From 1281e8ef37182e948ac683b390edce004a671c1f Mon Sep 17 00:00:00 2001 From: Danijel Simeunovic Date: Mon, 27 Apr 2026 12:54:18 +0200 Subject: [PATCH] databunker --- infra/base/databunker/databunker.yaml | 42 +++++++++++++++++++++ infra/base/databunker/kustomization.yaml | 4 ++ infra/base/kustomization.yaml | 1 + infra/overlays/upc-dev/kustomization.yaml | 9 +++++ infra/values/base/databunker-values.yaml | 34 +++++++++++++++++ infra/values/upc-dev/databunker-values.yaml | 3 ++ 6 files changed, 93 insertions(+) create mode 100644 infra/base/databunker/databunker.yaml create mode 100644 infra/base/databunker/kustomization.yaml create mode 100644 infra/values/base/databunker-values.yaml create mode 100644 infra/values/upc-dev/databunker-values.yaml diff --git a/infra/base/databunker/databunker.yaml b/infra/base/databunker/databunker.yaml new file mode 100644 index 0000000..b728aff --- /dev/null +++ b/infra/base/databunker/databunker.yaml @@ -0,0 +1,42 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: databunker + namespace: argocd + annotations: + argocd.argoproj.io/sync-wave: "1" + labels: + app.kubernetes.io/name: databunker + app.kubernetes.io/part-of: identity + app.kubernetes.io/managed-by: argocd + finalizers: + - resources-finalizer.argocd.argoproj.io +spec: + project: default + + sources: + - repoURL: https://securitybunker.github.io/databunkerpro-setup + chart: databunkerpro/databunkerpro + targetRevision: "0.1.0" + helm: + releaseName: databunkerpro + valueFiles: + - $values/infra/values/base/databunker-values.yaml + + - repoURL: ssh://git@git.forteapps.net:2222/Forte/launchpad.git + targetRevision: HEAD + ref: values + + destination: + server: https://kubernetes.default.svc + namespace: databunker + + syncPolicy: + automated: + prune: true + selfHeal: true + allowEmpty: false + syncOptions: + - CreateNamespace=true + - Validate=true + - ServerSideApply=true diff --git a/infra/base/databunker/kustomization.yaml b/infra/base/databunker/kustomization.yaml new file mode 100644 index 0000000..5349e5b --- /dev/null +++ b/infra/base/databunker/kustomization.yaml @@ -0,0 +1,4 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: +- databunker.yaml diff --git a/infra/base/kustomization.yaml b/infra/base/kustomization.yaml index 8b2f88f..1f216f1 100644 --- a/infra/base/kustomization.yaml +++ b/infra/base/kustomization.yaml @@ -20,3 +20,4 @@ resources: - tempo - grafana-dashboards - karpor +- databunker diff --git a/infra/overlays/upc-dev/kustomization.yaml b/infra/overlays/upc-dev/kustomization.yaml index 1895aac..be1f13c 100644 --- a/infra/overlays/upc-dev/kustomization.yaml +++ b/infra/overlays/upc-dev/kustomization.yaml @@ -5,3 +5,12 @@ resources: # No patches needed — base already has "upc-dev" paths # upc-dev is the default/base cluster + +patches: +- target: + kind: Application + name: databunker + patch: | + - op: add + path: /spec/sources/0/helm/valueFiles/- + value: $values/infra/values/upc-dev/databunker-values.yaml diff --git a/infra/values/base/databunker-values.yaml b/infra/values/base/databunker-values.yaml new file mode 100644 index 0000000..948a408 --- /dev/null +++ b/infra/values/base/databunker-values.yaml @@ -0,0 +1,34 @@ +# Default values for databunkerpro +image: + tag: 1.0.0 + +ingress: + enabled: false # Set to true to enable ingress + className: traefik + # Set host to enable ingress + host: databunker.example.com + annotations: + kubernetes.io/ingress.class: traefik + cert-manager.io/cluster-issuer: "letsencrypt-prod" # or your cluster issuer + traefik.ingress.kubernetes.io/ssl-redirect: "true" + traefik.ingress.kubernetes.io/force-ssl-redirect: "true" + traefik.ingress.kubernetes.io/ssl-passthrough: "false" + # Security headers + traefik.ingress.kubernetes.io/configuration-snippet: | + add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; + add_header X-Frame-Options DENY always; + add_header X-Content-Type-Options nosniff always; + add_header X-XSS-Protection "1; mode=block" always; + # TLS configuration + tls: + enabled: true # Set to true to enable TLS + secretName: "databunker-tls" # Name of the secret containing TLS certificate + +resources: + # Uncomment and adjust these values based on your requirements + # requests: + # memory: "512Mi" + # cpu: "250m" + # limits: + # memory: "1Gi" + # cpu: "500m" diff --git a/infra/values/upc-dev/databunker-values.yaml b/infra/values/upc-dev/databunker-values.yaml new file mode 100644 index 0000000..ab60a39 --- /dev/null +++ b/infra/values/upc-dev/databunker-values.yaml @@ -0,0 +1,3 @@ +ingress: + enabled: true + host: databunker.forteapps.net