CYBER-0 initial concept ready
This commit is contained in:
@@ -0,0 +1,77 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: demo-target
|
||||
namespace: test-automation
|
||||
labels:
|
||||
app: demo-target
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: demo-target
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: demo-target
|
||||
spec:
|
||||
containers:
|
||||
- name: ubuntu
|
||||
image: ubuntu:24.04
|
||||
imagePullPolicy: IfNotPresent
|
||||
command: ["/bin/bash", "-c"]
|
||||
args:
|
||||
- |
|
||||
set -e
|
||||
export DEBIAN_FRONTEND=noninteractive
|
||||
apt-get update
|
||||
apt-get install -y --no-install-recommends nginx openssh-server openssl python3
|
||||
mkdir -p /run/sshd /etc/nginx/tls
|
||||
id auditor >/dev/null 2>&1 || useradd --create-home --shell /bin/bash auditor
|
||||
echo 'auditor:DemoPassword1!' | chpasswd
|
||||
printf '\nPasswordAuthentication yes\nPermitRootLogin no\n' >> /etc/ssh/sshd_config
|
||||
openssl req -x509 -newkey rsa:2048 -nodes -days 30 -subj '/CN=demo-target' -keyout /etc/nginx/tls/server.key -out /etc/nginx/tls/server.crt
|
||||
cp /config/nginx.conf /etc/nginx/sites-enabled/default
|
||||
cp /config/index.html /var/www/html/index.html
|
||||
/usr/sbin/sshd
|
||||
exec nginx -g 'daemon off;'
|
||||
ports:
|
||||
- name: ssh
|
||||
containerPort: 22
|
||||
- name: https
|
||||
containerPort: 443
|
||||
readinessProbe:
|
||||
tcpSocket:
|
||||
port: https
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 3
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: "1"
|
||||
memory: 512Mi
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: /config
|
||||
volumes:
|
||||
- name: config
|
||||
configMap:
|
||||
name: demo-target-config
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: demo-target
|
||||
namespace: test-automation
|
||||
spec:
|
||||
selector:
|
||||
app: demo-target
|
||||
ports:
|
||||
- name: ssh
|
||||
port: 22
|
||||
targetPort: ssh
|
||||
- name: https
|
||||
port: 443
|
||||
targetPort: https
|
||||
Reference in New Issue
Block a user