Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
66 commits
Select commit Hold shift + click to select a range
4dee179
adaptive_export: chunk + bound the ordered capture path (flaky-captur…
entlein Aug 1, 2026
743fbd9
adaptive_export/pxl: filter infra noise from node-scoped dark capture…
entlein Aug 2, 2026
831162a
adaptive_export: bound ordered-capture subdivision (circuit-breaker +…
entlein Aug 2, 2026
7645a58
adaptive_export/control: widen near-zero /query windows to the lookback
entlein Aug 2, 2026
438bc3c
k8s/vizier: adaptive-export bootstrap = functional pem-direct DaemonSet
entlein Aug 3, 2026
279b436
adaptive_export: dc_snoop kernel-thread comm filter + adaptive-only d…
entlein Aug 4, 2026
f33b4ee
k8s/vizier/dx: skaffold module for dx-daemon deploy
entlein Aug 6, 2026
c4282c1
k8s/vizier/adaptive_export: skaffold overlay for AE deploy
entlein Aug 6, 2026
2e05ed2
skaffold: move AE/dx deploy configs to skaffold/ with root-relative p…
entlein Aug 6, 2026
0ac57f5
lab: bump dx->rc6 + AE->aeprod63, add evidence_graph env
entlein Aug 14, 2026
3a7672e
lab(dx): raise memory limit 1Gi->2Gi — fix OOM that empties the evide…
entlein Aug 14, 2026
2160f6d
lab(dx): DX_WORKERS=4->1 — fix SIGSEGV under the kill-chain referral …
entlein Aug 14, 2026
0b49e11
lab(dx): rc8 (pxapi nil-Timing SIGSEGV fix) + revert DX_WORKERS band-…
entlein Aug 15, 2026
c9b3742
dx lab manifest: non-garble optdbg2 image + 3Gi + DX_FOREST_PUSHDOWN
entlein Aug 15, 2026
cb1b68d
dx lab manifest: optdbg2 -> rc13 (obfuscated release, #138 fault 2 fi…
entlein Aug 15, 2026
5a52eb6
dx lab manifest: rc13 -> rc14 (clean trivy-free build, same config)
entlein Aug 16, 2026
c5c2736
adaptive_export: bounded-lookback watermark + wall-clock poison clamp…
entlein Aug 16, 2026
29a67c3
adaptive_export: secure-by-default control surface — TLS + auth ON (#96)
entlein Aug 16, 2026
7f4ef7d
ci: release manifest robust to lightweight tags (fix jq 'timestamp: ,…
entlein Aug 16, 2026
417b7a6
AE skaffold: aeprod63 -> aeprod64 (F8 watermark #97 + control secure-…
entlein Aug 16, 2026
573e630
pxl_scripts: dx/evidence_graph 3-level-zoom Live View bundle
entlein Aug 16, 2026
465e4d9
AE skaffold: aeprod64 -> aeprod65 (clean green release: #96 #97 + jq …
entlein Aug 16, 2026
0f5dbcc
pxl_scripts(px/dx_evidence_graph): fold in 3-level-zoom enhancements
entlein Aug 16, 2026
0a47333
pxl_scripts(px/dx_evidence_graph): fix reads validated live against f…
entlein Aug 16, 2026
aa3d30a
pxl_scripts(px/dx_evidence_graph): L3 shows the REAL anomaly records,…
entlein Aug 16, 2026
cef667b
pxl_scripts(px/dx_evidence_graph): join on uniqueID + surface process
entlein Aug 17, 2026
e322caf
pxl_scripts(px/dx_evidence_graph): L2 shows the actual attack cmdline…
entlein Aug 17, 2026
c591ab4
px/dx_evidence_graph: L2 = full pre-correlation record set; dx skaffo…
entlein Aug 17, 2026
75eec19
ae/pxl: stamp hostname on socket_tracer exports (#136 pushdown)
entlein Aug 18, 2026
49b0c2d
ae: dx_order_seeds table + dc_snoop dark-path hostname (#136)
entlein Aug 18, 2026
57268e1
px/dx_evidence_graph: multi-panel pre-correlation dashboard (#136)
entlein Aug 18, 2026
3f6b89f
test(clickhouse): dx_order_seeds joins the OperatorOwnedTables tail g…
Aug 18, 2026
133a226
ae: bake the order-UUID pre-correlation views into the image (#136)
entlein Aug 19, 2026
51652bc
ae: keep soc/AE ownership boundary — views tolerate a not-ready base …
entlein Aug 19, 2026
53d5e3c
test(clickhouse): the kubescape-ownership guard matches CREATE TABLE,…
Aug 19, 2026
9f4c9a8
px/dx_evidence_graph: add dc_snoop + stack_trace panels; rename to Ev…
entlein Aug 19, 2026
38ac499
px/dx_evidence_graph: hide plumbing columns from protocol panels
entlein Aug 19, 2026
e2be5ab
dx: pin dx-daemon image to rc21 (order-seed writer)
entlein Aug 19, 2026
59ed1e0
ae: dx_order_records bridge + dx-assigned order_id (#136 stamping)
entlein Aug 19, 2026
095a17c
ae: bake dx_src__stack_trace view + drop upid from the dx_src__ views…
entlein Aug 19, 2026
ddc7363
px/dx_evidence_graph: graph shows all alerts (process->target); panel…
entlein Aug 19, 2026
407e196
Revert ddc7363db: restore dx_evidence_graph.pxl to the agreed version
entlein Aug 19, 2026
da0c7a4
px/dx_evidence_graph: _consulted drops join/plumbing columns; vis.jso…
entlein Aug 19, 2026
c6fe707
skaffold: pin AE 0.14.19-aeprod71 + dx rc22 (latest order-UUID stampi…
entlein Aug 19, 2026
e426be3
ae: re-key dx_order_seeds + dx_anomaly_orders on order_id (dx owns de…
entlein Aug 19, 2026
1b9ca36
skaffold: pin dx rc23 (finer order_id = uniqueID+RuleID+Disc)
entlein Aug 19, 2026
a057cb6
skaffold: pin AE aeprod72 (order_id re-key; pairs with dx rc23)
entlein Aug 20, 2026
e168d19
px/dx_evidence_graph: order_id deep-links + kubescape detail in graph…
entlein Aug 20, 2026
8a7dd35
px/dx_evidence_graph: order deep-link opens the EXACT consulted set
entlein Aug 20, 2026
d72d904
px/dx_evidence_graph: ORDERS shows the kubescape alert text, not uniq…
entlein Aug 20, 2026
bbb8a5c
px/dx_evidence_graph: restore dx_src__ protocol-view panels (fix v0.0…
entlein Aug 20, 2026
1d24ba5
px/dx_evidence_graph: differential stack-trace flamegraph panel (atta…
entlein Aug 20, 2026
065f1dc
adaptive_export: bridge all consulted protocol tables to orders via u…
entlein Aug 21, 2026
77de8fa
build(ae): add the logrus dep to internal/control (strict deps)
Aug 21, 2026
4e079a5
pxl_scripts: add dx/evidence_graph (SOC, MITRE, deep-links, different…
entlein Aug 21, 2026
88977a3
adaptive_export: MITRE ATT&CK + per-order window views (operator-owne…
entlein Aug 21, 2026
83bab98
dx/evidence_graph: ORDERS disc->Alert, kubescape +pid/ppid -uniqueID,…
entlein Aug 21, 2026
4c7cb8e
deploy: pin AE 0.14.19-aeprod75 (bridge views + MITRE views) + dx 0.5…
entlein Aug 21, 2026
dc317b0
bazel: add sha256-verified mirror for org_libc_musl (musl.libc.org is…
entlein Aug 21, 2026
9827dbe
deploy: pin AE 0.14.19-aeprod76 (aeprod75 CI died on musl outage, ima…
entlein Aug 21, 2026
6512b69
dx/evidence_graph: fix _bridge unique_id compile error via passthroug…
entlein Aug 21, 2026
5b6e0ee
dx/evidence_graph: order-centric graph, revert dc_snoop to _ord, nati…
entlein Aug 21, 2026
1c20524
deploy: pin dx 0.5.0-keepset-rc2 (http collected as pod/ns metadata)
entlein Aug 21, 2026
703ebef
deploy: pin dx 0.5.0-keepset-rc4 (dns hops + dc_snoop union + redis h…
entlein Aug 21, 2026
a736fc2
dx/evidence_graph: differential stack window +/-30s with matched base…
entlein Aug 21, 2026
e12e864
deploy: pin dx 0.5.0-keepset-rc5 (dc_snoop union: comm + tree-pid + p…
entlein Aug 21, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion bazel/repository_locations.bzl
Original file line number Diff line number Diff line change
Expand Up @@ -456,7 +456,10 @@ REPOSITORY_LOCATIONS = dict(
org_libc_musl = dict(
sha256 = "7d5b0b6062521e4627e099e4c9dc8248d32a30285e959b7eecaa780cf8cfd4a4",
strip_prefix = "musl-1.2.3",
urls = ["http://musl.libc.org/releases/musl-1.2.3.tar.gz"],
urls = [
"https://sources.openwrt.org/musl-1.2.3.tar.gz",
"http://musl.libc.org/releases/musl-1.2.3.tar.gz",
],
manual_license_name = "libc/musl",
),
rules_cc = dict(
Expand Down
10 changes: 9 additions & 1 deletion ci/artifact_utils.sh
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,15 @@ create_manifest_update() {
tag_name="release/${component}/v${version}"
# actions/checkout doesn't get the tag annotation properly.
git fetch origin tag "${tag_name}" -f
timestamp="$(git tag -l --format "%(taggerdate:raw)" "${tag_name}" | awk '{print $1}' | jq '. | todate')"
# taggerdate is empty for a LIGHTWEIGHT tag → produces `timestamp: ,` → jq syntax
# error → release-metadata step fails even though the image built fine. Fall back to
# the tagged commit's committer date so the manifest is well-formed regardless of how
# the release tag was cut (annotated vs lightweight).
raw_ts="$(git tag -l --format "%(taggerdate:raw)" "${tag_name}" | awk '{print $1}')"
if [ -z "${raw_ts}" ]; then
raw_ts="$(git log -1 --format="%ct" "${tag_name}")"
fi
timestamp="$(printf '%s' "${raw_ts}" | jq '. | todate')"

jq -s \
"[{name: \"${component}\", artifact: [{timestamp: ${timestamp}, commitHash: \"${commit_hash}\", versionStr: \"${version}\", availableArtifactMirrors: .}]}]" \
Expand Down
10 changes: 10 additions & 0 deletions k8s/vizier/adaptive_export/kustomization.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: pl
resources:
- ../bootstrap/adaptive_export_role.yaml
- ../bootstrap/adaptive_export_deployment.yaml
images:
- name: vizier-adaptive_export_image
newName: ghcr.io/k8sstormcenter/vizier-adaptive_export_image
newTag: 0.14.19-aeprod76
142 changes: 62 additions & 80 deletions k8s/vizier/bootstrap/adaptive_export_deployment.yaml
Original file line number Diff line number Diff line change
@@ -1,115 +1,97 @@
---
# adaptive-export: node-local forensic capture operator. DaemonSet so each pod
# queries its own node's vizier-pem (pem-direct). Secret seeded per-cluster.
apiVersion: apps/v1
kind: Deployment
kind: DaemonSet
metadata:
name: adaptive-export
labels: { name: adaptive-export, plane: control }
spec:
replicas: 0
selector:
matchLabels:
name: adaptive-export
matchLabels: { name: adaptive-export }
template:
metadata:
labels:
name: adaptive-export
plane: control
labels: { name: adaptive-export, plane: control }
spec:
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
# The beta.kubernetes.io/os label has been deprecated since
# k8s v1.14; every modern kubelet sets kubernetes.io/os. The
# single term below is enough — kept both ORed terms in the
# past for pre-1.14 compatibility.
- matchExpressions:
- key: kubernetes.io/os
operator: In
values:
- linux
- { key: kubernetes.io/os, operator: In, values: [linux] }
serviceAccountName: pl-adaptive-export-service-account
containers:
- name: adaptive-export
image: vizier-adaptive_export_image:latest
# Bounded so AE can never memory-pressure a node (measured: AE uses
# only ~16-38Mi steady; passthrough with the raised 1M-row cap can
# spike, so 1Gi caps the worst case). CPU was pinned at the old 300m
# limit under concurrent passthrough → raised to 1 core.
ports:
- { name: control, containerPort: 9100, hostPort: 9100 }
resources:
requests:
cpu: 200m
memory: 128Mi
limits:
cpu: "1"
memory: 1Gi
requests: { cpu: 100m, memory: 128Mi }
limits: { cpu: "1", memory: 1Gi }
env:
- name: HOST_IP
valueFrom: { fieldRef: { fieldPath: status.hostIP } }
- name: ADAPTIVE_VIZIER_DIRECT_ADDR
value: "$(HOST_IP):50305"
- name: PL_JWT_SIGNING_KEY
valueFrom: { secretKeyRef: { name: pl-cluster-secrets, key: jwt-signing-key } }
- name: PX_DISABLE_TLS
value: "1"
- name: PL_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
valueFrom: { fieldRef: { fieldPath: metadata.namespace } }
- name: NODE_NAME
valueFrom: { fieldRef: { fieldPath: spec.nodeName } }
- name: PIXIE_API_KEY
valueFrom:
secretKeyRef:
name: pl-adaptive-export-secrets
key: pixie-api-key
valueFrom: { secretKeyRef: { name: pl-adaptive-export-secrets, key: pixie-api-key } }
- name: CLICKHOUSE_DSN
valueFrom:
secretKeyRef:
name: pl-adaptive-export-secrets
key: clickhouse-dsn
- name: VERBOSE
value: "true"
- name: DETECTION_INTERVAL_SEC
value: "10"
- name: DETECTION_LOOKBACK_SEC
value: "30"
# EXPORT_MODE controls the reconcile behaviour:
# auto - detection drives on/off (default)
# always - plugin always enabled (bypass detection)
# never - plugin always disabled and ch-* scripts purged
- name: EXPORT_MODE
value: "auto"
# Number of consecutive empty detection ticks before auto-disable fires.
- name: EXPORT_QUIET_TICKS
value: "6"
# Optional overrides for the ClickHouse PxL scripts. When unset they are
# parsed from CLICKHOUSE_DSN. Individual fields win over the parsed DSN.
# Defaults below match soc/tree/clickhouse-lab (forensic-soc-db CHI,
# ingest_writer user, forensic_db database).
valueFrom: { secretKeyRef: { name: pl-adaptive-export-secrets, key: clickhouse-dsn } }
- name: KUBESCAPE_TABLE
value: "kubescape_logs"
# - name: CLICKHOUSE_HOST
# value: "clickhouse-forensic-soc-db.clickhouse.svc.cluster.local"
# - name: CLICKHOUSE_PORT
# value: "9000"
# - name: CLICKHOUSE_USER
# value: "ingest_writer"
# - name: CLICKHOUSE_PASSWORD
# value: "changeme-ingest"
# - name: CLICKHOUSE_DATABASE
# value: "forensic_db"
# TLS for the control surface (CONTROL_TLS=true). server.crt/key from the
# same service-tls-certs secret the broker/PEM use; without this the dx
# bearer JWT crosses the CNI in cleartext. Harmless when control is off.
- name: EXPORT_MODE
value: "never"
# Control surface is secure-by-default (#96): TLS + bearer-JWT auth are ON
# out of the box. The service-tls-certs keypair mounted at /certs below is
# used for TLS (else AE self-generates an ephemeral in-memory cert), and
# PL_JWT_SIGNING_KEY above turns on auth. CONTROL_TLS / CONTROL_REQUIRE_AUTH
# are deprecated no-ops; set CONTROL_INSECURE=true only to opt out (dev).
- name: CONTROL_ADDR
value: ":9100"
- name: ADAPTIVE_PUSH_PIXIE_ROWS
value: "true"
- name: ADAPTIVE_RECONCILE
value: "true"
- name: DEPLOY_TRACEPOINTS
value: "true"
- name: INSTALL_PRESET_SCRIPTS
value: "false"
- name: ADAPTIVE_MAX_INFLIGHT_QUERIES_GLOBAL
value: "4"
- name: ADAPTIVE_ORDER_CHUNK_SEC
value: "600"
- name: VERBOSE
value: "true"
volumeMounts:
- name: certs
mountPath: /certs
readOnly: true
- { name: certs, mountPath: /certs, readOnly: true }
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
seccompProfile:
type: RuntimeDefault
capabilities: { drop: [ALL] }
seccompProfile: { type: RuntimeDefault }
volumes:
- name: certs
secret:
secretName: service-tls-certs
secret: { secretName: service-tls-certs }
securityContext:
runAsUser: 10100
runAsGroup: 10100
fsGroup: 10100
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
seccompProfile: { type: RuntimeDefault }
---
apiVersion: v1
kind: Service
metadata:
name: adaptive-export-control
spec:
selector: { name: adaptive-export }
internalTrafficPolicy: Local # dx reaches its co-located (same-node) AE
ports:
- { name: control, port: 9100, targetPort: 9100 }
79 changes: 79 additions & 0 deletions k8s/vizier/dx/dx-daemon.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
apiVersion: v1
kind: ServiceAccount
metadata: { name: dx-daemon, namespace: honey }
---
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: dx-daemon
namespace: honey
labels: { app: dx-daemon }
spec:
selector: { matchLabels: { app: dx-daemon } }
template:
metadata:
labels: { app: dx-daemon }
spec:
serviceAccountName: dx-daemon
tolerations: [{ operator: Exists }]
terminationGracePeriodSeconds: 35
containers:
- name: dx-daemon
# OBFUSCATED release rc13 (entlein/dx#138 fault 2 RESOLVED): garble -literals
# (WITHOUT -tiny — -tiny's pclntab stripping SIGSEGV'd under load). Passes the
# obfuscation gate AND survives the kill-chain (restarts=0, 4 rounds). Carries the
# evidence-manifest + DX_FOREST_PUSHDOWN code.
image: docker.io/entlein/dx-daemon:0.5.0-keepset-rc5
ports:
- { name: findings, containerPort: 9099, hostPort: 9099 }
env:
- { name: NODE_NAME, valueFrom: { fieldRef: { fieldPath: spec.nodeName } } }
- { name: HOST_IP, valueFrom: { fieldRef: { fieldPath: status.hostIP } } }
- { name: DX_RECEIVER_TLS, value: "1" }
# AE control surface is TLS-by-default (#96); the dx client TLS-skip-verifies
# the in-cluster (self-signed/shared) cert and attaches its bearer JWT.
- { name: AE_CONTROL_ADDR, value: "https://adaptive-export-control.pl.svc.cluster.local:9100" }
- { name: PX_API_KEY, valueFrom: { secretKeyRef: { name: dx-pixie-auth, key: api-key, optional: true } } }
- { name: PX_CLUSTER_ID, valueFrom: { secretKeyRef: { name: dx-pixie-auth, key: cluster-id, optional: true } } }
- { name: PX_CLOUD_ADDR, valueFrom: { secretKeyRef: { name: dx-pixie-auth, key: cloud-addr, optional: true } } }
- { name: DX_BENCH, value: "pemdirect" }
- { name: PL_JWT_SIGNING_KEY, valueFrom: { secretKeyRef: { name: dx-vizier-direct, key: jwt-signing-key, optional: true } } }
- { name: DX_VIZIER_DIRECT_ADDR, value: "vizier-query-broker-svc.pl.svc.cluster.local:50300" }
- { name: PX_DISABLE_TLS, value: "1" }
- { name: DX_CLUSTER_MALIGNANT_HTTP, valueFrom: { secretKeyRef: { name: dx-metastasis-ch, key: http-url, optional: true } } }
- { name: DX_PX_TIMEOUT_S, value: "90" }
- { name: DX_TELEMETRY_CACHE, value: "1" }
- { name: DX_WORKERS, value: "4" }
# evidence-graph: forest-scope the evidence, write the per-anomaly edge set,
# sink it straight to forensic_db.dx_evidence_graph (soc ingest_writer).
- { name: DX_FOREST_SCOPE, value: "1" }
# FOREST_PUSHDOWN (entlein/dx#138 fault 3): push the dc_snoop ppid-lineage filter
# INTO the PxL so dx pulls only the alert pod's subtree, not the whole node —
# frees the node-local PEM so AE can export dc_snoop under load (validated: 0→1777).
- { name: DX_FOREST_PUSHDOWN, value: "1" }
- { name: DX_FOREST_PUSHDOWN_DEPTH, value: "4" }
- { name: DX_PRECORRELATE_GRAPH, value: "1" }
- { name: DX_EVIDENCE_GRAPH_CH, value: "http://ingest_writer:changeme-ingest@clickhouse-forensic-soc-db.clickhouse.svc.cluster.local:8123/forensic_db" }
readinessProbe:
httpGet: { path: /healthz, port: 9099, scheme: HTTPS }
initialDelaySeconds: 3
periodSeconds: 10
resources:
# memory: the precorrelate/full-evidence workup (DX_PRECORRELATE_GRAPH) + pemdirect
# gRPC result streams pull the per-anomaly evidence set into memory; at 1Gi dx is
# OOM-killed mid-workup (exit 137) BEFORE it writes the graph → crash-loop, empty
# graph. Measured peak ~1.3GB/round under the redis kill-chain (entlein/dx#138
# fault 1); 3Gi clears it reliably on an 8GiB node (validated: restarts=0 over 6+ rounds).
requests: { cpu: 50m, memory: 1Gi }
limits: { cpu: "2", memory: 3Gi }
---
apiVersion: v1
kind: Service
metadata:
name: dx-daemon
namespace: honey
spec:
selector: { app: dx-daemon }
internalTrafficPolicy: Local
ports:
- { name: findings, port: 9099, targetPort: 9099 }
5 changes: 5 additions & 0 deletions k8s/vizier/dx/kustomization.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: honey
resources:
- dx-daemon.yaml
44 changes: 44 additions & 0 deletions skaffold/skaffold_adaptive_export.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
---
# Deploy-only Skaffold for the adaptive_export DaemonSet using a prebuilt image
# (lab / review), overlaying an already-running vizier. Run from the repo root:
# skaffold deploy -f skaffold/skaffold_adaptive_export.yaml
# Bump the image via newTag in k8s/vizier/adaptive_export/kustomization.yaml.
apiVersion: skaffold/v4beta11
kind: Config
metadata:
name: adaptive-export
manifests:
kustomize:
paths:
- k8s/vizier/adaptive_export
buildArgs:
- --load-restrictor=LoadRestrictionsNone
deploy:
kubectl:
defaultNamespace: pl
hooks:
before:
- host:
command:
- bash
- -c
- |
set -e
# PL_CLOUD_ADDR must carry an explicit :443 or the AE cloud client crashloops.
CA=$(kubectl -n pl get cm pl-cloud-config -o jsonpath='{.data.PL_CLOUD_ADDR}' 2>/dev/null || true)
case "$CA" in ""|*:*) ;; *) kubectl -n pl patch cm pl-cloud-config --type merge -p "{\"data\":{\"PL_CLOUD_ADDR\":\"$CA:443\"}}";; esac
# Seed pl-adaptive-export-secrets ONLY when a key is supplied; never clobber a good secret with an empty one.
API="${PIXIE_API_KEY:-${PX_API_KEY:-}}"
CH_DSN="${AE_CH_DSN:-ingest_writer:changeme-ingest@clickhouse-forensic-soc-db.clickhouse.svc.cluster.local:9000/forensic_db}"
if [ -n "$API" ]; then
kubectl -n pl create secret generic pl-adaptive-export-secrets \
--from-literal=pixie-api-key="$API" \
--from-literal=clickhouse-dsn="$CH_DSN" \
--dry-run=client -o yaml | kubectl apply -f -
elif ! kubectl -n pl get secret pl-adaptive-export-secrets >/dev/null 2>&1; then
echo "ERROR: set PIXIE_API_KEY (or source keys.env) to seed pl-adaptive-export-secrets" >&2
exit 1
else
echo "pl-adaptive-export-secrets exists; PIXIE_API_KEY unset -> leaving it untouched"
fi
os: [linux, darwin]
42 changes: 42 additions & 0 deletions skaffold/skaffold_dx.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
---
# Deploy-only Skaffold for the dx-daemon DaemonSet (prebuilt image), overlaying an
# already-running vizier + soc stack. Run from the repo root, AFTER adaptive_export
# (the hook mirrors pl-adaptive-export-secrets into honey):
# skaffold deploy -f skaffold/skaffold_dx.yaml
apiVersion: skaffold/v4beta11
kind: Config
metadata:
name: dx-daemon
manifests:
kustomize:
paths:
- k8s/vizier/dx
deploy:
kubectl:
defaultNamespace: honey
hooks:
before:
- host:
command:
- bash
- -c
- |
set -e
kubectl create namespace honey --dry-run=client -o yaml | kubectl apply -f -
JWT=$(kubectl -n pl get secret pl-cluster-secrets -o jsonpath='{.data.jwt-signing-key}' | base64 -d)
CID=$(kubectl -n pl get secret pl-cluster-secrets -o jsonpath='{.data.cluster-id}' | base64 -d)
CA=$(kubectl -n pl get cm pl-cloud-config -o jsonpath='{.data.PL_CLOUD_ADDR}')
API=$(kubectl -n pl get secret pl-adaptive-export-secrets -o jsonpath='{.data.pixie-api-key}' 2>/dev/null | base64 -d)
CH_URL="${DX_CH_HTTP_URL:-http://ingest_writer:changeme-ingest@clickhouse-forensic-soc-db.clickhouse.svc.cluster.local:8123/?database=forensic_db}"
kubectl -n honey create secret generic dx-vizier-direct \
--from-literal=jwt-signing-key="$JWT" \
--dry-run=client -o yaml | kubectl apply -f -
kubectl -n honey create secret generic dx-pixie-auth \
--from-literal=api-key="$API" \
--from-literal=cluster-id="$CID" \
--from-literal=cloud-addr="$CA" \
--dry-run=client -o yaml | kubectl apply -f -
kubectl -n honey create secret generic dx-metastasis-ch \
--from-literal=http-url="$CH_URL" \
--dry-run=client -o yaml | kubectl apply -f -
os: [linux, darwin]
Loading
Loading