blumeops/argocd/apps/prowler.yaml
Erich Blume a97391177a Deploy Prowler CIS scanner as weekly CronJob on minikube-indri
Custom slim container (no PowerShell/Trivy), NFS-backed reports
on sifaka:/volume1/reports/prowler/, ClusterRole with read-only
RBAC for Kubernetes CIS Benchmark v1.11 checks.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-24 15:00:48 -07:00

17 lines
403 B
YAML

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: prowler
namespace: argocd
spec:
project: default
source:
repoURL: ssh://forgejo@forge.ops.eblu.me:2222/eblume/blumeops.git
targetRevision: main
path: argocd/manifests/prowler
destination:
server: https://kubernetes.default.svc
namespace: prowler
syncPolicy:
syncOptions:
- CreateNamespace=true