Deploying External S-TAP from the Guardium UI
If your site uses Kubernetes, you can deploy an External S-TAPĀ® directly from GuardiumĀ®.
About this task
To deploy with Kubernetes from the Guardium UI, use either Amazon Elastic Container Service for Kubernetes (Amazon EKS) or Microsoft Azure Kubernetes Service (AKS).
- Create a Kubernetes admin user.
- Retrieve the Kubernetes cluster access token.
- Retrieve the master URL.
- Create the registry key for your cluster.
- For IBM Cloud deployments only, create a repository with a registry key.
- Make sure that any SSL-enabled collectors have valid SSL certificates.
container.clusterRoleBindings.create and
container.clusterRoles.bin.These permissions allow the IAM user to add the cluster user and create tokens for GUI deployment.
Without these permissions, the IAM user can still deploy with Kubernetes by using the templates. For more information about generating and using the templates, see Deploy External S-TAP window.
Procedure
What to do next
After you complete these tasks, you can deploy a new External S-TAP directly from Guardium. Kubernetes automatically manages the Docker container and balancing the load.
For more information, see The External S-TAP user interface and the Deploy External S-TAP window
In step 1a above, is it your-account is the name of service account OR your-secret-name is the name of service account? Please confirm.