-
Notifications
You must be signed in to change notification settings - Fork 9
feat(cp-node): Add systemd mode support for imagescan installation #401
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
097cbc6 to
21c1277
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
So with In Cluster Scan for VM.. We will be additionally deploying kubeshield agent?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If yes... Can we perform a benchmarking on the max memory being utilised by the services ??
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
No, we are not deploying the kubeshield agent; we are running the knoxctl command to discover and scan the image in the VM.
For this benchmarking, we scanned 214 container images.
Benchmarking results:
- Consumed 2min 24.569s CPU time.
- 81.7M memory peak.
- 42.1M memory swap peak.
| DiscoverAgent string = "accuknox-discover" | ||
| HardeningAgent string = "accuknox-hardening-agent" | ||
| RRA string = "accuknox-rra" | ||
| Kubeshield string = "accuknox-scanner" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why added twice ? One in line 93 and other in line 99?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
addressed, please verify
| CPUWeight=50 | ||
| {{- end }} | ||
|
|
||
| OOMPolicy=stop |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We are missing a dependency env here... We might be dependent on spire-agent if it is a control-plane right... Can we add the same here..
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added spire agent in the wants and after in the systemd service file.
Signed-off-by: Paveen Kumar <paveenkumar@accuknox.com>
Purpose of this PR?
Ticket: https://accu-knox.atlassian.net/browse/CNAPP-24231