Venafi Kubernetes Agent

Jetstack Secure 的开放源码组件。「Open source components of Jetstack Secure」

Github星跟蹤圖

Venafi Kubernetes Agent

tests
Go Reference
Go Report Card

"The agent" manages your machine identities across Cloud Native Kubernetes and OpenShift environments and builds a detailed view of the enterprise security posture.

Installation

Please review the documentation for the agent.

Detailed installation instructions are available for a variety of methods.

Local Execution

To build and run a version from master:

go run main.go agent --agent-config-file ./path/to/agent/config/file.yaml -p 0h1m0s

You can configure the agent to perform one data gathering loop and output the data to a local file:

go run . agent \
   --agent-config-file examples/one-shot-secret.yaml \
   --one-shot \
   --output-path output.json

Some examples of agent configuration files:

You might also want to run a local echo server to monitor requests sent by the agent:

go run main.go echo

Metrics

The agent exposes its metrics through a Prometheus server, on port 8081.

The Prometheus server is disabled by default but can be enabled by passing the --enable-metrics flag to the agent binary.

If you deploy the agent using the venafi-kubernetes-agent Helm chart, the metrics server will be enabled by default, on port 8081.

If you use the Prometheus Operator, you can use --set metrics.podmonitor.enabled=true to deploy a PodMonitor resource,
which will add the venafi-kubernetes-agent metrics to your Prometheus server.

The following metrics are collected:

  • Go collector: via the default registry in Prometheus client_golang.
  • Process collector: via the default registry in Prometheus client_golang.
  • Agent metrics: data_readings_upload_size: Data readings upload size (in bytes) sent by the in-cluster agent.

End to end testing

An end to end test script is available in the ./hack/e2e/test.sh directory. It is configured to run in CI
in the tests.yaml GitHub Actions workflow. To run the script you will need to add the test-e2e label to the PR.
The script creates a cluster in GKE and cleanups after itself unless the keep-e2e-cluster label is set on the PR. Adding that
label will leave the cluster running for further debugging but it will incur costs so manually delete the cluster when done.

主要指標

概覽
名稱與所有者jetstack/jetstack-secure
主編程語言Go
編程語言Makefile (語言數: 4)
平台
許可證Apache License 2.0
所有者活动
創建於2019-11-06 11:55:36
推送於2025-10-24 14:20:02
最后一次提交2025-10-23 14:47:10
發布數86
最新版本名稱v1.7.0 (發布於 2025-10-23 15:48:31)
第一版名稱v0.1.8-alpha.1 (發布於 )
用户参与
星數261
關注者數21
派生數25
提交數1.1k
已啟用問題?
問題數78
打開的問題數11
拉請求數455
打開的拉請求數10
關閉的拉請求數191
项目设置
已啟用Wiki?
已存檔?
是復刻?
已鎖定?
是鏡像?
是私有?