.yaml b/teams/team-danger/dev/templates/privileged-pod.yaml new file mode 100644 index 000000000..9a819518e --- /dev/null +++ b/teams/team-danger/dev/templates/privileged-pod.yaml @@ -0,0 +1,13 @@ +# This is a privileged pod that can be used to test Guard Duty findings generation +apiVersion: v1 +kind: Pod +metadata: + name: privileged-pod +spec: + containers: + - name: app + image: centos + command: ["/bin/sh"] + args: ["-c", "sleep 999"] + securityContext: + privileged: true diff --git a/teams/team-danger/dev/values.yaml b/teams/team-danger/dev/values.yaml new file mode 100644 index 000000000..8b4b0fc83 --- /dev/null +++ b/teams/team-danger/dev/values.yaml @@ -0,0 +1,9 @@ +labels: + env: dev + team: danger +spec: + env: + ingress: + host: + region: + type: alb